Ad tech stocks
TEAD0.60▲ +17.40%CDLX2.69▼ -8.67%PSKY9.52▼ -7.80%186013.51▲ +7.48%U43.15▲ +5.42%APP276.19▼ -4.90%LFTO15.29▼ -3.20%STGW8.38▲ +2.95%MNTN10.46▲ +2.85%APPS11.40▲ +2.75%SFOR44.85▼ -2.50%RDDT145.90▲ +2.43%ZETA32.33▲ +2.41%CCO2.40▲ +2.30%NFLX68.02▼ -2.25%OMC75.26▲ +2.21%TRU62.39▲ +2.08%INUV0.57▲ +2.02%WPP382.90▲ +1.81%DSP12.51▲ +1.62%GOOGL338.65▼ -1.58%ILLM0.66▲ +1.54%SIRI25.48▼ -1.53%AAPL328.26▼ -1.43%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%BIDU85.69▼ -1.36%SST2.58▼ -1.34%CART43.69▲ +1.32%035420191200.00▼ -1.29%4755681.70▼ -1.26%PUBM18.96▲ +1.23%SPOT493.31▲ +1.22%AZRN0.82▼ -1.20%ROKU150.64▼ -1.08%IHRT2.12▲ +0.95%TBLA3.33▼ -0.89%PUB95.34▲ +0.87%IBTA39.73▲ +0.84%NEXN8.93▼ -0.83%PINS18.75▼ -0.71%BABA106.92▼ -0.57%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%META729.03▲ +0.53%MGNI25.38▲ +0.48%SNAP5.42▲ +0.46%OUT27.64▼ -0.40%24331308.00▲ +0.38%TTD12.13▼ -0.37%RAMP37.65▲ +0.35%0700431.00▼ -0.23%PERI8.68▼ -0.17%DEC24.68▲ +0.16%CRTO15.21▲ +0.07%WBD30.93▼ -0.06%SNOW339.72▲ +0.05%CPNG13.87▼ -0.04%DV13.48▼ -0.04%43243564.00▲ +0.03%VER12.08▲ 0.00%
Ticker byClearTrust

Lesson 3 of 8 · 9 min read · intermediate

This lesson counts towards the ClearTrust Invalid Traffic & Ad Fraud certificate. Enrol with your email to record your progress and scores.Get certified, free

How bots fake humans

From data-center scripts to malware on your TV box: the tiers of bot sophistication, and how Methbot and 3ve faked billions of views.

A bot is just software that does something a person would normally do. Most bots on the internet are useful. The ones this lesson is about exist to be counted as audiences. To earn money they must pass as human at three moments: when the ad is requested, when it renders, and when anyone later checks the numbers. Each generation of detection has pushed fraudsters to build a more convincing disguise.

Picture a fake guest trying to get into an exclusive party. The crude version wears a paper mask and walks in with forty identical friends. A better version rents a real tuxedo. The best version quietly borrows the invitation, car and phone of a real guest who is asleep at home. Ad bots have evolved in exactly this order.

The five tiers of bot sophistication

Each tier costs more to run and is harder to detect. Tier 1 is GIVT; tiers 2 to 5 are mostly SIVT.
TierWhat it isHow it is usually caught
1. Simple scriptsPrograms on cloud servers that request pages and ads with no real browser at allGIVT: data-center IP lists, non-browser user agents, non-rendering checks
2. Headless browsersA real browser engine running without a screen (headless browser), able to execute ad scriptsInconsistencies in the browser environment, missing rendering, automation fingerprints
3. Disguised automationAutomated browsers on servers routed through residential proxies and fed forged device detailsSignal mismatches (time zone vs location vs language), device fingerprinting, proxy intelligence
4. Hijacked real devicesMalware on ordinary computers, phones and TV boxes loading hidden ads in the background (botnet)Population-level analysis, malware reverse-engineering, threat intelligence
5. Hybrid and humanClick farms, device farms, emulator farms and humans assisting botsBehavioural clustering, device-graph anomalies, investigations

Why residential proxies matter so much

The cheapest place to run a bot is a data center, but data-center IP ranges are published and filtered as GIVT. So fraud moved to borrowed home internet connections. A residential proxy routes traffic through someone's home broadband or mobile connection, so a bot in a server rack appears to be a person in Ohio, Berlin or Pune. Some proxy networks are built from apps whose users agreed, often in fine print, to share bandwidth. Others are built from malware: the BADBOX 2.0 operation, which you will meet in the CTV lesson, sold access to infected devices as a residential proxy service. For detectors, the IP address stops being proof of anything on its own.

Headless browsers and fake fingerprints

Modern ad measurement runs JavaScript inside the page to check the environment: screen size, fonts, graphics card, battery, touch support and dozens more properties. That bundle is a device fingerprint. A headless browser can run that JavaScript, and bot operators patch it to report plausible values. The weakness is consistency. Faking one property is easy. Faking hundreds of properties that must all agree with each other, with the user agent string, and with the network, across millions of sessions, is very hard. Detectors look for impossible combinations, such as an iPhone reporting a desktop graphics card.

Faking behaviour

Once the device looks real, the behaviour must look real too. Bots simulate scrolling, mouse movement, dwell time and clicks. Some even pick up tracking cookies by visiting retail and travel sites first, so that they look like valuable shoppers to audience-targeting systems and command higher prices. Behavioural analysis catches them statistically: real humans are messy, and a thousand "people" who scroll at identical speeds or only ever visit high-priced sites are not.

Anatomy of a bot fraud scheme

1/7
!Fraud ringwants ad money!Botnetinfected devices / servers!Residential proxieshide the servers▤Fake or spoofed siteslook premium⇄Resellers & SSPssell the traffic★Advertisers payfor nobody✓Detectionpatterns give it away
1
The goal: real money for fake views

An ad fraud ring earns money every time an ad is “shown”. It doesn’t need people, just traffic that looks like people.

  1. The goal: real money for fake views: An ad fraud ring earns money every time an ad is “shown”. It doesn’t need people, just traffic that looks like people.
  2. Build the audience: It runs a Botnet: malware-infected phones and PCs, or rented servers running automated browsers that load pages and scroll like humans.
  3. Hide where it comes from: Data-center traffic is easy to spot, so traffic is routed through residential proxies: home internet connections, often from people who don’t know their device is involved.
  4. Send it to “premium” pages: The bots visit sites that are fake, or that spoof famous publishers’ names in bid requests so the inventory looks valuable.
  5. Launder it through the supply chain: The impressions are sold through resellers and exchanges, sometimes mixed with real traffic (sourced traffic), until they look ordinary.
  6. Cash out: Advertisers pay for impressions nobody saw. The money flows back up the chain to the ring. At its peak, the Methbot operation was estimated to earn millions of dollars a day.
  7. Where it breaks: Scale is the fraudster’s weakness. Identical behaviour, impossible device mixes, ads.txt mismatches and IP patterns expose SIVT. Detection firms, platforms and law enforcement have taken down many such rings.

Case study: Methbot (2016)

In December 2016 the security firm White Ops (now HUMAN) exposed Methbot. It ran from hundreds of servers in data centers in the US and Amsterdam, used a custom-written browser, and made its traffic look residential with fraudulently registered IP addresses. It spoofed thousands of premium publishers: White Ops published 250,267 fake URLs across 6,111 domains. The firm estimated Methbot produced 200 to 300 million fake video impressions a day, earning $3 to $5 million daily. Methbot aimed at video because video CPMs were high.

Case study: 3ve (2018)

3ve (pronounced "eve") was the evolution. Its operators used a mix of data-center bots and malware (Kovter and Boaxxe) on real computers, spoofed domains and hijacked IP addresses. A coalition including Google, White Ops, Proofpoint and others mapped it, and on 27 November 2018 the US Department of Justice unsealed a 13-count indictment against eight defendants covering both schemes, alongside an FBI-led takedown of the botnet infrastructure. Aleksandr Zhukov, charged as the leader of Methbot, was later convicted in Brooklyn and sentenced to 10 years in prison.

1.7 millionInfected computers the US Justice Department said the 3ve operators accessed, causing businesses to pay more than $29 million for ads never seen by humans.Source: US Attorney's Office EDNY: Two international cybercriminal rings dismantled and eight defendants indicted

The human tier

Not every fake audience is software. Click farms and device farms, rooms full of real phones operated by low-paid workers or simple automation, have been documented across Asia and elsewhere. Human fraud is valuable because it defeats behavioural checks, but it is expensive, so it is usually reserved for high-value actions like app installs, sign-ups and social engagement. Purchased traffic from unvetted vendors often blends all five tiers together.

Key takeaways

  • Bots evolved from data-center scripts to headless browsers, disguised automation, hijacked real devices and hybrid human operations.
  • Residential proxies make a server look like a home user, so IP addresses alone prove little.
  • Detectors win on consistency: hundreds of device and behaviour signals must all agree, and fakes rarely manage it at scale.
  • Methbot (2016) and 3ve (2018) proved fraud could be industrial and prosecutable; the DOJ indicted eight defendants.

Questions people ask

How do bots click on ads?

Ad bots are programs, often running in headless browsers or as malware on real devices, that load web pages and apps, render ads and simulate human actions like scrolling and clicking. Sophisticated bots route traffic through residential proxies to hide their origin and fake device fingerprints to look like ordinary phones or computers. Detection vendors catch them by finding inconsistencies across many signals rather than any single tell.

What was Methbot?

Methbot was a video ad fraud operation exposed by White Ops (now HUMAN) in December 2016. It used servers in US and Amsterdam data centers, a custom browser and falsely registered IP addresses to fake 200 to 300 million video views a day on more than 6,000 spoofed premium domains, earning an estimated $3 to $5 million daily. Its alleged leader was later convicted in the US.

What is a residential proxy in ad fraud?

A residential proxy routes internet traffic through someone's home or mobile connection, so traffic from a server appears to come from an ordinary household. Fraudsters use them to get past data-center IP filters. Some proxy networks are built from infected devices, such as the BADBOX 2.0 TV boxes. Because of this, detectors combine IP data with device, behaviour and supply-chain signals.

Previous: GIVT vs SIVT: the two kinds of invalid trafficNext: Spoofing: fake websites, apps and devices