Ad tech stocks
TEAD0.60▲ +18.12%CDLX2.72▼ -7.48%186013.51▲ +7.48%PSKY9.57▼ -7.36%U43.06▲ +5.20%APP276.27▼ -4.88%LFTO15.25▼ -3.48%MNTN10.47▲ +3.00%STGW8.35▲ +2.58%RDDT146.07▲ +2.55%SFOR44.85▼ -2.50%OMC75.38▲ +2.38%CCO2.40▲ +2.34%APPS11.36▲ +2.34%TRU62.53▲ +2.31%NFLX68.02▼ -2.25%ZETA32.28▲ +2.25%SST2.56▼ -2.19%INUV0.57▲ +2.02%WPP382.90▲ +1.81%DSP12.53▲ +1.79%SIRI25.45▼ -1.64%ILLM0.66▲ +1.54%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%AAPL328.66▼ -1.31%035420191200.00▼ -1.29%GOOGL339.68▼ -1.28%4755681.70▼ -1.26%BIDU85.81▼ -1.22%AZRN0.82▼ -1.20%ROKU150.49▼ -1.18%NEXN8.89▼ -1.17%PUBM18.93▲ +1.09%SPOT492.56▲ +1.06%TBLA3.33▼ -1.04%SNAP5.46▲ +1.02%IHRT2.12▲ +0.95%PUB95.34▲ +0.87%CART43.48▲ +0.83%PINS18.77▼ -0.64%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%MGNI25.40▲ +0.55%META728.54▲ +0.46%24331308.00▲ +0.38%IBTA39.55▲ +0.38%BABA107.16▼ -0.35%RAMP37.63▲ +0.29%PERI8.66▼ -0.29%TTD12.13▼ -0.29%0700431.00▼ -0.23%CRTO15.23▲ +0.23%OUT27.68▼ -0.23%DEC24.68▲ +0.16%SNOW340.10▲ +0.16%CPNG13.88▲ +0.11%DV13.48▼ -0.07%WBD30.93▼ -0.06%43243564.00▲ +0.03%VER12.08▲ 0.00%
Ticker byClearTrust

Invalid traffic & fraud

Botnet

A botnet is a network of computers, phones or smart devices infected with malware and remotely controlled by criminals, often used to generate fake ad impressions and clicks from real consumer devices.

The short answer, from the AdTech Sumo glossary

A botnet is a crowd of hijacked machines taking orders from one operator. The owners usually have no idea; their laptop, phone, router or cheap streaming box quietly runs hidden tasks in the background.

For ad fraud, botnets are valuable because the traffic comes from real homes, real IP addresses and real devices, so it sails past simple data center traffic filters. Malware may open invisible browser windows, load ad-heavy pages, click ads or hijack an app's ad calls. The 3ve operation, disrupted in 2018 by the FBI and industry partners, used infected computers in this way; separately, the US Department of Justice described the 911 S5 botnet it dismantled in 2024 as having used some 19 million IP addresses as proxies. HUMAN's research on BADBOX 2.0 in 2025 described off-brand Android TV boxes shipped with ad-fraud malware preinstalled.

Because individual devices look legitimate, detection relies on SIVT techniques: spotting coordinated behaviour across many devices, hidden rendering, impossible activity at odd hours and infection signatures. Botnet traffic is classified as SIVT under the MRC IVT guidelines ("hijacked devices" and adware).

Think of it like this

A botnet is like someone secretly copying thousands of house keys and using the houses at night to host fake parties, so the neighbourhood looks lively while the owners sleep.

An example

A detection vendor notices 150,000 home PCs in Germany, Mexico and Indonesia all loading the same 40 obscure recipe sites in hidden windows between 1 and 4 a.m. local time, a hallmark of malware-driven browsing.

Related terms

Sources: MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update), TAG: fighting malware