Ad tech stocks
TEAD0.61▲ +20.29%CDLX2.72▼ -7.48%186013.51▲ +7.48%PSKY9.85▼ -4.70%U42.71▲ +4.35%APP280.13▼ -3.55%LFTO15.36▼ -2.82%MNTN10.45▲ +2.75%SFOR44.85▼ -2.50%CCO2.40▲ +2.34%STGW8.31▲ +2.09%SAX36.16▲ +1.97%SST2.57▼ -1.91%OMC74.97▲ +1.82%NFLX68.32▼ -1.81%WPP382.90▲ +1.81%AAPL327.58▼ -1.63%SIRI25.46▼ -1.62%NEXN8.86▼ -1.61%PINS18.61▼ -1.46%APPS11.26▲ +1.44%SCOR4.75▲ +1.39%RDDT144.43▲ +1.39%TBLA3.31▼ -1.34%ZETA31.98▲ +1.30%035420191200.00▼ -1.29%4755681.70▼ -1.26%AZRN0.82▼ -1.20%CPNG13.71▼ -1.15%PUBM18.94▲ +1.12%BIDU85.92▼ -1.09%DSP12.43▲ +0.97%GOOGL341.01▼ -0.89%ROKU150.98▼ -0.85%PUB95.28▲ +0.80%PERI8.63▼ -0.69%47511238.50▲ +0.57%MGNI25.13▼ -0.53%BABA107.08▼ -0.43%24331308.00▲ +0.38%CRTO15.15▼ -0.33%TRU61.32▲ +0.33%INUV0.56▲ +0.32%HAVAS17.70▲ +0.28%META726.91▲ +0.24%0700431.00▼ -0.23%OUT27.69▼ -0.22%RAMP37.60▲ +0.21%CART43.18▲ +0.14%IBTA39.35▼ -0.13%SPOT487.93▲ +0.11%SNAP5.41▲ +0.09%DEC24.62▼ -0.08%WBD30.93▼ -0.06%DV13.48▼ -0.04%43243564.00▲ +0.03%IHRT2.10▲ 0.00%ILLM0.65▲ 0.00%SNOW339.57▲ 0.00%TTD12.17▲ 0.00%VER12.08▲ 0.00%
Ticker byClearTrust

What is SDK spoofing?

SDK spoofing is a mobile fraud in which criminals send fake install and in-app event messages directly to an attribution provider's servers, imitating the measurement SDK inside a real app. No device, app or user is involved; the fraudster simply fabricates convincing data so an advertiser pays for installs and purchases that never happened.

Short answer · AdTech Sumo

Mobile apps include an SDK from their MMP that reports installs and events. If fraudsters reverse-engineer how that SDK talks to its servers, they can replay or forge the messages from a server farm. SDK spoofing became prominent around 2017–2018, when measurement providers reported large volumes of perfectly formed but fake installs.

The main countermeasure is cryptographic signing: modern SDKs sign each message with a secret that is hard to extract, and servers reject unsigned or tampered payloads. Advertisers should confirm their MMP enforces signing and watch for cohorts with zero retention or impossible event patterns, signs of install fraud regardless of method.

Related questions