Investigation reveals a network of 125+ Android apps and websites that are part of a massive ad fraud scheme; the apps were installed an estimated 115M+ times
straight up stolen by crooks! My latest investigation, and a thread: http://www.buzzfeednews.com/ ... Maria Chong / @mariachong : Wow. “... a single mobile app could generate $75 million a year in stolen ad revenue.” http://twitter.com/... Wilfred Hughes / @_wilfredh : A remarkable new scam: buy a smartphone app, record user interactions, and replay them with bots to fraudulently increase ad clicks and therefore revenue! https://www.buzzfeednews.com/ ... Seems very hard to detect, as it's using real user data to make bots appear human. Ivan Kozik / @ivankozik : “They then capture the behavior of the app's human users and program a vast network of bots to mimic it” https://www.buzzfeednews.com/ ... Joshua Lowcock / @joshuaumww : Great investigative report by @BuzzFeedNews on mobile bot ad fraud and useful reminder to be cautious about apps you use or if the ownership suddenly changes. https://www.buzzfeednews.com/ ... #AdFraud Ryan Moon / @ryanoneillmoon : Thanks for the great reporting @BuzzFeedNews - I'm fairly certain my company was affected by this Ad Fraud scheme. Google was not helpful when I tried to get refunded. We detected the fraud because of runaway costs in Search Partners traffic https://www.buzzfeednews.com/ ... Dan Gillmor / @dangillmor : Maybe this is one reason why street crime is down — easier to be a crook without leaving home. http://twitter.com/... Dieter Bohn / @backlon : Holy shit, this is super super devious. http://www.buzzfeednews.com/ ... http://twitter.com/... Craig Silverman / @craigsilverman : Exclusive: Android apps installed +100 million times tracked user behavior and used this data to create an army of bots — which stole millions of dollars from digital advertisers. This massive ad fraud scheme touched more than 125 apps and websites: https://www.buzzfeednews.com/ ... Lisa Tozzi / @lisatozzi : A @BuzzFeedNews investigation uncovered a sophisticated ad fraud scheme involving more than 125 Android apps and websites, some of which were targeted at kids. https://www.buzzfeednews.com/ ... Tripp Mickle / @trippmickle : iPhone XR “has the best feature-to-price ratio of any iPhone possibly ever, and given that Apple 's AAPL 0.61% lineup now has as many choices as the cereal aisle, that has never been more important” says @JoannaStern https://www.wsj.com/... See also Mediagazer
Context & Ripple Effects
This BuzzFeed News investigation extends a reporting thread that began when researchers flagged 41 Android apps from a single developer that fraudulently clicked ads in 2017. What changed here is scale and technique: instead of crude automated clicking, the 125+ apps and linked websites recorded genuine user interactions — including from apps aimed at children — and replayed them with bots so the traffic looked human.
The estimated 115M+ installs make this one of the largest app-based fraud networks exposed to date, and it set up the outlet's follow-up weeks later on 8 Play Store apps with 2B+ downloads, including seven from Cheetah Mobile, exploiting user permissions for ad revenue.
First-order effects
- Advertisers whose programmatic budgets flowed into these apps were paying for bot-replayed clicks rather than human attention, while the 115M+ users who installed the apps had their interactions captured without meaningful disclosure.
- Google faces immediate takedown and policy questions over how apps that record and replay user behavior passed Play Store review.
Second-order effects
- Ad buyers and verification vendors are pushed to treat behavioral realism as insufficient proof of humanity, raising scrutiny of install-heavy, low-engagement apps across the Play Store ecosystem.
- Legitimate developers relying on ad monetization inherit the distrust: networks tighten payouts and audits, squeezing revenue for honest apps in the same inventory pools.
Third-order effects
- If the pattern holds — from the 2017 click-fraud apps through this behavior-cloning network to later sweeps like the 85-app removal across both app stores — app-store economics shift toward continuous post-publication policing rather than one-time review.
- The recurring structure of these schemes points to a durable governance gap in third-party SDKs and permissions, where the same recording capabilities marketed for analytics become the raw material for fraud.
The trend: Mobile ad fraud is escalating from simple automated clicking toward schemes that clone real user behavior at fleet scale, forcing app stores and ad buyers into a permanent arms race over what counts as a human impression.