Inside the Million-Machine Clickfraud Botnet
labs.bitdefender.com
labs.bitdefender.com
You could go via a bunch of brokers who have less stringent identity verification than Google. They will all take cuts, but you don't care, since that's just a cost of doing business.
Source: have been defrauded before by one of the major ad exchanges and been stonewalled when I asked for my money back.
You've just describe most high volume ad supported publishing websites these days.
https://www.chromium.org/Home/chromium-security/security-faq...
Tl;Dr key pinning doesn't protect against local root certs.
A lot of mid-sized ad networks and ad buyers actually have a negative incentive when it comes to detecting fraud -- those fraudulent clickthroughs look great on the aggregate metrics, so if you're the only person flagging them, you look like you're getting your customers a lower CTR than the competition, unless your customers are sufficiently educated.
They decided to use that cert directly, instead of creating their own cert with a more normal name.