Ad tech stocks
TEAD0.59▲ +15.48%CDLX2.66▼ -9.52%PSKY9.55▼ -7.55%186013.51▲ +7.48%U43.11▲ +5.33%APP276.30▼ -4.87%LFTO15.22▼ -3.67%RDDT146.56▲ +2.89%STGW8.38▲ +2.89%MNTN10.46▲ +2.85%ZETA32.39▲ +2.60%APPS11.38▲ +2.52%OMC75.48▲ +2.52%SFOR44.85▼ -2.50%CCO2.40▲ +2.34%TRU62.49▲ +2.24%NFLX68.05▼ -2.21%SST2.56▼ -2.19%INUV0.57▲ +2.02%WPP382.90▲ +1.81%DSP12.53▲ +1.79%SIRI25.48▼ -1.56%ILLM0.66▲ +1.54%SAX35.96▲ +1.41%GOOGL339.24▼ -1.41%CART43.73▲ +1.40%SCOR4.75▲ +1.39%AAPL328.56▼ -1.34%SPOT493.82▲ +1.32%035420191200.00▼ -1.29%4755681.70▼ -1.26%BIDU85.81▼ -1.21%AZRN0.82▼ -1.20%PUBM18.95▲ +1.17%ROKU150.63▼ -1.08%IHRT2.12▲ +0.95%PUB95.34▲ +0.87%NEXN8.93▼ -0.78%SNAP5.44▲ +0.74%TBLA3.33▼ -0.74%META730.31▲ +0.71%IBTA39.65▲ +0.63%PINS18.78▼ -0.58%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%CRTO15.28▲ +0.53%BABA107.12▼ -0.39%24331308.00▲ +0.38%RAMP37.65▲ +0.33%MGNI25.34▲ +0.32%0700431.00▼ -0.23%PERI8.67▼ -0.23%TTD12.14▼ -0.21%CPNG13.89▲ +0.18%DEC24.68▲ +0.16%OUT27.70▼ -0.16%DV13.48▼ -0.07%SNOW339.77▲ +0.06%WBD30.94▼ -0.03%43243564.00▲ +0.03%VER12.08▲ 0.00%
Ticker byClearTrust

IVT master

The hard one. Twelve questions on MRC's GIVT and SIVT rules, SSAI spoofing, click injection versus click spamming, and the landmark cases from Methbot to BADBOX. advanced · 12 questions

Question 1 of 12Score 0

Per the MRC IVT guidelines, what fundamentally separates SIVT from GIVT?

All questions with answers
  1. Per the MRC IVT guidelines, what fundamentally separates SIVT from GIVT?
    Answer: GIVT is caught with routine filtration such as lists and standard checks; SIVT needs advanced analytics, multi-point corroboration or significant human intervention. The MRC IVT guidelines define the split by how hard detection is. GIVT yields to lists and parameter checks; SIVT needs deeper analysis. Intent is not the test: much GIVT is innocent, and not every SIVT case is prosecuted.
  2. Traffic comes from a cloud-hosting IP range that appears on a published data-center list. How is it normally classified?
    Answer: GIVT, because it is identified through a standard list. Known data center traffic matched against a list is a standard GIVT category. The same bots routed through residential proxies would need SIVT-grade detection, which is exactly why fraudsters do it.
  3. Which of these sits on the MRC's SIVT side?
    Answer: Adware on a person's PC that opens hidden browser windows to load ads. Hijacked devices, adware and malware are named SIVT categories. The other three are routine GIVT filters, such as the IAB/ABC Spiders & Bots List and irregular user agent checks.
  4. Why is SSAI spoofing effective against naive CTV filters?
    Answer: Genuine SSAI requests already come from a few server IPs, so data-center origin is not a red flag, and the forwarded device IP and user agent can be forged. In SSAI, a stitching server calls the ad server on behalf of each TV and passes device details in headers. SSAI spoofing fakes that server and invents the devices, so buyers need signed or verified server lists, not IP checks alone.
  5. An Android campaign shows many installs whose click-to-install time is under 10 seconds. Which scheme does that point to?
    Answer: Click injection. In click injection, a malicious app detects an app being installed and fires a fake click just before first open, stealing last-click credit. The tell is implausibly short click-to-install times; click spamming produces the opposite, long and flat timing.
  6. Which pattern is the classic signature of click spamming?
    Answer: Huge click volumes, very low click-to-install conversion and installs spread evenly over days, which quietly claims credit for organic installs. Click spamming fires masses of clicks for people who never saw an ad, hoping some later install organically so the network gets credit. Short timing is click injection; spamming is a volume game.
  7. What made Methbot, exposed by White Ops (now HUMAN) in 2016, distinctive?
    Answer: Data-center servers ran fake browsers that watched video ads on spoofed premium domains, reportedly earning $3–5 million a day. Methbot faked both the audience and the inventory: data-center bots with falsely registered residential-looking IPs, plus domain spoofing of thousands of premium sites. Its ringleader was later convicted in the US. See bot traffic.
  8. What was 3ve, taken down in 2018?
    Answer: A multi-part operation using botnets of infected home PCs (such as Kovter and Boaxxe) plus data-center servers, disrupted with help from the FBI, Google and White Ops. 3ve blended a botnet of roughly 1.7 million infected computers with data-center infrastructure, so its traffic came from real residential IPs. It showed that residential IPs are not proof of a human.
  9. How did VASTFLUX, disrupted by HUMAN in 2022, make money?
    Answer: It won in-app banner slots, then injected code that stacked many hidden video ads behind the visible one while spoofing app IDs. VASTFLUX abused VAST video tags for ad stacking and app spoofing, peaking at over 12 billion bid requests a day across about 1,700 spoofed apps. The creative itself was the attack vehicle, a reminder that malvertising can also be fraud.
  10. What set the BADBOX and BADBOX 2.0 operations apart?
    Answer: Cheap Android-based TV boxes and other devices shipped with, or picked up, backdoor malware, enrolling over a million devices into ad fraud and residential proxy schemes. BADBOX showed fraud built into the supply chain of the hardware itself; the FBI issued a public warning about BADBOX 2.0 in 2025. Infected devices serve as residential proxies and run hidden ads, so their traffic looks like real homes. See CTV fraud.
  11. A bot passes user-agent checks and moves the mouse along human-like curves. What is most likely to catch it?
    Answer: Cross-checking signals for inconsistencies, such as a claimed iPhone exposing a desktop GPU or a timezone that contradicts IP location, corroborated across many events. Sophisticated bots imitate any single signal well but struggle to keep every signal consistent. Device fingerprinting plus behavioral analysis at scale is how SIVT is found; list lookups only catch declared bots.
  12. What does a traffic quality score such as ClearTrust's TQI Score summarise?
    Answer: The combined verdict of many detection checks, such as 150+ filters for bots, fake clicks and fake impressions, into one quality rating for a traffic source. A TQI Score™ rolls many fraud detection signals into one comparable number for a source or campaign. It complements, rather than replaces, the raw IVT rate and viewability figures behind it.