ReflectEditorial
/boostCMSStart free
Home/Blog/Fraud Defense
Fraud Defense·10 min read·Published September 9, 2026

The Mobile Ad Fraud Defense Playbook: Click Flooding, Fake Installs, and Sub-Publisher Poisoning

How bad actors siphon billions in UA budgets and the real-time cryptographic techniques modern MMPs use to block fraudulent clicks before attribution.

Key Executive Takeaways
  • Mobile ad fraud consumes an estimated $5.4 billion annually in paid user acquisition spend, targeting performance marketers across gaming, fintech, delivery, and e-commerce.
  • Click Flooding (Click Spamming) sends millions of synthetic clicks to hijack organic installs. It can be diagnosed by analyzing Click-to-Install Time (CTIT) distributions.
  • Install Hijacking (Click Injection) monitors Android broadcast intents to inject a fraudulent click milliseconds before an app finishes downloading, stealing the attribution credit.
  • Sub-Source / `af_siteid` Laundering: Rogue ad networks hide fraudulent publisher sub-IDs behind generic aggregators. Real-time sub-source monitoring is essential to isolate toxic supply paths.
  • In-Memory Pre-Attribution Defense: Rejecting fraud after attribution still incurs postback pollution and reporting disputes. Reflect blocks invalid clicks at the edge before attribution occurs.

The Industrialization of Mobile Ad Fraud

Mobile ad fraud is no longer the work of isolated script kiddies running emulator macros on desktop PCs. Today, it is an organized, multi-billion-dollar shadow economy operated by sophisticated syndicates leveraging real device farms, resident proxy networks, and hijacked SDK libraries embedded in utility apps.

When growth marketers evaluate partners purely on reported Cost Per Install (CPI) rather than down-funnel retention and verified ROAS, they inadvertently create an economic incentive for fraudulent publishers to steal organic attribution.

$5.4B
Fintech and Gaming apps experience the highest attack rates
Estimated global marketing budget lost to mobile ad fraud annually

In this playbook, we dissect the four most damaging mobile ad fraud vectors and detail the cryptographic defense mechanisms implemented in Reflect's real-time engine.


1. Click Flooding (Click Spamming)

How It Works:

Click Flooding targets organic and high-intent users. A fraudulent app (often a torch, VPN, cleaner, or free utility app) running in the background generates hundreds of silent, invisible HTTP clicks for popular App Store apps while the user is actively using their phone.

When that user later decides organically to download one of those apps, the MMP checks its attribution database and finds a recent click from the rogue publisher. Because last-touch attribution rules credit the most recent click, the rogue network steals credit for an organic install!

Diagnosis: The CTIT Distribution Curve

A healthy, legitimate paid ad campaign exhibits a log-normal Click-to-Install Time (CTIT) distribution:

  • 0–15 seconds: Very few installs (users need time to reach the App Store and download the binary).
  • 1–3 minutes: Peak install volume (normal Wi-Fi / 5G download and open time).
  • > 2 hours: Steady, exponential decay.

In a Click Flooding attack, the CTIT curve is unnaturally flat: clicks are evenly distributed across 4, 8, 12, and 24 hours because the clicks were generated randomly long before the user initiated the install.

Healthy Campaign CTIT:
Installs │      ▲
         │     ╱ ╲
         │    ╱   ╲
         │   ╱     ╲________
         └──────────────────────> Time (0m -> 2h)

Click Flooding Attack:
Installs │  ──────────────────── (Flat across 24h)
         └──────────────────────> Time (0m -> 24h)

2. Install Hijacking (Click Injection)

How It Works:

Install hijacking is specific to Android. When a user begins downloading an app from the Google Play Store, Android broadcasts an intent: ACTION_PACKAGE_ADDED or download progress notifications.

A malicious app installed on the user's phone listens for this broadcast. The millisecond the download initiates, the rogue app fires a click through an ad network API. By the time the user opens the newly installed app, the fraudulent click is registered as the "last click," stealing attribution from the legitimate ad that drove the download.

How Reflect Neutralizes Install Hijacking:

Reflect inspects the Google Play Install Referrer API timestamps:

  • install_begin_timestamp_seconds
  • referrer_click_timestamp_seconds

If the click timestamp occurred after the install download began, Reflect's ingestion filter automatically drops the click and flags the partner for malicious injection.


3. Fake Installs and Automated Device Farms

Modern device farms use automated racks of physical Android devices running custom ROMs that randomize:

  • IMEI / MEID
  • Android ID / Google Advertising ID
  • Battery state, accelerometer sensor noise, and screen brightness
  • IP addresses via residential 4G/5G mobile proxies (SOCKS5 rotating proxies)

These bots execute scripted post-install actions (e.g., reaching Tutorial Level 3 or signing up for a trial) to bypass naive engagement heuristics.

⚠️ Caution & Risk

The Device Telemetry Check: True human devices generate natural sensor drift, fluctuating battery temperatures, and realistic touch coordinates. Automated farms show robotic touch paths and static device physics.

Reflect's SDK captures low-level hardware entropy indicators (without accessing sensitive user data) to verify that the runtime environment is an authentic, untampered physical device.


4. Sub-Publisher / af_siteid Laundering

One of the dirtiest secrets of ad networks is sub-source masking. A network will deliver 10,000 installs under a single transparent label like Partner_X, but behind the scenes, that network buys traffic from 500 unvetted third-party affiliate sub-sources (sub_id, site_id, or AppsFlyer's af_siteid).

When fraud is detected on Sub-Publisher #49, the network simply changes the sub-ID string to #50 tomorrow while continuing to charge you full CPI.

Reflect's Sub-Source Transparency Framework:

Reflect tracks performance, conversion rate, CTIT variance, and chargeback rates at the granular sub-source level.

  • Automated blocking of toxic sub-publishers without pausing the broader campaign.
  • Real-time CVR anomaly alerts when a sub-source displays a 0.02% or 95% conversion rate.

5. Architectural Defense: Edge-Native Pre-Attribution Blocking

Most legacy MMPs evaluate fraud as a "post-processing" audit script that runs hours after the install. This has disastrous consequences:

  1. The postback has already been delivered to the ad network.
  2. The ad network algorithm uses the fraudulent conversion to optimize future spend.
  3. You are forced into weeks of frustrating billing reconciliation disputes with network reps.

Reflect shifts fraud evaluation to the Edge Doorway:

Ad Click ──> Reflect Global Edge Fabric ──> [In-Memory Anomaly Rules]
                                                    │
                                     ┌──────────────┴──────────────┐
                                     ▼                             ▼
                            [PASS: Clean Click]           [BLOCKED: Invalid/Bot]
                                     │                             │
                            Processed into DO             Written to Evidence Log
                            Attribution Ledger            Zero D1 Pollution

Instantly eliminate wasted budget, protect your organic baselines, and guarantee that every dollar of UA spend drives verified, incremental growth.

Explore our Deterministic Attribution Guide and see how Reflect's Transparent Pricing keeps measurement honest.

Marcus Vance

Written by Marcus Vance

Principal Security Researcher

12+ years in mobile telemetry and botnet analysis. Former cybersecurity consultant to major global banking and fintech apps.

Scale Your Mobile App With Sub-Linear Pricing

Eliminate enterprise MMP lock-in. Real-time deterministic matching, full SKAN 4 & AdAttributionKit support, and sub-penny pricing at scale.