STA 045° · GROWTH & UA

The Mobile UA Fraud Playbook: How Operators Detect Emulator Farms, Click Injection and Fake Installs

June 17, 202610 min readBy AllAspect

Mobile ad fraud is not an edge case; on open programmatic exchanges it is a line item. The fraud is designed to look exactly like the KPI you optimize for, which is why detection has to be structural rather than intuitive.

The playbook below still works. But an operator running it unchanged in 2026 will pass a lot of fraud, because the dominant technique has shifted from manipulating signals around a real install to fabricating the install entirely — and fabricated traffic does not produce the anomalies the classic detection stack was built to find.

The shift that broke the old playbook

AppsFlyer's 2026 State of Ad Fraud report identifies spoofing as the fastest-growing fraud technique of 2025, with spoofed installs outpacing overall install growth every quarter between Q3 2025 and Q1 2026.

The distinction matters operationally. Hijacking steals credit for an install that was going to happen anyway. Spoofing fabricates everything from scratch — devices, users, in-app events — engineered to mimic real device fingerprints and behavioral sequences. AppsFlyer notes the specific danger plainly: because spoofing generates clean-looking signals rather than anomalies, it is the fraud type most likely to be undercounted in any dataset, including the one underpinning their own report.

The category-level numbers reflect the same shift. Per that report, fake installs now account for 87% of detected fraud on Android and 92% on iOS — hijacking is no longer where the money is. Store validation fraud, which fabricates app store receipts, made up as much as 73% of detected iOS fraud in 2025, falling to 51% by Q1 2026 not because volume dropped but because fraudsters began combining fabricated receipts with fake in-app behavior.

Two findings from the same report deserve to change how you allocate attention:

Organic is now the blind spot. AppsFlyer's 2026 data puts organic installs at 52% of all fraudulent mobile installs. If your fraud review only examines paid sources, you are looking at slightly less than half the problem. Fraud that successfully impersonates organic is fraud you will never dispute, because there is no partner to dispute it with — it simply corrupts the organic baseline you measure every paid channel against.

iOS is no longer the safe assumption. The report shows iOS improving 38% year over year and running cleaner than Android for the first time — while Finance on Android has been stuck at a 50–53% Real Users Lift for five consecutive quarters with no improvement. Category and platform now matter more than the old post-ATT heuristic that iOS is inherently safer.

Know the five dominant schemes

Emulator and device farms. Hundreds of virtual or physical devices generating installs, opens, and early-funnel events. The tell is uniformity: identical device models clustering on one sub-publisher, sequential-looking device parameters, GPU and sensor fingerprints that do not match claimed hardware, and time-zone or language settings inconsistent with the geo.

Click injection. Malware on real devices fires a click the moment a legitimate install begins, stealing attribution from the channel that actually earned it. The signature is impossibly short click-to-install time (CTIT) — installs attributed seconds after the click. Any source with a CTIT distribution spiking under roughly 10 seconds is stealing, not driving, installs.

Click spam / click flooding. Networks fire massive volumes of fake clicks hoping to win last-click attribution on organic installs. The mirror image of injection: abnormally long and flat CTIT distributions, very low click-to-install conversion rates, and a suspicious lift in attributed installs that tracks your organic baseline.

SDK spoofing and synthetic installs. The current frontier. Rather than interacting with your app at all, the attacker reverse-engineers the measurement SDK's signing scheme and injects fabricated install and event payloads directly into the attribution graph. Both AppsFlyer and Adjust document HMAC-signed payloads with rotating server-side salts as the defense — clicks and installs bound by cryptographic signatures only the MMP server can validate. The critical operational point is that a forge attack scales where a replay attack does not: once an attacker can compute valid signatures, they can mint installs on demand, limited only by salt rotation and downstream volume anomaly detection.

Incentivized and misattributed junk. Real humans, worthless intent — users paid or misled into installing. Looks clean at the install level, collapses at retention: D1 retention a fraction of your organic benchmark and near-zero deep-funnel events.

The detection stack, in order of leverage

  1. CTIT distribution analysis. Still the highest-value single report for hijacking-class fraud. Pull click-to-install time curves per source and sub-publisher. Healthy traffic forms a log-normal hump over minutes-to-hours; injection spikes at seconds; spam drags a long flat tail. Know its limit: CTIT tells you nothing about a synthetic install, because there was never a real device to time.
  2. Retention-curve comparison. Plot D1/D7/D30 per source against your organic curve. Fraudulent cohorts do not decay like humans — they cliff. This remains one of the few signals that catches spoofing, because faking a plausible retention curve over thirty days is materially harder than faking an install. A source at half your organic D1 with a flat D7 is buying you spreadsheet rows, not users.
  3. Cross-system reconciliation. Compare install counts in your MMP against actual session counts in your product analytics. Synthetic installs that never opened your app show up as a gap between the two systems, and this is one of the cheapest checks available to any team running both.
  4. Device integrity signals. Google Play Integrity API and App Attest on iOS flag emulators, rooted devices and tampered clients at the platform level. Commercial device-fingerprinting layers add cross-app history: a "new" device seen resetting its ID forty times is not new.
  5. New-device-rate and IP anomalies. Sources delivering implausible shares of never-before-seen device IDs, or clusters resolving to data-center IP ranges, are farms by definition.
  6. Sub-publisher granularity. Fraud hides in aggregates. A network can look acceptable overall while three sub-publishers supply all the junk. Demand transparency and blacklist at the sub-publisher level, or assume the network's average is laundering its worst suppliers.
  7. Deep-funnel event integrity. As detection improved at the install layer, fabrication moved downstream into in-app events. If a source's install-to-purchase rate looks better than organic, that is not a win — that is the most common signature of event spoofing.

Signal reliability by fraud type

Detection signal Emulator farms Click injection Click spam SDK spoofing Incent junk
CTIT distribution Weak Strong Strong None Weak
Retention vs organic Strong Weak Weak Strong Strong
MMP vs analytics sessions Strong None None Strong Weak
Device integrity API Strong Moderate None Moderate None
New-device rate Strong Weak Moderate Strong Weak
Deep-funnel event ratios Moderate None None Strong Strong
SDK signature validation Moderate Moderate None Strong None

The pattern worth internalizing: no single signal covers the board, and the two techniques growing fastest — spoofing and event fabrication — are precisely the ones the industry's most-used report (CTIT) cannot see at all.

Why detection improvements make the problem move rather than shrink

The most useful mental model for this category is displacement. Detection improvements in one channel consistently push fraudulent traffic toward the next weakest point — which is why a flat or declining overall fraud rate can coexist with accelerating fraud in specific verticals and in channels receiving less scrutiny. AppsFlyer's 2026 data shows exactly that pattern: aggregate iOS improvement alongside categories that have not moved in over a year, and a documented year-over-year rise in DSP-attributed fraud.

Sophistication is rising on the supply side too. DoubleVerify's September 2025 research into AI-powered fraudulent mobile applications documented a ShadowBot operation in which individual devices appeared to open ten different spoofed applications — synthetic app inventory generated at a speed manual review cannot match.

The operational conclusion: fraud rates are not a property of your stack, they are a property of your stack relative to everyone else's. Re-baseline quarterly. Fraud adapts to whatever KPI you pay on — when you start optimizing to D7 events, the farms start faking D7 events. The arms race is the job.

Process beats tools

Run a weekly fraud review with four artifacts: CTIT curves by source, retention curves by source versus organic, MMP-to-analytics install reconciliation, and a rejected-install report from your MMP. Add a monthly organic-baseline review, because organic is now where the majority of fabricated installs land and nobody is watching it.

Negotiate contracts with fraud clawback clauses before scaling a new channel — post-hoc refund conversations without contractual teeth recover pennies. Insist on sub-publisher-level transparency as a condition of spend, not as a favor.

And connect this to measurement rather than treating it as a separate compliance exercise. Fraud is, in the end, a measurement problem: it inflates the numerator of every efficiency metric you report. The only method that is structurally immune is a holdout — fabricated installs cannot manufacture incremental revenue in a control-versus-exposed comparison. If a channel's fraud picture is ambiguous, our incrementality testing guide covers the test design that settles it, and the same signal-quality logic underpins everything in our AI media buying breakdown — an optimization algorithm fed fraudulent conversions will faithfully buy you more fraud.

Bottom Line for Operators

The classic detection stack — CTIT, retention curves, device integrity, sub-publisher granularity — still catches the majority of hijacking-class fraud, and you should run all of it weekly. But the growth is in fabrication, which produces no anomalies by design, so the signals that matter most now are the ones that are hard to fake over time: retention shape against organic, MMP-versus-analytics reconciliation, and deep-funnel event ratios that look implausibly good. Watch your organic baseline, since AppsFlyer's 2026 data puts most fraudulent installs there. Stop assuming iOS is the safe platform. And validate the whole picture with a holdout, because that is the one measurement fraud cannot fake. For the MMP and fraud-prevention tooling landscape, see our tools directory.


Frequently asked questions

What percentage of mobile ad installs are fraudulent?

It varies enormously by platform, category and traffic source, so a single global figure is misleading. AppsFlyer's 2026 report shows iOS improving 38% year over year and now running cleaner than Android for the first time, while specific segments have not improved at all — Finance on Android has held a 50–53% Real Users Lift for five straight quarters. Self-attributing networks like Meta and Google run dramatically cleaner than open exchange and affiliate traffic. Measure your own rate per source against your own organic baseline rather than benchmarking against an industry average.

What is click injection and how do I detect it?

Click injection is when malware on a user's device fires an ad click the instant an app install begins, stealing attribution for an install another channel or organic demand actually drove. Detect it with click-to-install time analysis: attributed installs with CTIT under roughly 10–15 seconds are physically implausible and indicate injection. Note that CTIT analysis will not detect SDK spoofing, where no real install occurred at all.

What is SDK spoofing and why is it harder to catch?

SDK spoofing sends fabricated install and in-app event payloads directly to your attribution provider without any app ever being installed. It is harder to catch because it produces clean-looking data by design rather than the anomalies most detection is tuned for — AppsFlyer describes it as the fraud type most likely to be undercounted in any dataset. The defenses are cryptographic signature validation on install payloads, which both AppsFlyer and Adjust document, plus behavioral checks that are expensive to fake over time: retention shape, and reconciliation between MMP install counts and real sessions in your product analytics.

Are installs from emulators always fraud?

For consumer app UA, effectively yes — a paid install from an emulated device will never become a monetizing user. Platform integrity APIs (Google Play Integrity, App Attest) flag emulators reliably, and sources with elevated emulator rates should be blacklisted at the sub-publisher level.

Which tools help detect mobile UA fraud?

Start with your MMP's fraud suite — AppsFlyer Protect360, Adjust's fraud prevention, Singular Fraud Prevention — and confirm that SDK signature validation is actually enabled rather than merely available. Add platform integrity signals (Google Play Integrity API, App Attest). For high-spend operations, layer commercial device fingerprinting to catch ID-reset abuse across apps, and make sure your product analytics can be reconciled against MMP install counts, since that gap is one of the few reliable tells for synthetic installs.

STA 360° · THE BRIEF

One transmission. Every angle that mattered.

A short weekly brief on AI marketing tools, programmatic shifts, and measurement — written for operators, not tourists. No spam, unsubscribe anytime.