Hey man,
Yeah, this kind of fraud sucks—been there. If they’re using rotating residential IPs with different IPs each time and the same user agent, you're basically getting hit with a botnet or some kind of click farm using mobile proxies or 4G/LTE IPs. IP blocking won't do much, you're right about that.
Here’s what you can do:
First, stop relying on Google’s built-in click fraud protection—it's not gonna catch this level of abuse. You’ll need a third-party click fraud detection tool. Something like ClickCease, CHEQ, or even custom setups with fingerprinting tools. But to be honest, those only go so far when it’s this aggressive.
The best way to cut it off is by using a pre-lander or intermediate redirect page and putting your real landing page behind some basic filtering logic. Use JavaScript or server-side logic to detect bad behavior—like headless browsers, odd timezones, no mouse movement, copy-paste behavior, etc. Anything bots struggle with. If something looks shady, just bounce them or redirect them somewhere else. That way they don’t hit your real landing page or cost you conversion data.
Also, keep an eye on your ad schedule and geo. A lot of this stuff happens in weird bursts—track patterns, and if certain regions or times are worse, cut them out temporarily.
You could even try switching to manual bidding and controlling your placements better, or pausing Search entirely for a bit and shifting some traffic to Display or Performance Max if it’s less targeted by the fraud.
It’s fixable, but you’ll need to layer a few things. You won’t beat this with one tool. Happy to chat more if you need help with setups.
Hope that helps, and good luck—don’t let these losers eat your ad budget.