How ad fraud emulates mobile devices

curious duck

Newbie
Joined
Jul 14, 2025
Messages
3
Reaction score
1
Recently I started being a bit obsessed about ad fraud. How a supposedly 100 billion dollar fraud is barely talked about and known.
Anyway, I keep reading how they use selenium base and residential proxy to cover their track. But something makes 0 sense to me. Most of web traffic is web yet no guide about how to do ad fraud mentions how to emulate mobile.

Once, to run a simple like WhatsApp I got instantly detected and rejected because I used an emulator (BlueStacks). So I don't believe using emulator would work. Even if website can't access every thing they can extremely easily access plugins, screen resolution and others and probably determine emulators (if they keep having Sam fingerprint etc.).

So either fraudster are very advanced (good emulator quality/VM/real devices) and very strictly respect the number of models of each device, right number of 4g vs wifi etc. Which I find incredibly hard to believe as it would be costly buying each device physically or fully emulate perfectly everything.

Either ad networks do not check for that ? I mean obviously u can modify user agents but it's incredibly easy to detect (u have to spoof everything to be coherent such as font, width/height, device characteristics etc.) and I found literally 0 project to turn Selenium into something spoofing perfectly Android or iOS.

So I'm extremely lost here.

And I won't even talk about Spotify. This makes 0 sense to me. Most people use phones so you'd have to spoof phones to be realistic. Spotify literally OWN their own app so they can so easily detect fakes. So either u buy a massive farm of real devices with 4g proxy (very costly) either u don't do it. Don't tell me 100% computer traffic doesn't get detected lol
 
Ad fraud ops have gotten insanely advanced. These days, they’re not just spoofing user-agents — they’re emulating full device stacks, down to touch behavior, sensor data, and even battery state.
A few key tricks being used:
  • Real-time JS rendering to simulate mobile browser behavior
  • Mimicking device motion/orientation via virtual sensors
  • IP + carrier spoofing to pass as mobile networks
  • Generating real-looking session depth (scrolling, tapping, timing patterns)
The line between emulation and real devices is getting thinner. Anti-fraud systems now look for tiny inconsistencies in how mobile environments respond — stuff like latency spikes, unusual resource timing, or missing API responses.

If you’re studying it from a defense angle, there’s a lot to watch for. If you're on the offense... well, it's a constant cat and mouse game.
 
Ad fraud ops have gotten insanely advanced. These days, they’re not just spoofing user-agents — they’re emulating full device stacks, down to touch behavior, sensor data, and even battery state.
A few key tricks being used:
  • Real-time JS rendering to simulate mobile browser behavior
  • Mimicking device motion/orientation via virtual sensors
  • IP + carrier spoofing to pass as mobile networks
  • Generating real-looking session depth (scrolling, tapping, timing patterns)
The line between emulation and real devices is getting thinner. Anti-fraud systems now look for tiny inconsistencies in how mobile environments respond — stuff like latency spikes, unusual resource timing, or missing API responses.

If you’re studying it from a defense angle, there’s a lot to watch for. If you're on the offense... well, it's a constant cat and mouse game.
Do most ad fraudster got very advanced but then why can't I find any easy to use Android and iOS browser emulators on the internet. Why just finding undetectable emulators (if I can't find mobile browser at least just good emulators) seems so hard (BlueStacks and all are dead easy to find out as fake) ?

Or do a lot of ad networks just don't do anything to detect fraud.
Because I can't imagine an absolutely gigantic market of 100 billion fraud with extremely advanced techs etc. that I would find barely 0 information about. so I strongly assume a lot of small editors with fake website and a handful of low level ad networks (often partners with Google and Microsoft as everyone says their partner's quality is trash).

also just the cost of residential proxy seems so high. 2 bucks a GB. If my website+ads take 1MB to load it means I pay 2 bucks/1000 customers. So my RPM should be over 2 bucks I guess. But the less reputable ad network i'm not sure they'd give that much. Maybe by extremely packing the ads you could have 4 RPM so 2 bucks a profit/1000. So you'd need like 100s of thousands to make like a few grands. But then it's so easy to detect all devices look the same.

I'm asking very specific question because since I learned about all that like a year ago I'm extremely curious about that HUGE 100B market.
 
Wouldn't be surprised if they used phone farms as well for this kind of stuff

Rotating mobile network proxies with a good automation script should allow you to be pretty much undetectable/unbannable

And I know for a fact that there are some farms out there that are absolutely huge
 
Wouldn't be surprised if they used phone farms as well for this kind of stuff

Rotating mobile network proxies with a good automation script should allow you to be pretty much undetectable/unbannable

And I know for a fact that there are some farms out there that are absolutely huge
Maybe it's the case but then it means ad fraud is something that's just unaccessible for low budgets not willing to buy hardware ? Maybe
But I also read many people in marketing complaining some ad networks are really sketchy and barely check anything. So I'm wondering if that means also not checking user agents are correct etc. Because if yes then that means the 100B fraud market is spread across many malicious actors.
Otherwise it means only a few (hundreds ? Thousands?) with the hardware, software, money capabilities do that fraud. But then it changes everything it means each operations makes 100s of millions. And idk I find it hard to believe but maybe I never hear of it because it's concentrated in China/India. I really don't know.
To be honest I wanted to try a little bit (I don't think I'll end up in jail for small amounts) to make the ends meet and mostly by curiosity so I guess I'll just have to try it out myself ? (No one gets in legal trouble for a few Gs, right ?)
 
Maybe it's the case but then it means ad fraud is something that's just unaccessible for low budgets not willing to buy hardware ? Maybe
But I also read many people in marketing complaining some ad networks are really sketchy and barely check anything. So I'm wondering if that means also not checking user agents are correct etc. Because if yes then that means the 100B fraud market is spread across many malicious actors.
Otherwise it means only a few (hundreds ? Thousands?) with the hardware, software, money capabilities do that fraud. But then it changes everything it means each operations makes 100s of millions. And idk I find it hard to believe but maybe I never hear of it because it's concentrated in China/India. I really don't know.
To be honest I wanted to try a little bit (I don't think I'll end up in jail for small amounts) to make the ends meet and mostly by curiosity so I guess I'll just have to try it out myself ? (No one gets in legal trouble for a few Gs, right ?)
A lot of sophisticated fraud i tends to be unaccessible for low budgets, so I def wouldn't be surprised.

Good luck trying it out for yourself haha, keep me posted
 
Back
Top