What is Install Fraud?
Install fraud is fake, incentivized, or hijacked mobile app installs billed on CPI or install CPA. The advertiser pays for an event that does not represent a real user—a core risk in the mobile apps vertical.
Main methods
- SDK spoofing — forged install postbacks without a real install.
- Click injection — fake click injected before an organic install (attribution fraud).
- Device farms — bulk installs on device farms.
- Incent walls — rewarded installs without IO approval.
Detection
MMPs (AppsFlyer, Adjust) score fraud, CTIT (click-to-install time), and device clusters. Abnormally short CTIT, datacenter IPs, zero D1 retention trigger rejection. Advertisers claw back payouts; networks ban sources.
Mitigation for buyers
Pay on in-app events (registration, D1, purchase) instead of raw installs; non-incent IOs; reconcile MMP and tracker data. SKAdNetwork on iOS limits last-click attribution but does not eliminate fraud.