Invalid traffic & fraud · also called Replay attack, server-to-server install fraud
SDK spoofing
SDK spoofing is mobile ad fraud in which fabricated install or in-app event messages, mimicking a real measurement SDK, are sent straight to attribution servers without any real device or user.
An app's measurement SDK reports installs and events to an MMP over the internet. SDK spoofing forges those reports. Fraudsters study the traffic a legitimate SDK sends, then generate look-alike messages from servers, complete with believable device models, OS versions and timestamps, so the MMP records installs that never happened.
Because there is no phone, no store download and no user, SDK spoofing can produce enormous volumes cheaply, and it can fake post-install events (registrations, purchases) to defeat advertisers who pay on deeper KPIs. It is install fraud and SIVT.
Defences focus on proving that a message came from a genuine SDK in a genuine app. MMPs have introduced signed or hashed SDK payloads with secrets embedded in the app, server-side validation of app-store purchase receipts, and cross-checks against store download data. Red flags include installs with no matching store activity, events that arrive in impossible sequences and bursts of "new" devices from a small set of IPs. Compare click injection, which piggybacks on real installs, and emulator farms, which at least run the app somewhere.
Think of it like this
SDK spoofing is like forging a stack of signed delivery receipts without ever sending a van out: the paperwork looks perfect, but no parcel moved.
An example
A game studio pays per install plus a bonus for players who reach level 10. It notices 8,000 installs from one source whose "level 10" events arrive exactly 11 minutes after install every time and have no matching App Store downloads; signed SDK messages later confirm they were forged.
Related terms
Install fraud
Install fraud is faking app installs, or stealing credit for real ones, so that advertisers pay cost-per-install fees for users who do not exist or would have installed anyway.
MMP (mobile measurement partner)
An MMP (mobile measurement partner) is an independent company that attributes app installs and in-app events to the ads and ad networks that drove them, and detects mobile install fraud.
SDK (software development kit)
An SDK (software development kit) is a package of pre-built code developers add to apps to provide features, such as showing ads, measuring installs or analytics, without building them.
Attribution fraud
Attribution fraud is manipulating how conversions are credited, so a fraudster claims payment for installs, sales or leads it did not actually cause, often by faking or timing clicks.
Emulator farm
An emulator farm is a set of servers running many software-simulated phones or TVs, used to fake app installs, ad views and engagement at scale without real devices.
Sources: AppsFlyer glossary: SDK spoofing, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)