SlideShare ist ein Scribd-Unternehmen logo
1 von 27
Downloaden Sie, um offline zu lesen
February 2020 / Page 0marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Ad Fraud is “Cash Out”
for Malware/Hacking
February 2020
Augustine Fou, PhD.
acfou [at] mktsci.com
February 2020 / Page 1marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Why do hackers hack?
February 2020 / Page 2marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
To make enormous profits
Stealing from digital ad budgets – like an open vault of gold
Advertisers Publishers
Bad Guys
1/3
2/3
Ads are not shown
to humans, wasted
ad dollars
Ad revenue declines
because dollars are
stolen by bad guys.
Steal money using fake ads;
siphon dollars out of ecosystem.
February 2020 / Page 3marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
How big? $330B every year
Worldwide digital ad spending to exceed $330 billion by 2020
February 2020 / Page 4marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
How do hackers make
money?
February 2020 / Page 5marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Counterfeit goods bits/bytes
Fakes or unauthorized replicas of real ad impressions
ad impressions shown to
bots/software not to humans
ad fraud
February 2020 / Page 6marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Simple three step process
1. set up
FAKE SITES
2. buy
FAKE TRAFFIC
3. sell
FAKE ADS
February 2020 / Page 7marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
More profitable use of DDoSNow use enormous DDoS traffic to generate enormous ad revenues
Google Digital Attack Map
February 2020 / Page 8marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
New “largest ever” botnet every year
Vast botnets targeting high-value video ads, disguising/hiding
February 2020 / Page 9marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake Sites, Fake News Thrive
November 2019
https://www.buzzfeednews.com/
article/craigsilverman/fake-local-
news-sites-albany-edmonton
February 2020
https://www.buzzfeednews.com/article/
craigsilverman/these-fake-local-news-
sites-have-confused-people-for-years
Fake sites are
spreading
disinformation,
hate, fake news,
and other
content; they
are able to
thrive and grow
because they
make money
using adtech.
February 2020 / Page 10marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
What about mobile?
February 2020 / Page 11marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Millions of apps on millions of phones
Apps loading ads in background, continuously; stealing data
September 2019
https://www.buzzfeednews.com/
article/craigsilverman/sweet-
camera-play-store-removed-
ihandy
May 2019
https://www.buzzfeednews.com/
article/craigsilverman/vidmate-
app-download
April 2019
https://www.buzzfeednews.com/
article/craigsilverman/google-
play-store-ad-fraud-du-group-
baidu
February 2020 / Page 12marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Millions of apps on millions of phones
Stealing data, abusing permissions, attribution fraud
October 2018
https://www.buzzfeednews.com/
article/craigsilverman/how-a-
massive-ad-fraud-scheme-
exploited-android-phones-to
November 2018
https://www.buzzfeednews.com/
article/craigsilverman/android-
apps-cheetah-mobile-kika-
kochava-ad-fraud
March 2019
https://www.buzzfeednews.com/
article/craigsilverman/in-banner-
video-ad-fraud
February 2020 / Page 13marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Uber sues 100 mobile exchanges
https://www.linkedin.com/pulse/stone-meet-glass-
house-significance-ubers-second-ad/
Mobile exchanges
were falsifying
placement reports to
make it appear the ads
ran on legitimate sites
and apps; some
exchanges were
fabricating the reports
entirely, when no ads
were even shown
February 2020 / Page 14marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
(2017) Been going on for a while…
May 26 Forbes “Judy Malware”
• 40 bad apps to load ads
• 36 million fake devices to load
bad apps
• e.g. 30 ads per device /minute
• 30 ads per minute = 1 billion
fraud impressions per minute
June 1 Checkpoint “Fireball”
• 250 million infected computers
• primary use = traffic for ad
fraud
• 4 ads /pageview (2s load time)
• fraudulent impressions at the
rate of 30 billion per minute
February 2020 / Page 15marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
What about CTV/OTT?
February 2020 / Page 16marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Mobile Apps Fake Video Streams
January 2020
https://www.buzzfeednews.com/
article/craigsilverman/grindr-
roku-apps-ad-fraud-scheme
Source: http://blog.pixalate.com/invalid-ssai-measure-ott-ctv-ad-fraud
Fraudsters use the same bots to
simulate more video streams to
cause more video ads.
February 2020 / Page 17marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
What else?
February 2020 / Page 18marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Browser extensions, js code
Extensions can load ads, fake clicks, record clicks, exfiltrate data
https://gadgets.ndtv.com/internet/news/google-chrome-web-store-
extensions-500-removed-ad-fraud-2180242
Source: Freedom to Tinker, Nov 2017
February 2020 / Page 19marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Malvertising
Malware in ads used to compromise fresh devices, for ad fraud
https://twitter.com/j_rom_/status/1221715676907393024
https://medium.com/@clean.io/summary-of-
malicious-ads-and-reputation-threats-q3-2019-
2dd285e1c65a
February 2020 / Page 20marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Online child abuse images
“Using a variety of sophisticated techniques to avoid detection,
offenders are exploiting online advertising networks to
monetise their distribution of child sexual abuse material.”
Source: The Drum Nov 6, 2018 Source: CNN, Feb 2019 Source: NYT, Sep 2019
February 2020 / Page 21marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Alter measurement; click fraud
Make the ads appear viewable; affiliate fraud (click flooding)
Buzzfeed, March 2018
Source:
http://articles.latimes.com/2013/apr/19/business/la-
fi-mo-cookie-stuffing-ebay-20130419
“Laguna Niguel man pleads
guilty in 'cookie stuffing' scam
against Ebay. The online
auctioneer paid Dunning’s
company about $5.2 million in
2006 and 2007, the U.S. Attorney
said.”
February 2020 / Page 22marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Stolen identities; fake accounts
Unverifiable lookalike audiences contain fake profiles/preferences
Bots pretend to be
oncologists by visiting
oncology related sites.
“[LOTAME] purged 400 million
of its over 4 billion profiles after
identifying them as bots.”
Adweek, Feb 2018
February 2020 / Page 23marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Money laundering
Dollars are laundered as digital media ad spend on “cash out” sites
1. Buy and place digital ads on sites and apps
controlled by the same entity
2. Collect dollars from “cash out” sites, fully
laundered
February 2020 / Page 24marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Financial crimes - laundering
Dollars are laundered and moved via digital games, virtual goods
Valve suspended the trading between
players of “container keys”—an in-
game gambling device that players can
buy (with real money) to try to win
(virtual) rewards such as special
weapons or clothing. The firm says
“nearly all” of the trades of such
keys were “believed to be fraud-
sourced”. It is a rare admission of the
growing problem of using video games
to facilitate financial crime.
https://www.economist.com/finance-and-
economics/2019/11/07/financial-crime-through-video-
games-is-on-the-rise
February 2020 / Page 25marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
About the Author
Augustine Fou, PhD.
acfou [@] mktsci.com
February 2020 / Page 26marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Dr. Augustine Fou – Researcher
2013
2014
Published slide decks and posts:
http://www.slideshare.net/augustinefou/presentations
https://www.linkedin.com/today/author/augustinefou
2016
2015
2017
20192018

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Hidden Costs in Digital Media Supply Path
Hidden Costs in Digital Media Supply PathHidden Costs in Digital Media Supply Path
Hidden Costs in Digital Media Supply Path
 
Fake Everything 2019 Update
Fake Everything 2019 UpdateFake Everything 2019 Update
Fake Everything 2019 Update
 
Still nothing but ad fraud 2021 dr augustine fou
Still nothing but ad fraud 2021 dr augustine fouStill nothing but ad fraud 2021 dr augustine fou
Still nothing but ad fraud 2021 dr augustine fou
 
How to Use FouAnalytics For Marketers
How to Use FouAnalytics   For MarketersHow to Use FouAnalytics   For Marketers
How to Use FouAnalytics For Marketers
 
History and Impact of Digital Ad Fraud
History and Impact of Digital Ad FraudHistory and Impact of Digital Ad Fraud
History and Impact of Digital Ad Fraud
 
State of Digital Ad Fraud Q2 2018
State of Digital Ad Fraud Q2 2018State of Digital Ad Fraud Q2 2018
State of Digital Ad Fraud Q2 2018
 
Entire ecosystem supporting ad fraud 2018
Entire ecosystem supporting ad fraud 2018Entire ecosystem supporting ad fraud 2018
Entire ecosystem supporting ad fraud 2018
 
Good Publishers Will Save Digital Marketing v2019
Good Publishers Will Save Digital Marketing v2019Good Publishers Will Save Digital Marketing v2019
Good Publishers Will Save Digital Marketing v2019
 
Why Fraud detection doesn't work
Why Fraud detection doesn't workWhy Fraud detection doesn't work
Why Fraud detection doesn't work
 
Digital Fraud Viewability Benchmarks Q4 2020
Digital Fraud Viewability Benchmarks Q4 2020Digital Fraud Viewability Benchmarks Q4 2020
Digital Fraud Viewability Benchmarks Q4 2020
 
FouAnalytics DIY site media analytics fraud detection baked in
FouAnalytics DIY site media analytics fraud detection baked inFouAnalytics DIY site media analytics fraud detection baked in
FouAnalytics DIY site media analytics fraud detection baked in
 
Q1 2022 Update on ad fraud for AMM
Q1 2022 Update on ad fraud for AMMQ1 2022 Update on ad fraud for AMM
Q1 2022 Update on ad fraud for AMM
 
Fraud by Browser Study
Fraud by Browser StudyFraud by Browser Study
Fraud by Browser Study
 
Ad Tech Organized Crime
Ad Tech Organized CrimeAd Tech Organized Crime
Ad Tech Organized Crime
 
Four types of digital ad spend updated august 2020
Four types of digital ad spend updated august 2020Four types of digital ad spend updated august 2020
Four types of digital ad spend updated august 2020
 
Digital ad fraud impact on class action notice industry
Digital ad fraud impact on class action notice industryDigital ad fraud impact on class action notice industry
Digital ad fraud impact on class action notice industry
 
In app fraud vs app install fraud
In app fraud vs app install fraudIn app fraud vs app install fraud
In app fraud vs app install fraud
 
Digital ad fraud is an iceberg
Digital ad fraud is an icebergDigital ad fraud is an iceberg
Digital ad fraud is an iceberg
 
Digital ad spend and ad fraud
Digital ad spend and ad fraudDigital ad spend and ad fraud
Digital ad spend and ad fraud
 
Digital Media Trust Collaborative
Digital Media Trust CollaborativeDigital Media Trust Collaborative
Digital Media Trust Collaborative
 

Ähnlich wie Ad Fraud is Cash Out for Malware/Hacking

[Phybbit] Series A Deck
[Phybbit] Series A Deck[Phybbit] Series A Deck
[Phybbit] Series A DeckSatoko Ohtsuki
 
COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...
COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...
COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...yStats.com
 
Rpa m2 l2-common online channels
Rpa m2 l2-common online channelsRpa m2 l2-common online channels
Rpa m2 l2-common online channelsVikas Gaur
 

Ähnlich wie Ad Fraud is Cash Out for Malware/Hacking (20)

How Brands are Solving Ad Fraud Themselves
How Brands are Solving Ad Fraud ThemselvesHow Brands are Solving Ad Fraud Themselves
How Brands are Solving Ad Fraud Themselves
 
Digital Ad Fraud Is Not Illegal Yet
Digital Ad Fraud Is Not Illegal YetDigital Ad Fraud Is Not Illegal Yet
Digital Ad Fraud Is Not Illegal Yet
 
How Bad Measurements Harm Good Publishers
How Bad Measurements Harm Good PublishersHow Bad Measurements Harm Good Publishers
How Bad Measurements Harm Good Publishers
 
State of Digital Ad Fraud Q4 2018
State of Digital Ad Fraud Q4 2018State of Digital Ad Fraud Q4 2018
State of Digital Ad Fraud Q4 2018
 
Marketers' Playbook Questions to Ask Verification Vendors
Marketers' Playbook   Questions to Ask Verification VendorsMarketers' Playbook   Questions to Ask Verification Vendors
Marketers' Playbook Questions to Ask Verification Vendors
 
Unintended Consequences for Publishers using Adtech
Unintended Consequences for Publishers using AdtechUnintended Consequences for Publishers using Adtech
Unintended Consequences for Publishers using Adtech
 
Mobile display fraud is rampant beyond belief
Mobile display fraud is rampant beyond beliefMobile display fraud is rampant beyond belief
Mobile display fraud is rampant beyond belief
 
Digital ad fraud is a Major Economic Crime
Digital ad fraud is a Major Economic CrimeDigital ad fraud is a Major Economic Crime
Digital ad fraud is a Major Economic Crime
 
Diy CTV and OTT Ad Fraud Prevention
Diy CTV and OTT Ad Fraud PreventionDiy CTV and OTT Ad Fraud Prevention
Diy CTV and OTT Ad Fraud Prevention
 
Procurement to Help Fight Ad Fraud
Procurement to Help Fight Ad FraudProcurement to Help Fight Ad Fraud
Procurement to Help Fight Ad Fraud
 
State of digital ad fraud 2017 by augustine fou
State of digital ad fraud 2017 by augustine fouState of digital ad fraud 2017 by augustine fou
State of digital ad fraud 2017 by augustine fou
 
Fraud Detection is Easily Fooled
Fraud Detection is Easily FooledFraud Detection is Easily Fooled
Fraud Detection is Easily Fooled
 
Low-Cost, No-Tech Ways to Fight Fraud vMiMA
Low-Cost, No-Tech Ways to Fight Fraud vMiMALow-Cost, No-Tech Ways to Fight Fraud vMiMA
Low-Cost, No-Tech Ways to Fight Fraud vMiMA
 
State of Digital Ad Fraud Q2 2017 by Augustine Fou
State of Digital Ad Fraud Q2 2017 by Augustine FouState of Digital Ad Fraud Q2 2017 by Augustine Fou
State of Digital Ad Fraud Q2 2017 by Augustine Fou
 
[Phybbit] Series A Deck
[Phybbit] Series A Deck[Phybbit] Series A Deck
[Phybbit] Series A Deck
 
Digital Ad Fraud FAQ Question 1
Digital Ad Fraud FAQ Question 1Digital Ad Fraud FAQ Question 1
Digital Ad Fraud FAQ Question 1
 
What The Hell Happened to Good Publishers 1995 2015
What The Hell Happened to Good Publishers 1995 2015What The Hell Happened to Good Publishers 1995 2015
What The Hell Happened to Good Publishers 1995 2015
 
Fraud investigation - apps loading pages
Fraud investigation -  apps loading pagesFraud investigation -  apps loading pages
Fraud investigation - apps loading pages
 
COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...
COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...
COVID-19 Impact on E-commerce and Payments: Newsflash April 9-15, 2020 by ySt...
 
Rpa m2 l2-common online channels
Rpa m2 l2-common online channelsRpa m2 l2-common online channels
Rpa m2 l2-common online channels
 

Mehr von Dr. Augustine Fou - Independent Ad Fraud Researcher

Mehr von Dr. Augustine Fou - Independent Ad Fraud Researcher (12)

Forensic Auditing of Digital Media.pdf
Forensic Auditing of Digital Media.pdfForensic Auditing of Digital Media.pdf
Forensic Auditing of Digital Media.pdf
 
Ad blocking benchmarks q4 2021
Ad blocking benchmarks q4 2021Ad blocking benchmarks q4 2021
Ad blocking benchmarks q4 2021
 
Digital ad dollars trickle down chart
Digital ad dollars trickle down chartDigital ad dollars trickle down chart
Digital ad dollars trickle down chart
 
Bad guys optimize ad fraud efficiency
Bad guys optimize ad fraud efficiencyBad guys optimize ad fraud efficiency
Bad guys optimize ad fraud efficiency
 
Alternative to ANA's end to end supply chain transparency study v final
Alternative to ANA's end to end supply chain transparency study v finalAlternative to ANA's end to end supply chain transparency study v final
Alternative to ANA's end to end supply chain transparency study v final
 
Impact of Loss of 3P Cookies on Publishers' Ad Revenue
Impact of Loss of 3P Cookies on Publishers' Ad RevenueImpact of Loss of 3P Cookies on Publishers' Ad Revenue
Impact of Loss of 3P Cookies on Publishers' Ad Revenue
 
Programmatic reach analysis 2021
Programmatic reach analysis 2021Programmatic reach analysis 2021
Programmatic reach analysis 2021
 
Browser and OS Share Jan 2021
Browser and OS Share Jan 2021Browser and OS Share Jan 2021
Browser and OS Share Jan 2021
 
Checking abnormal referrer traffic in google analytics
Checking abnormal referrer traffic in google analyticsChecking abnormal referrer traffic in google analytics
Checking abnormal referrer traffic in google analytics
 
Digital ad dollars trickle down chart
Digital ad dollars trickle down chartDigital ad dollars trickle down chart
Digital ad dollars trickle down chart
 
Marketer Outcomes Study
Marketer Outcomes StudyMarketer Outcomes Study
Marketer Outcomes Study
 
Site analytics click location research
Site analytics click location researchSite analytics click location research
Site analytics click location research
 

Kürzlich hochgeladen

Company Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxCompany Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxMario
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxDyna Gilbert
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书zdzoqco
 
ETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxNIMMANAGANTI RAMAKRISHNA
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书rnrncn29
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predieusebiomeyer
 
TRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxTRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxAndrieCagasanAkio
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa494f574xmv
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书rnrncn29
 
Unidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxUnidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxmibuzondetrabajo
 

Kürzlich hochgeladen (11)

Company Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxCompany Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptx
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptx
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
 
ETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptx
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predi
 
TRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxTRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptx
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
 
Unidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxUnidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptx
 

Ad Fraud is Cash Out for Malware/Hacking

  • 1. February 2020 / Page 0marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Ad Fraud is “Cash Out” for Malware/Hacking February 2020 Augustine Fou, PhD. acfou [at] mktsci.com
  • 2. February 2020 / Page 1marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Why do hackers hack?
  • 3. February 2020 / Page 2marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou To make enormous profits Stealing from digital ad budgets – like an open vault of gold Advertisers Publishers Bad Guys 1/3 2/3 Ads are not shown to humans, wasted ad dollars Ad revenue declines because dollars are stolen by bad guys. Steal money using fake ads; siphon dollars out of ecosystem.
  • 4. February 2020 / Page 3marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou How big? $330B every year Worldwide digital ad spending to exceed $330 billion by 2020
  • 5. February 2020 / Page 4marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou How do hackers make money?
  • 6. February 2020 / Page 5marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Counterfeit goods bits/bytes Fakes or unauthorized replicas of real ad impressions ad impressions shown to bots/software not to humans ad fraud
  • 7. February 2020 / Page 6marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Simple three step process 1. set up FAKE SITES 2. buy FAKE TRAFFIC 3. sell FAKE ADS
  • 8. February 2020 / Page 7marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou More profitable use of DDoSNow use enormous DDoS traffic to generate enormous ad revenues Google Digital Attack Map
  • 9. February 2020 / Page 8marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou New “largest ever” botnet every year Vast botnets targeting high-value video ads, disguising/hiding
  • 10. February 2020 / Page 9marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake Sites, Fake News Thrive November 2019 https://www.buzzfeednews.com/ article/craigsilverman/fake-local- news-sites-albany-edmonton February 2020 https://www.buzzfeednews.com/article/ craigsilverman/these-fake-local-news- sites-have-confused-people-for-years Fake sites are spreading disinformation, hate, fake news, and other content; they are able to thrive and grow because they make money using adtech.
  • 11. February 2020 / Page 10marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou What about mobile?
  • 12. February 2020 / Page 11marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Millions of apps on millions of phones Apps loading ads in background, continuously; stealing data September 2019 https://www.buzzfeednews.com/ article/craigsilverman/sweet- camera-play-store-removed- ihandy May 2019 https://www.buzzfeednews.com/ article/craigsilverman/vidmate- app-download April 2019 https://www.buzzfeednews.com/ article/craigsilverman/google- play-store-ad-fraud-du-group- baidu
  • 13. February 2020 / Page 12marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Millions of apps on millions of phones Stealing data, abusing permissions, attribution fraud October 2018 https://www.buzzfeednews.com/ article/craigsilverman/how-a- massive-ad-fraud-scheme- exploited-android-phones-to November 2018 https://www.buzzfeednews.com/ article/craigsilverman/android- apps-cheetah-mobile-kika- kochava-ad-fraud March 2019 https://www.buzzfeednews.com/ article/craigsilverman/in-banner- video-ad-fraud
  • 14. February 2020 / Page 13marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Uber sues 100 mobile exchanges https://www.linkedin.com/pulse/stone-meet-glass- house-significance-ubers-second-ad/ Mobile exchanges were falsifying placement reports to make it appear the ads ran on legitimate sites and apps; some exchanges were fabricating the reports entirely, when no ads were even shown
  • 15. February 2020 / Page 14marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou (2017) Been going on for a while… May 26 Forbes “Judy Malware” • 40 bad apps to load ads • 36 million fake devices to load bad apps • e.g. 30 ads per device /minute • 30 ads per minute = 1 billion fraud impressions per minute June 1 Checkpoint “Fireball” • 250 million infected computers • primary use = traffic for ad fraud • 4 ads /pageview (2s load time) • fraudulent impressions at the rate of 30 billion per minute
  • 16. February 2020 / Page 15marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou What about CTV/OTT?
  • 17. February 2020 / Page 16marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Mobile Apps Fake Video Streams January 2020 https://www.buzzfeednews.com/ article/craigsilverman/grindr- roku-apps-ad-fraud-scheme Source: http://blog.pixalate.com/invalid-ssai-measure-ott-ctv-ad-fraud Fraudsters use the same bots to simulate more video streams to cause more video ads.
  • 18. February 2020 / Page 17marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou What else?
  • 19. February 2020 / Page 18marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Browser extensions, js code Extensions can load ads, fake clicks, record clicks, exfiltrate data https://gadgets.ndtv.com/internet/news/google-chrome-web-store- extensions-500-removed-ad-fraud-2180242 Source: Freedom to Tinker, Nov 2017
  • 20. February 2020 / Page 19marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Malvertising Malware in ads used to compromise fresh devices, for ad fraud https://twitter.com/j_rom_/status/1221715676907393024 https://medium.com/@clean.io/summary-of- malicious-ads-and-reputation-threats-q3-2019- 2dd285e1c65a
  • 21. February 2020 / Page 20marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Online child abuse images “Using a variety of sophisticated techniques to avoid detection, offenders are exploiting online advertising networks to monetise their distribution of child sexual abuse material.” Source: The Drum Nov 6, 2018 Source: CNN, Feb 2019 Source: NYT, Sep 2019
  • 22. February 2020 / Page 21marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Alter measurement; click fraud Make the ads appear viewable; affiliate fraud (click flooding) Buzzfeed, March 2018 Source: http://articles.latimes.com/2013/apr/19/business/la- fi-mo-cookie-stuffing-ebay-20130419 “Laguna Niguel man pleads guilty in 'cookie stuffing' scam against Ebay. The online auctioneer paid Dunning’s company about $5.2 million in 2006 and 2007, the U.S. Attorney said.”
  • 23. February 2020 / Page 22marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Stolen identities; fake accounts Unverifiable lookalike audiences contain fake profiles/preferences Bots pretend to be oncologists by visiting oncology related sites. “[LOTAME] purged 400 million of its over 4 billion profiles after identifying them as bots.” Adweek, Feb 2018
  • 24. February 2020 / Page 23marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Money laundering Dollars are laundered as digital media ad spend on “cash out” sites 1. Buy and place digital ads on sites and apps controlled by the same entity 2. Collect dollars from “cash out” sites, fully laundered
  • 25. February 2020 / Page 24marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Financial crimes - laundering Dollars are laundered and moved via digital games, virtual goods Valve suspended the trading between players of “container keys”—an in- game gambling device that players can buy (with real money) to try to win (virtual) rewards such as special weapons or clothing. The firm says “nearly all” of the trades of such keys were “believed to be fraud- sourced”. It is a rare admission of the growing problem of using video games to facilitate financial crime. https://www.economist.com/finance-and- economics/2019/11/07/financial-crime-through-video- games-is-on-the-rise
  • 26. February 2020 / Page 25marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou About the Author Augustine Fou, PhD. acfou [@] mktsci.com
  • 27. February 2020 / Page 26marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Dr. Augustine Fou – Researcher 2013 2014 Published slide decks and posts: http://www.slideshare.net/augustinefou/presentations https://www.linkedin.com/today/author/augustinefou 2016 2015 2017 20192018