Or a Bottle of wine, or a car, or a room for the night, or insurance or a Solar System for that matter?
Advertising on the internet is big business especially for mega companies such as Google, Facebook or Twitter.
It is estimated that Google makes $121 Million per day from adverts with Facebook trailing at around $4 Million per day.
The way that these companies make money from adverts mainly combines the number of times an advert is shown with the number of times that an advert is clicked on. Depending on the model this revenue can go straight to the company (mainly Facebook) or be shared with other publishers willing to show adverts alongside their content. Google calls this ‘sharing economy’, AdSense. In Adsense publishers sign up to display Google generated adverts and search boxes on their sites with Google sharing a percentage of the revenue generated with the publisher. Publisher payments are made every month to qualifying publishers who must generate a minimum of $100 in order to be paid.
This very ecosystem is one that is attractive to fraudsters and people wanting to make ‘easy money’.
The eternal quest for any publisher is to get as many page views and clicks on the adverts as possible on his/her web pages.
Enter the world of bots. In this case a bot is a malicious programme that visits web sites and ‘views’ and ‘clicks’ on determined elements of that web site. Now, if a publisher owns the web site being viewed AND is part of the Google AdSense programme then the potential for mischief and fraudulent earnings increases exponentially.
PLUS, if the owner of an AdSense web site (or Mobile Application) can write a bot (virus) to take over thousands of random users browsers or Mobile Applications then the revenue potential soars.
REASON – on a first level most anti fraud detection systems rely on the most basic of detection which is to monitor the IP Addresses of users accessing and clicking on adverts. Too many clicks from a specific IP and the revenue is denied. BUT, if thousands of users from all over the world are infected then the dispersion of IP Addresses is too wide for adequate detection.
AND this is just what BuzzFeed News uncovered this month and provided Google with information that helped identify new aspects of an ad fraud operation across apps and websites that were monetizing with numerous ad platforms, including Google.
The BuzzFeed News report covers several fraud tactics (both web and mobile app) that are allegedly utilized by the same group. The web-based traffic is generated by a botnet that Google and others have been tracking, known as “TechSnab.” The TechSnab botnet is a small to medium-sized botnet that has existed for a few years. The number of active infections associated with TechSnab was reduced significantly after the Google Chrome Cleanup tool began prompting users to uninstall the malware.
In similar fashion to other botnets, this operates by creating hidden browser windows that visit web pages to inflate ad revenue. The malware contains common IP based cloaking, data obfuscation, and anti-analysis defenses. This botnet drove traffic to a ring of websites created specifically for this operation, and monetized with Google and many third party ad exchanges.
See: https://www.buzzfeednews.com/article/craigsilverman/how-a-massive-ad-fraud-scheme-exploited-android-phones-to and https://security.googleblog.com/2018/10/google-tackles-new-ad-fraud-scheme.html for more technical details on how this fraud was perpetrated.
Various estimates of the extent of this fraud range from $10 Million to $750 Million.
And what can advertisers learn from this:
- Make sure that your ads have a call to action in them that is measureable – a web site visit, a phone call, a physical visit, an order and continually monitor that statistic
- Quantity is not necessarily the best option.
- Sometimes developing relationships with smaller local publishers and spreading your ad spend over many products is the best.
