Lesson 5 of 8 · 10 min read · intermediate
Mobile app and CTV fraud
Click injection, SDK spoofing, SSAI spoofing and backdoored TV boxes: how fraud works in apps and on TVs, told through ICEBUCKET, VASTFLUX and BADBOX.
Web fraud grew up in browsers, where measurement scripts can inspect the page. Apps and TVs are different. Code runs inside closed environments, ads are often stitched in by servers, and measurement relies on signals the device or the server chooses to report. That makes mobile and CTV the two richest hunting grounds for fraud, and the channels where the biggest recent schemes lived.
On the web, a verification vendor is like an inspector standing inside the shop. In apps and on CTV, the inspector often has to stand outside and read a report the shopkeeper slips under the door. If the report is forged, the inspector may never know, unless they compare it with thousands of other reports and spot the pattern.
Part 1: mobile app install fraud
App marketers often pay per install. A mobile measurement partner (MMP) decides which ad network "caused" each install, usually by last click, and that network gets paid. Much mobile fraud is therefore attribution fraud: stealing credit for installs that would have happened anyway, or inventing installs outright.
| Scheme | Mechanism in brief | What catches it |
|---|---|---|
| Click spamming | Firing huge numbers of fake clicks for users who never clicked, hoping to be the last click before a natural install | Very low click-to-install rates; installs spread evenly long after the "click" |
| Click injection | A malicious app on the same Android phone detects a new app being installed and fires a click just before it opens, stealing the credit | Click-to-install time of a few seconds; install-referrer timestamps |
| SDK spoofing | Server-generated fake install and in-app events that imitate a real app's measurement SDK, with no device involved | Cryptographic signing of SDK messages; impossible device data |
| Install farms | Real or emulated devices installing and opening apps at scale, sometimes resetting their IDs | Device-ID resets, emulator signals, identical behaviour clusters |
Inside apps, ad fraud also includes hidden ads loaded in the background and stacked ads. The largest known example is VASTFLUX, disrupted by HUMAN and disclosed in January 2023. Malicious code hidden in in-app banner ads on iOS stacked dozens of invisible video ads behind the visible banner, and each counted as a view. It used the VAST video standard and "fast flux" network evasion, which gave it its name.
Part 2: CTV and the SSAI problem
On many streaming services, ads are not fetched by the TV. A server stitches the ad into the video stream using server-side ad insertion (SSAI), which makes playback smooth. The side effect is that the ad server and measurement vendors see a request from the SSAI server, not the TV. The server passes along the viewer's IP address and device details in HTTP headers so the impression can be targeted and counted. Those headers are just text.
SSAI spoofing is the fraud this enables: servers pretend to be SSAI servers and invent the viewers behind them, forging household IP addresses, app IDs and device IDs, while no video or ad is ever delivered to anyone. The MRC explicitly lists SSAI spoofing as SIVT.
How a CTV ad reaches your TV
You are watching a show in a streaming app. An ad pod (a break of several ads) is due.
- An ad break is coming: You are watching a show in a streaming app. An ad pod (a break of several ads) is due.
- The server asks for ads on the TV’s behalf: With SSAI, a server, not the TV, requests the ads. It passes along the TV’s IP address and device details in the VAST request.
- The pod is sold: Buyers bid for the slots. CTV prices are high because the screen is big and the viewer is often a whole household.
- Stitched into the stream: The SSAI server stitches the ads into the video so they play smoothly, like broadcast TV. Great for viewers, but the buyer never talks to the TV directly.
- The fraud: SSAI spoofing: Because requests come from servers, a fraudster can run a server that pretends to be SSAI for millions of TVs that are not watching anything. This is SSAI spoofing. Schemes like this have faked huge volumes of requests.
- The defence: Buyers verify that SSAI servers are known and certified, check that device signals are consistent, and use standards and signed identifiers to prove a real device requested the ad.
- ICEBUCKET (sometimes written ICEBUCKER): disclosed by White Ops in April 2020 after building through 2019. At its January 2020 peak it sent 1.9 billion ad requests a day, impersonating about two million people in 30 countries, and at peak made up 28% of the programmatic CTV traffic White Ops could see.
- StreamScam: exposed by Oracle's Moat in December 2020. Servers sent fake impression events while spoofing 28.8 million valid US household IP addresses, about 3,600 apps and 3,400 CTV device models; the scheme reportedly took more than $14 million before it was stopped.
- PARETO: disclosed in 2021 (covered in the spoofing lesson), where phones posed as TVs rather than servers posing as SSAI.
Part 3: the fraud that ships in the box
The newest frontier is hardware. In 2023, HUMAN described BADBOX: cheap, off-brand Android TV boxes, phones and tablets sold online and in shops that came with a backdoor installed in the firmware before they reached buyers. About 74,000 devices were found in the first cluster, and one of the downloaded modules, PEACHPIT, ran an ad fraud scheme that HUMAN said peaked at 9 billion bid requests a day.
In March 2025 HUMAN and partners disclosed BADBOX 2.0, with more than one million infected consumer devices, over a third of them observed in Brazil. The devices loaded hidden ads, committed click fraud and were rented out as residential proxies. Google, HUMAN, Trend Micro and the Shadowserver Foundation sinkholed part of the infrastructure, the FBI issued a public warning in June 2025, and in July 2025 Google filed a lawsuit against the alleged operators describing a network of more than 10 million devices.
How buyers defend these channels
- Demand signed SSAI trafficPrefer supply where SSAI providers are identified and verifiable, and where the IAB Tech Lab's guidance on passing device information is followed consistently.
- Check app-ads.txt and store listingsOnly buy apps that are listed in the relevant app store and authorised through app-ads.txt, and check the CTV app actually exists on the platform claimed.
- Use in-app measurement standardsThe Open Measurement SDK gives verification vendors a common, consistent view inside apps rather than relying only on server reports.
- Watch the numbers that cannot lieImpossible household counts, one IP streaming on hundreds of "TVs", 3 a.m. prime-time peaks and completion rates of exactly 100% are all red flags in CTV fraud.
Key takeaways
- Mobile fraud mostly targets attribution: click spamming, click injection, SDK spoofing and install farms steal credit for installs.
- SSAI makes the server, not the TV, request ads, so SSAI spoofing can invent viewers who never existed (ICEBUCKET, StreamScam).
- VASTFLUX hid stacked video ads inside in-app banners, peaking at 12 billion ad requests a day according to HUMAN.
- BADBOX and BADBOX 2.0 showed fraud can be pre-installed in cheap devices and double as residential proxy networks.
Questions people ask
What is SSAI spoofing?
SSAI spoofing is CTV ad fraud in which fraudsters' servers pretend to be server-side ad insertion (SSAI) servers and invent the viewers behind them, forging household IP addresses, app IDs and device IDs in the ad requests. No ad is shown to any person. It works because SSAI traffic naturally comes from servers. ICEBUCKET and StreamScam were major examples, and the MRC lists SSAI spoofing as SIVT.
What is click injection?
Click injection is a mobile install-fraud technique in which a malicious app on an Android phone detects that another app is being installed and fires a fake ad click just before the new app is first opened. Last-click attribution then credits the fraudster for an install they did not cause. Mobile measurement partners detect it by analysing very short click-to-install times and install-referrer timestamps.
What is BADBOX 2.0?
BADBOX 2.0 is a fraud and residential-proxy operation disclosed by HUMAN and partners in March 2025, built on more than a million cheap, off-brand Android TV boxes, projectors and tablets that were infected with backdoors, many before sale. The devices loaded hidden ads, committed click fraud and relayed criminal traffic. The FBI issued a warning in June 2025 and Google sued alleged operators in July 2025.