
NEW New report: We analyzed 200M ad clicks

We improve your ad performance by blocking click fraud and fake emails

Click fraud is costing advertisers billions in loses. Learn more here.

Click fraud is costing advertisers billions in loses. Learn more here.

Read our in-depth study by independent research firm Juniper Research.
Q1 showed that fraudsters can now use AI tools, user-hijacked devices, and even Google’s own Android app store to drain advertiser budgets at an unprecedented scale. We also saw how bad actors can create fraud environments for cheap and use hijacked devices to drive their invalid traffic.
Here’s the breakdown of the top ad fraud schemes reported.
Ad fraud schemes have always used hijacked devices to drive fraudulent traffic. But in January, mobile security firm Dr. Web uncovered a new type of scheme that added AI to the mix. They found a family of Android trojan apps that hijacked users’ devices and used invisible browsers to interact with apps in the background.
According to reports, the apps were hosted on Xiaomi’s official app store and distributed through Telegram channels, Discord servers, and third-party APK sites.
Once a user downloaded an infected app, the malware created a hidden browser running on a virtual screen invisible to the user. It used a TensorFlow machine learning model to visually scan the screen, identify ad elements, and click on them automatically.
A second mode let the fraudsters stream a live video feed, click on elements, and enter text on the hidden browser. The report doesn’t specify how this mode was used for ad fraud, but manual control of a device like this would be challenging for ad platforms to filter as invalid traffic.
Each interaction on the target site looks legitimate because it came from a real device. But it’s all invalid traffic that will never convert.
Another Android-based fraud operation was shut down in February, this time by Google and Integral Ad Science. Reports show that the operation had been running silently across over 25 million customer devices through late 2025.
Dubbed “Genisys,” the scheme was spread through more than 115 utility mobile apps (calculators, PDF readers, etc.). Once installed, each app contained a secret in-app browser that ran silently in the background, pushing traffic to programmatic ads on nearly 500 AI-generated domains. The Genisys scheme used app bundle ID spoofing to stay hidden and falsely attributed its traffic to legitimate apps like Netflix and Instagram. We found similar spoofing tactics when we analyzed 200 million clicks for ad fraud patterns.
One key detail with the Genisys scheme: Every visit from a hijacked device was counted as legitimate traffic and billed to advertisers. After Google and IAS intervened, bid request volume from the affected apps dropped by more than 95%. That shows how much fraudulent traffic flowed through a handful of compromised devices.
The AutoBait scheme gives some context on the economics of AI ad fraud operations we see today. Before getting disbanded, AutoBait was a network of more than 200 domains, each presenting as an independent lifestyle blog. Every article and image on the sites was AI-generated but tweaked to look as authentic as possible.
Double Verify uncovered the scheme and estimated each page costs less than $2.25 to produce and could host dozens of ad banners, refreshed every few seconds. Each of these ad slots is sold to real advertisers who have no knowledge of the host website or traffic quality.
We see from AutoBait just how lucrative this kind of ad fraud can be for bad actors. For $2.25 per page, they can create hundreds of ad-serving opportunities, all primed to drain your budgets. Worse, fraudsters can create hundreds of these sites faster than anyone can take them down.
– Mike Schrobo, Founder and CEO of Fraud Blocker
Ad fraud is cheaper to run and harder to detect. Networks of fake blog sites now cost just a few dollars per page to create, yet each one can host dozens of ad slots that all bill advertisers.
Additionally, AI-powered malware can now mimic human click patterns well enough to evade sophisticated filters. Both of these factors increase the odds that your ads will get shown to fake users.
A reliable way to protect your budget is click fraud prevention software like Fraud Blocker. Our solution analyzes every click on your ads and blocks invalid traffic before it drains your budget. Try it free for 7 days.
ABOUT THE AUTHOR
Matthew is the resident content marketing expert at Fraud Blocker with several years of experience writing about ad fraud. When he’s not producing killer content, you can find him working out or walking his dogs.
Matthew is the resident content marketing expert at Fraud Blocker with several years of experience writing about ad fraud.


