Invalid traffic & fraud
Click injection
Click injection is mobile ad fraud where a malicious app detects another app being installed and fires a fake ad click just before the install completes, stealing the credit.
In app marketing, the ad network credited with the last click before an install usually gets paid (see attribution). Click injection hijacks that rule. A bad app already on the phone, often a flashlight or cleaner app, notices when the user starts installing something else, then quickly sends a fake click on behalf of a fraudulent source. The real install, which the user chose organically or because of a different ad, is credited to the fraudster.
The mechanism relies on the phone broadcasting install activity to other apps, which is why it historically affected Android most. Google's Play Install Referrer API gives MMPs timestamps for when the click happened and when the install started, so a "click" logged after the download began is a strong signal.
The classic detection signal is click-to-install time (CTIT): a real user needs time to see an ad, visit the store and download, but injected clicks show abnormally short gaps, often a few seconds. Injection is classed as attribution fraud and SIVT. It is different from click spamming, which floods clicks hoping to get lucky, and shows long, flat CTIT distributions instead.
Think of it like this
It is like someone standing at the checkout who, just as you pay, shouts "I recommended this shop to them!" and pockets the referral bonus.
An example
An MMP sees 12,000 installs from one network in India where 70% of clicks arrive less than 10 seconds before the install begins, compared with a typical spread of minutes to hours. The installs are rejected as injected.
Related terms
Click spamming
Click spamming, or click flooding, is sending huge numbers of fake ad clicks for devices that never saw an ad, hoping some later install organically so the spammer gets attribution credit.
Attribution fraud
Attribution fraud is manipulating how conversions are credited, so a fraudster claims payment for installs, sales or leads it did not actually cause, often by faking or timing clicks.
Install fraud
Install fraud is faking app installs, or stealing credit for real ones, so that advertisers pay cost-per-install fees for users who do not exist or would have installed anyway.
MMP (mobile measurement partner)
An MMP (mobile measurement partner) is an independent company that attributes app installs and in-app events to the ads and ad networks that drove them, and detects mobile install fraud.
App install campaign
An app install campaign is advertising designed to get people to download and install a mobile app, usually optimised and often paid per install or per post-install action.
Sources: AppsFlyer glossary: click injection, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)