Ad tech stocks
TEAD0.55▲ +8.59%186013.51▲ +7.48%SAX36.96▲ +4.23%MNTN10.60▲ +4.23%PSKY9.90▼ -4.16%OMC76.17▲ +3.45%WPP387.90▲ +3.14%INUV0.58▲ +2.97%TRU62.86▲ +2.85%DSP12.63▲ +2.60%CCO2.40▲ +2.34%APP284.30▼ -2.11%PUB96.44▲ +2.03%SCOR4.59▼ -2.03%RDDT145.32▲ +2.02%STGW8.30▲ +1.97%APPS11.30▲ +1.80%ZETA32.07▲ +1.58%NFLX68.55▼ -1.49%SIRI25.53▼ -1.35%035420191200.00▼ -1.29%4755681.70▼ -1.26%BABA108.85▲ +1.22%AZRN0.82▼ -1.20%IHRT2.08▼ -1.19%U41.40▲ +1.15%HAVAS17.85▲ +1.13%DEC24.90▲ +1.06%LFTO15.65▼ -0.95%CPNG13.76▼ -0.83%IBTA39.11▼ -0.74%SNAP5.44▲ +0.74%BIDU87.46▲ +0.68%NEXN9.05▲ +0.61%OUT27.58▼ -0.61%AAPL331.05▼ -0.59%PUBM18.84▲ +0.59%VER12.15▲ +0.58%47511238.50▲ +0.57%SPOT489.81▲ +0.50%META728.66▲ +0.48%TTD12.22▲ +0.45%24331308.00▲ +0.38%SST2.61▼ -0.38%GOOGL342.87▼ -0.35%TBLA3.37▲ +0.30%0700431.00▼ -0.23%CRTO15.23▲ +0.23%SFOR46.10▲ +0.22%PINS18.93▲ +0.21%RAMP37.59▲ +0.20%PERI8.71▲ +0.17%CART43.09▼ -0.07%DV13.48▼ -0.04%MGNI25.25▼ -0.04%SNOW339.48▼ -0.03%43243564.00▲ +0.03%ROKU152.31▲ +0.02%CDLX2.94▲ 0.00%ILLM0.65▲ 0.00%WBD30.95▲ 0.00%
Ticker byClearTrust

Ad fraud case files

Documented fraud operations, newest first. Scale figures are as reported by the investigators at the time.

Presented byClearTrust· Advanced solutions to prevent ad fraud and boost traffic quality.
2026 · MIXED · found by Google Threat Intelligence, with Lumen Black Lotus Labs

IPIDEA residential proxy network

Residential proxy network built from consumer devices · Advertised 6.1 million daily-refreshed IP addresses; about 5 million bots still connecting at disruption (Google, January 2026)

How it worked. Software on phones, TV boxes and PCs quietly rented out the owners' home internet connections. Buyers of that access, including many criminal groups, could make their traffic look like ordinary households.

What happened. Google took legal action to seize dozens of control domains in January 2026 and updated Play Protect to remove apps with the proxy code; proxy numbers fell by about 40% within weeks.

The lesson. Residential IPs are for sale at scale; IP reputation alone cannot separate humans from bots.

2026 · MOBILE · found by Kaspersky

Keenadu

Firmware-level backdoor on Android devices used heavily for ad fraud · About 13,700 affected users detected worldwide (Kaspersky, 2026)

How it worked. The malware sat inside a core part of the Android system on some devices, so it ran inside every app and could get around normal app permissions. It was used mainly to generate fraudulent ad activity and showed links to BADBOX and Triada.

What happened. Google removed three related smart-camera apps from Play and Play Protect now flags known versions.

The lesson. When fraud lives in firmware, app-level checks see nothing wrong; device provenance is part of ad quality.

2026 · MOBILE · found by HUMAN Satori Threat Intelligence

Trapdoor

Utility apps that pushed secondary apps running hidden ad traffic · 455 apps, 24 million downloads and up to 659 million bid requests a day; more than 75% of traffic from the US (HUMAN, 2026)

How it worked. Harmless-looking PDF and clean-up apps showed misleading ads that pushed users to install further apps. Those apps opened hidden web views that requested ads, and switched on only for users acquired through the operators' campaigns.

What happened. Google removed all identified apps from Google Play after disclosure in May 2026.

The lesson. Malvertising and ad fraud feed each other: bad ads recruit the devices that then fake impressions.

2025 · MOBILE · found by Integral Ad Science Threat Lab and Bitdefender

Vapor

Android apps that turned malicious after approval and flooded phones with ads · 331 apps with more than 60 million downloads and over 200 million bid requests a day (IAS/Bitdefender, 2025)

How it worked. The apps were published as working tools, then updated to add harmful features. They hid themselves and showed full-screen video ads out of context, sometimes making the phone hard to use; some variants also tried to steal credentials.

What happened. Google removed all the identified apps from the Play Store.

The lesson. An app that was clean at review time may not be clean later; ongoing monitoring beats one-time vetting.

2025 · MIXED · found by HUMAN Satori with Google, Trend Micro, Shadowserver and others

BADBOX 2.0

Backdoored uncertified Android devices (TV boxes, projectors, car systems) used for ad fraud and proxies · About 1 million infected devices at disclosure (HUMAN, March 2025); Google later cited more than 10 million uncertified devices (Google, July 2025)

How it worked. Low-cost devices made in mainland China were sold with a hidden backdoor or picked one up through trojanized apps. Several cooperating groups used the devices to run hidden ads, click fraud and a residential proxy service.

What happened. Partners sinkholed domains and Google removed 24 apps (March 2025). The FBI issued a public warning in June 2025, and in July 2025 Google sued 25 unnamed operators in New York federal court and won a preliminary injunction.

The lesson. Cheap "free TV" boxes are a major source of CTV and residential-proxy fraud; buyers should demand device-level traffic quality signals.

2025 · MOBILE · found by Integral Ad Science Threat Lab

Kaleidoscope

"Evil twin" apps on third-party stores mimicking Google Play apps · Heaviest impact in Latin America, Turkey, Egypt and India (IAS, 2025)

How it worked. A clean version of each app sat on Google Play while look-alike versions distributed through third-party app stores bombarded users with intrusive ads. The fraudulent traffic borrowed the identity of the legitimate app.

What happened. IAS published the findings and shared indicators with the industry; the operation was linked to earlier campaigns.

The lesson. Where side-loading and third-party app stores are common, as in parts of India and Latin America, app-identity spoofing is a bigger risk.

2025 · MOBILE · found by HUMAN Satori Threat Intelligence

IconAds

Apps that hid their own icons and showed out-of-context ads · 352 apps and up to 1.2 billion bid requests a day at peak (HUMAN, 2025)

How it worked. After installation the apps made their icons disappear so users could not easily find or remove them, then displayed ads outside of any app the user was actually using.

What happened. Google removed all the identified apps from Google Play.

The lesson. Out-of-context ads are both bad user experience and a fraud signal.

2025 · MOBILE · found by HUMAN Satori Threat Intelligence

SlopAds

Apps that only turned fraudulent for users acquired through the operators' own ads · 224 apps, 38 million downloads in 228 countries, and up to 2.3 billion bid requests a day (HUMAN, 2025)

How it worked. The fraud code stayed dormant for normal downloads and switched on only for users who arrived via the operators' ad campaigns, which helped it hide from researchers. Hidden web views then generated ad traffic on sites the operators controlled.

What happened. Google removed all the apps from Google Play.

The lesson. Fraudsters now use attribution data to decide when to misbehave, so a clean test install proves little.

2024 · MOBILE · found by HUMAN Satori Threat Intelligence

Konfety

"Evil twin" apps spoofing harmless decoy apps · 250+ decoy apps on Google Play and up to 10 billion fraudulent requests a day at peak (HUMAN, 2024)

How it worked. The operators published innocent "decoy" apps on the official store and spread malicious twins of them elsewhere through malicious ads. The twins used the decoys' identities so their fraudulent ad traffic looked like it came from legitimate apps.

What happened. Google Play Protect detects and disables the twin apps; a new variant was reported in 2025.

The lesson. An app ID in a bid request is only a claim; the store listing can be clean while the traffic is not.

2023 · MOBILE · found by HUMAN Satori Threat Intelligence

VASTFLUX

Malicious code inside in-app video ads, stacking invisible players · About 11 million devices, 1,700 spoofed apps, 120 publishers and up to 12 billion bid requests a day at peak (HUMAN, 2023)

How it worked. The fraudsters bought legitimate ad slots inside apps, then used code hidden in their ad to secretly stack many video ad players behind one another. Each hidden player registered a paid view, while the user saw only one ad.

What happened. HUMAN disrupted the operation in mid-2022 through targeted blocking; traffic fell sharply and the scheme was reported shut down in January 2023.

The lesson. An ad creative can itself be an attack; buyers and sellers need creative scanning and ad stacking detection.

2023 · MOBILE · found by Trend Micro

Lemon Group pre-infected phones

Malware installed on budget phones before sale, used for ads and proxies · About 8.9 million compromised Android devices in 180+ countries (Trend Micro, 2023)

How it worked. Malware was added to cheap phones somewhere in the manufacturing or supply chain. Among other things it showed unwanted ads, committed click fraud and rented out the phone's internet connection as a residential proxy.

What happened. Trend Micro presented the research at Black Hat Asia 2023; the infrastructure overlapped with later BADBOX findings.

The lesson. Some fraud begins in the factory, which makes device and supply-chain provenance part of traffic quality.

2023 · MIXED · found by HUMAN Satori Threat Intelligence (building on Trend Micro research)

BADBOX and PEACHPIT

Backdoored off-brand Android devices and CTV boxes plus an app-based ad fraud botnet · PEACHPIT peaked at 121,000 Android and 159,000 iOS devices a day; 39 apps with 15 million installs; activity in 227 countries (HUMAN, 2023)

How it worked. Cheap, uncertified Android TV boxes and tablets shipped with a hidden backdoor. The infected devices, together with look-alike apps, generated hidden ad traffic, served as residential proxies and created fake accounts.

What happened. HUMAN worked with Google and Apple to disrupt it. In December 2024 Germany's BSI cut off at least 30,000 infected devices in Germany by sinkholing the operators' servers.

The lesson. Traffic from real homes and real TV boxes can still be fraudulent; hardware provenance matters in CTV fraud.

2022 · MOBILE · found by HUMAN Satori Threat Intelligence

SCYLLA (Poseidon and Charybdis)

Hidden ads and app spoofing across Android and iOS apps · 85 apps (75 Android, 10 iOS) with more than 13 million installs (HUMAN, 2022)

How it worked. The apps pretended to be other popular apps so ad systems would pay higher prices, and loaded ads off-screen where nobody could see them. It was the third wave of a scheme that began in 2019.

What happened. Google and Apple removed the apps after HUMAN reported them.

The lesson. Fraud operations come back in new versions; takedowns are ongoing work, not a one-off.

2020 · MOBILE · found by Check Point Research

Tekya

Click-fraud code in children's games and utility apps · 56 apps with about 1 million downloads, including 24 children's games (Check Point, 2020)

How it worked. The apps imitated a user's taps to click ads from major mobile ad networks, so advertisers paid for clicks no person made.

What happened. Google removed all the apps from Google Play.

The lesson. Apps aimed at children are a frequent target, which also raises COPPA concerns for advertisers.

2020 · CTV · found by White Ops (now HUMAN), working with Roku and Google

PARETO

Connected TV spoofing: Android phones pretending to be streaming TVs · Around 1 million infected mobile devices spoofing thousands of CTV apps, with hundreds of millions of bid requests a day at peak (White Ops, 2020)

How it worked. Malicious Android apps made phones send ad requests that claimed to come from TV-streaming devices watching popular channels. Because CTV ads cost far more than mobile ads, faking the device type multiplied the payout.

What happened. White Ops disrupted the operation in 2020 with Roku and Google; Google removed the apps. It became a key example in industry calls for stronger CTV supply-chain checks such as app-ads.txt.

The lesson. CTV's high prices make it the most profitable place to fake; check device claims, not just the app name.

2019 · MOBILE · found by Facebook

Facebook v. LionMobi and JediMobi

Click injection against Facebook's audience network · Amount not disclosed; Facebook refunded affected advertisers (Facebook, 2019)

How it worked. According to Facebook's lawsuit, the developers' apps generated fake clicks on Facebook ads shown on users' phones, making it look as though the users had clicked and earning payouts for installs and clicks they did not drive.

What happened. Facebook banned the developers from its ad network in March 2019, refunded advertisers and sued in August 2019; Google suspended the developers' Play accounts.

The lesson. Platforms increasingly use lawsuits, not only blocklists, to deter fraud.

2019 · MOBILE · found by White Ops (now HUMAN) Satori team

TERRACOTTA

Android apps turning phones into hidden ad-loading browsers · Tens of thousands of Android devices and hundreds of apps (White Ops, 2019)

How it worked. Apps on Google Play promised free goods such as shoes or coupons. After installation they ran a hidden browser in the background that loaded ads and generated fraudulent impressions from real consumer devices.

What happened. White Ops shared its findings with Google, which removed the apps and updated Play Protect.

The lesson. Fraud on real devices defeats simple datacenter filtering; behaviour-based fraud detection is needed.

2018 · MOBILE · found by Kochava, reported by BuzzFeed News

Cheetah Mobile and Kika install-attribution fraud

Click injection to steal app-install bounties · Eight popular Android apps with about 2 billion combined downloads were implicated (BuzzFeed News, 2018)

How it worked. App-install ads pay whichever partner "caused" the install. The implicated apps watched for new app downloads on the phone and fired a last-second fake click, so they got credit and payment for installs they did not drive.

What happened. Google investigated and removed some of the apps from Play and its ad networks; the companies disputed parts of the findings. The case pushed MMPs to add click-injection filters.

The lesson. In attribution, "last click wins" rewards whoever clicks last, not whoever persuaded the user.

2018 · WEB · found by White Ops (now HUMAN) and Google, with FBI and a coalition of security firms

3ve

Multi-scheme botnet: datacenter bots plus malware-infected home PCs, spoofing thousands of publishers · 1.7 million infected computers, 3–12 billion bid requests a day at peak, more than $30 million in profit for the operators (Google/White Ops, 2018)

How it worked. Three linked operations combined rented servers and malware on real people's computers (Kovter and Boaxxe) to load ads invisibly on counterfeit websites posing as real publishers. The mix of datacenter and residential traffic made it hard to spot.

What happened. In November 2018 the US Justice Department unsealed a 13-count indictment against eight people; the FBI seized 31 domains and 89 servers. Aleksandr Zhukov was convicted and sentenced to 10 years in 2021.

The lesson. Large frauds are only dismantled when platforms, verification firms and law enforcement share data; the case also showed buyers why ads.txt matters.

2017 · MOBILE · found by Check Point Research

Judy

Auto-clicking adware hidden in Android games · 41 apps from one Korean developer; an estimated 8.5–36.5 million downloads across all related apps (Check Point, 2017)

How it worked. Harmless-looking games on Google Play later received instructions from a remote server to open hidden web pages on the phone and click ads there. The phone owner saw nothing while the fraudsters collected ad revenue.

What happened. Google removed the apps after Check Point reported them.

The lesson. Clicks can come from real phones owned by real people who never saw the ad; device reputation alone is not enough.

2017 · WEB · found by Adform

Hyphbot

Malware botnet on home PCs generating fake traffic to spoofed domains · Hundreds of thousands of infected PCs, mainly in the US, UK, Canada and the Netherlands, and tens of thousands of spoofed domains (Adform, 2017)

How it worked. Malware on ordinary home computers quietly loaded web pages in the background. The traffic was labelled as coming from well-known publishers' domains, so buyers thought they were paying for premium placements.

What happened. Adform published its findings and shared them with the industry; the case was widely cited as a reason to adopt ads.txt, launched the same year.

The lesson. Residential IP addresses do not guarantee a human; the device itself can be hijacked.

2016 · WEB · found by White Ops (now HUMAN)

Methbot

Video ad fraud: datacenter bots posing as people on spoofed premium sites · An estimated $3–5 million in fraudulent revenue per day; 250,000+ spoofed URLs and 570,000+ bot IP addresses (White Ops, 2016)

How it worked. The operators ran automated browsers on servers in data centres and registered IP addresses so they looked like US home internet users. Those bots "watched" video ads on fake pages dressed up as famous publishers, faking mouse movements and logins to look human.

What happened. White Ops published the IP and domain lists so buyers could block them. Methbot's operators were later charged in the 3ve indictments, and ringleader Aleksandr Zhukov was sentenced to 10 years in US prison in 2021.

The lesson. An impression that claims to be from a premium site is not proof it was; verify the seller with ads.txt and filter data center traffic.