• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechMobile

Mobile botnets are costing advertisers $1 billion in ad fraud, study shows

By
Mathew Ingram
Mathew Ingram
Down Arrow Button Icon
By
Mathew Ingram
Mathew Ingram
Down Arrow Button Icon
July 23, 2015, 9:00 AM ET
Photograph by Bloomberg via Getty Images

As mobile devices proliferate, app advertising has become a huge business, worth an estimated $20 billion in the U.S. alone. But how much of that is being wasted? According to a new report from fraud-detection firm Forensiq, as much as $1 billion of that advertising money is being lost to fraud in a number of ways—including malicious apps that hijack mobile phones and turn them into an ad-viewing botnet.

There are already several well-known varieties of mobile fraud, including device emulation, mobile user-agent and location spoofing, and fraudulent user-acquisition methods. But Forensiq says that its research has uncovered a new variety, which it calls “mobile device hijacking.”

In this process, malicious mobile applications pretend to exhibit human behavior by loading new pages or cycling through functions in an app, all of which loads advertising. But they load far more ads than any normal application would—as many as 20 ads per minute—and in many cases they do so in the background when the app isn’t being used—which means they are never seen.

Based on the amount of estimated fraudulent inventory, the company said the total loss to advertisers could reach the $1 billion mark this year. And the loss of hundreds of millions of dollars worth of mobile advertising revenue isn’t the only downside: These apps can also consume a huge amount of bandwidth and battery life, leading to higher costs for owners.

“These apps run constantly, even when not actively in use, serving thousands of invisible ads every day on a single device. To the consumer, this means potentially petabytes of bandwidth wasted daily; in just an hour, a typical malicious app installed on a single device can download 2GB of data per day, consisting of images and videos that are never seen.”

This kind of behavior is similar to the “botnets” that malicious computer hackers can create using infected computers, first by turning them into zombies that can be controlled remotely, and then tying them together and forcing them to load webpages, click on ads or distribute malware. But as Forensiq points out, most PC malware is downloaded without the user’s knowledge via email or infected webpages, whereas mobile app fraud comes from apps that users download willingly.

Mobile ad fraud
Forensiq

The firm said that it tracked down more than 5,000 apps that were exhibiting suspicious behavior. It found the apps by using the real-time tracking data that it gets from the various mobile ad networks that it is integrated with, which allowed it to look for the kind of rapid ad-loading and background functions that most malicious apps exhibit. The company then loaded several of these apps and tracked their behavior.

Some of the malicious apps the firm discovered downloaded a script that allowed them to simulate clicks on ads, and to load the advertiser’s landing page without the user’s permission. Others redirected users through affiliate links to websites and other apps in the iOS and Android app stores.

Forensiq said its research showed that more than 13% of total mobile app inventory was at risk, and 14% of all mobile apps on iOS, Android and Windows Mobile platforms.

[vimeo 133457903 w=500 h=281]

Over a period of 10 days, Forensiq says it observed more than 12 million unique devices with installed apps that exhibited fraudulent behavior: about 1% of all devices it observed in the U.S. and between 2% and 3% of those in Europe & Asia. In addition to malicious apps, the company says it also saw some apps that don’t even display ads showing up in its scan of ad behavior—including BlackBerry’s BBM messenger—which suggests that other apps are spoofing their unique identifiers.

Many malicious apps can be identified because they ask for a suspicious number of permissions that shouldn’t be required given their purpose—such as the ability to prevent the device from sleeping, the ability to run at startup automatically, to modify or delete content and to access location services even when the app is running in the background.

Forensiq said that fraudulent apps drove traffic through most of the major mobile ad exchanges and networks, and in some cases established 1,000 connections per minute, connecting to more than 300 networks, servers, exchanges and ad providers in less than an hour.

About the Author
By Mathew Ingram
See full bioRight Arrow Button Icon

Latest in Tech

Big TechSpotify
Spotify users lamented Wrapped in 2024. This year, the company brought back an old favorite and made it less about AI
By Dave Lozo and Morning BrewDecember 4, 2025
4 hours ago
InnovationVenture Capital
This Khosla Ventures–backed startup is using AI to personalize cancer care
By Allie GarfinkleDecember 4, 2025
8 hours ago
AIEye on AI
Companies are increasingly falling victim to AI impersonation scams. This startup just raised $28M to stop deepfakes in real time
By Sharon GoldmanDecember 4, 2025
8 hours ago
Jensen Huang
SuccessBillionaires
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant ‘state of anxiety’ out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
9 hours ago
Ted Pick
BankingData centers
Morgan Stanley considers offloading some of its data-center exposure
By Esteban Duarte, Paula Seligson, Davide Scigliuzzo and BloombergDecember 4, 2025
9 hours ago
Zuckerberg
EnergyMeta
Meta’s Zuckerberg plans deep cuts for metaverse efforts
By Kurt Wagner and BloombergDecember 4, 2025
9 hours ago

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
14 hours ago
placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
2 days ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
9 hours ago
placeholder alt text
Economy
Ford workers told their CEO 'none of the young people want to work here.' So Jim Farley took a page out of the founder's playbook
By Sasha RogelbergNovember 28, 2025
6 days ago
placeholder alt text
Health
Bill Gates decries ‘significant reversal in child deaths’ as nearly 5 million kids will die before they turn 5 this year
By Nick LichtenbergDecember 4, 2025
20 hours ago
placeholder alt text
Economy
Tariffs and the $38 trillion national debt: Kevin Hassett sees ’big reductions’ in deficit while Scott Bessent sees a ‘shrinking ice cube’
By Nick LichtenbergDecember 4, 2025
8 hours ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.