Hackers Make $5M a Day by Faking 300M Video Views
forbes.com
forbes.com
It was discovered years ago because:
* Their IP stack was acting like Linux[1]
* Their flash player said "I'm Linux"
* Their user agent said other things (random user agents)
* Their DNS traffic was going UK, but the hosts were coming out of the US
* list of botnet infected IPs participating in ad fraud
* list of offending/incompetent SSP blindly accepting forged requests
There are a lot of vendors in this space now, offering various kinds of "spamhaus"-type solutions. They're all crap because they operate blacklists of various kinds to keep their customers dependent.
The ideal scenario is for ad networks/SSPs to implement the anti-fraud technology themselves, however getting there from here is difficult: The first ad network to go clean will be at a significant (fiscal) disadvantage.
I'd like to get in touch with anyone ad network/SSP that wants to go first.
> lists of botnet infected IPs participating in ad fraud
This won't be enough.
A popular "audience extender" is to use an iframe containing your site as an ad tag, and run it on your display network. Unless you have been using an ad blocker for the last ten years (and maybe even then), it's very likely your IP address has been used in ad fraud.
> lists of offending/incompetent SSP blindly accepting forged requests
Google facilitates an enormous amount of ad fraud, but media buyers have to buy from Google because nobody else sells Google search ads (except, I suppose, the injection people...)
Yahoo purchased a company who was selling video ads that were muted using uncommon AS3 mixer controls.
I think a much shorter list would be the media suppliers that don't have ad fraud on them and don't facilitate ad fraud. You'll find such a list below.
var st:SoundTransform = new SoundTransform(1.0);
st.leftToLeft = st.leftToRight = 0.0;
st.rightToLeft = st.rightToRight = 0.0;
SoundMixer.soundTransform = st;
Mutes the audio, but if a VPAID component naively checks: SoundMixer.soundTransform.volume
they will get 1.0. Most don't even bother checking though.As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?
Someone has some "sites" that they show to an ad network or an advertiser and tries to sell the impressions on those sites. They receive "ad tags" in exchange, and the theory is that users are exposed to the ads shown by those ad tags, and the advertiser is satisfied.
However, once they have "ad tags", they can do whatever they want with them. They can find the URL signal that represents "give me money" and arrange to fire that signal.
> As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?
No.
The Media Rating Council[1] was endowed by congress with special powers that allow participants to talk to each other antitrust protections kicking in, but these conversations are extremely non-productive.
Thanks for the code above. What was the company name? never heard of it.
And yet they're still active with the same tech stack.
When three-letter television companies will buy an audience extender from one of these shady guys rather than tell the advertiser that they don't have as much traffic as they projected, you don't really even need to worry about detection.
There exist passive techniques powerful enough to really map these kinds of actors out thoroughly, however the industry has been reticent to stop it because everyone from Viacom to Google has facilitated ad fraud, and there's this fear that stopping things too abruptly will cause advertisers to lose faith in this (still nascent) $60 billion dollar industry (US numbers).
All the other techniques require JavaScript and/or AS3 and are thus subject to modification by these kinds of sophisticated attackers. The only real way to do JavaScript in these cases is to change it often enough and run enough parallel versions that the attacker cannot keep up.
The level of programming skill in the "industrial scale botting" community is high. Top tier botters can easily get into +$100k club if they were doing whitehat stuff.
Bot detection, ad auditing, antifraud systems
I imagine somewhere in MethBots virtual DOM emulation they got sloppy and ran code (JS) from the server. Using metaprogramming plus some output they could predict they could use runtime reflection and inspect server side JS object.
>
On page 19 in the The Methbot Operation report they state that ‘White Ops detection technology was able to use a JavaScript language feature called “reflection” to gather extensive, detailed information about its inner workings.’
I have personally never heard about JavaScript reflection before, but it appear to be a debug method for one object to dump information or data about another object.
Maybe the White Ops software loaded some JavaScript that was able to dump much of its environment and send it back to White Ops?
let test = function() { return "hello";}
test.toString()
returns "function() { return "hello";}"
It's not too difficult to imagine that pairing that with some JS parsing would allow you to slowly crawl your way around an app and gather the app structure. Crazy, and fascinating idea.It reminds me of ns.cnet.com
It's pretty common now to do things like intentionally tagging the wrong friends in facebook because people are paranoid that facebook knows too much. Even with non-techie people. They're creeped out.
Throwing off retargeting is something a lot of people might want to do.
Trump ad ... click Comcast ... click Ambulance chasing lawyer ... click click click
So that would be better than random - a plugin that clicks the ads for things you don't like or aren't interested in.
I also think that prices are extremely inflated.
Even stuff which shows like hundred people a day costs you 8 dollar per click. No amount of selling will you get back the money.
Imho something is wrong there...
I'd guess on the keywords where law firms are spending hundreds per click, you're dealing with malpractice and personal injury cases. Those cases are likely to be done on contingent and can have pretty huge upsides. I'd think a well-run firm would have some idea of the expected value of those types of cases and can spend accordingly to acquire clients. Considering how targeted search ads are compared to how these firms normally advertise -- local TV, radio, billboards, busses, etc. the costs probably aren't radically different than they're used to spending on advertising.
If that were true these ads would just go away, or cost less. They are making money.
Depending on the exchange, you can sometimes see how much the DSP/client paid for the impression by looking at the win notification URL. Typically there will be a URL query parameter that has been filled in by the exchange, like `BID_CPM=4.00`, and when your browser requests this URL (which is owned by the DSP/client), your browser is effectively notifying the winner of the auction that they won and how much it cost. However, ad exchanges are increasingly sending these fields encrypted to protect against manipulation/fraud.
If you really want to manipulate the amount of money that advertisers pay to show you ads, look at what ad botnets like the one in this article do. The PDF above only briefly mentions it, but one of the things they do to increase their perceived value to DSPs and clients is they make their browsers visit high value advertisers websites (e.g. they might visit a shopping website and put items in their cart to make it look like they were strongly considering purchasing the items). Later, when you visit a publisher site, this will cause the bidders' machine learning systems to predict a much higher value for you than they otherwise would have, and submit higher bids as a result.
(Have they come up with "no fly" lists over there yet?)
Sends a click to everything blocked in uBlock Origin.
If you sell shoes, put up some shoe ads with an affiliate link, shouldn't that work good enough? You'd save millions by not being susceptible to attacks like the one in the article.
Imagine now a beefy box with a couple hundred VMs running on it.
Now imagine fake cameras catching a rendered environment and tracking virtual eyes that move according to what the camera would expect.
If you want ad networks that rely on cameras to detect your presence capturing your image, imagine installing a fake camera driver on your PC that shows a rendered person in a rendered environment doing random browsing.
edit: last part was unclear
Contrary to what many people in adtech and web development seem to believe, electricity isn't free. Not to mention such silly concerns as worldwide resource usage and climate change.
Basically, that's why advertising needs to be reigned in hard, squeezed with regulations until it starts to behave. Because it's a zero-sum game on enough fronts to make everyones' lives worse if it's not fought against hard.
The bigger picture is virality. Nobody wants to watch your video with 100 views. Same video with 10M views, now everyone has to watch it.
The music business has been doing this so much for so long that it's to the point where I automatically distrust everything that's "popular" as having been gamed.
When I need something, I buy it online most of the time (if possible).
I'm kinda happy someone is gaming that whole system against them, maybe it will help transform the ad ecosystem into something that does not seem to be obtrusive and annoying to most people.
Quite open to counter points if anyone accepts explaining them (instead of simply down voting this comment)
Maybe those companies who lost money go back and try to sue the ad exchanges because they didn't adequately detect the click fraud, so then it's the ad companies who take the hit.
In the end, what actual change do you think would be enacted by companies who wish to advertise their products being the victim of fraud?
They stop advertising through the web, and we can get rid of the ad-driven startup bubble, and get rid of most ads on the web in general.
To play devil's advocate, it would be a huge loss to society if advertisements were no longer viable due to constant fraud.
Information would flow a lot less freely because then content providers would be forced to switch to directly charging for their content rather than giving it to you for "free + ads" as they do currently. It wouldn't just be "low value" content dropping off, "low value" is another individual value judgement.
It would become much harder to connect products and services or become harder to separate actual stories from long-form product placement.
I don't find much wrong with the concept of "advertising". I do take issue with certain types of "bad" or malicious ads, but I'm also generally not receptive to most advertising.
However, ads exist because they are effective at connecting users with products.
But, it becomes a race to the bottom, and it is to be expected that every business will want more eyeballs on its products and try to outdo their competitors. The collateral damage of this advertisement frenzy is with people who are bombarded and overstimulated by product placement and a relentless marketing machine. Consumers become skeptic and dulled by the efforts and advertising becomes the pain in the a it is now.
"Getting rid of most online ads" doesn't remove a business' need to connect with consumers in the most effective, lowest cost way possible. It also doesn't change a news agency's need to get paid for the content it creates.
I'm not disputing that digital advertising can get out of hand. Malicious ads are bad. Ads with dark UX patterns are bad. We likely have different definitions of "bad ads".
However, if it's the number of ads you're concerned about, you generally have a choice to pay to remove them to continue consuming the content you're interested in or product which you are using.
I still don't see how your original comment about criminals defrauding businesses out of their money and inflating the cost/risk of advertising somehow puts everyone in a better place.
Do they help you in making any decision in what to buy? No, they just mislead you, because you don't end up buying the best product, but the one that spent the most marketing dollars, meaning the product where the price is inflated the most (as, ifthey didn't pay for marketing, you could have gotten it cheaper).
Instead, you should make your decisions on what to buy based on independent product tests.
Such as the tests from Stiftung Warentest — subscribing to their tests is the best decision you could do, as they constantly test all types of products in comparison tests, you get the results in a nice readable matrix per category, and can directly see which is the best product for your use case. (Same with similar tests in other newspapers, comparing a hundred different types of headphones, or child seats for the car, or banana juices, etc).
Advertising is harmful because it means the market is not a well-working free market anymore, as the buyers don't buy the best product anynore, but the one with the highest marketing budget.
Based on the way you describe business and what you think is objectively the best way to purchase products, my hunch is that you have little experience working in a company or making products you need to sell to others.
I mean this in a most genuine way: if you have any aspiration of managing a company or even building your own, it will greatly help you to learn more about why marketing and advertising are important to business. You simply won't succeed without them.
The more concerning part is that it didn't raise any red flags on the ad exchanges that some random corporation was getting paid to display ads on nbc.com and nytimes.com etc. That part makes no sense to me. They also managed to purchase blocks of IPV4 addresses in the names of major residential ISPs such as Comcast. That part had to be an inside job.
[1] http://methbot.s3-website-us-east-1.amazonaws.com/URLs.txt
[2] http://methbot.s3-website-us-east-1.amazonaws.com/domains.tx...
How is an ad buyer ever supposed to make an informed decision about how susceptible their chosen ad vendor is to fraud?
I suspect it's similar for the R&D spend on preventing them in the first place.
As long as you're hitting your target ROI than advertising on still makes sense.
The goal of DR is drive an immediate action, for ex. a purchase or news letter signup. Branding/Awareness is more about keeping the brand/product top of mind for the eventual time when the purchasing is actually done.
Usually small and mid-sized advertisers focus on DR. That's why you see a lot of re-targeting type ads for buying products you abandoned in your shopping cart (exception: large ecommerce).
Then you have large advertisers like the Fortune 500 and beyond. They know that you're not making the purchase right there. Hardly any toothpaste, car, $25k server ads or retirement account ads lead to a conversion instantaneously. This is Branding/Product advertising. The hope is to keep their product top-of-mind so you'll consider it when you're driving by the dealership or in the toothpaste isle at Target. This is like your traditional newspaper advertising. Traditional KPIs like CPA used in DR ads don't make sense here. And, due to fraud CPC and CTR are not that useful.
A lot of brand/product advertisements don't have a good instantaneous KPI and measuring long term ROI for a year long $25k server campaign is nebulous art at best.
So to wrap up this story. The guys running this fraud operation were spoofing "premium" video sites with $13.00+ average CPMs (this is high); they were going for the most expensive inventory. The people buying ads on "premium" video sites are not DR advertisers. The goal was to capture Branding/Product advertisers dollars.
It's a bit of a misconception that all online advertising is ROI focused. This was true maybe 4 years ago. With younger audiences (40 and under) consuming more video content online versus linear television there's been in a influx of branding dollars coming "premium" online video.
(Disclosure: My company Adfin provided data for financial estimate for this anti-fraud operation done by WhiteOps)
The vendors that are letting the supply in (SSPs and exchanges) should do more to verify the supply. This could verifying their supply id with provided domain (would get rid of a lot of crappy arbitrage). Additional verification on new suppliers who are generating more traffic. And longer net payment terms for new suppliers to allow for clawing some of it back.
The problem is that many vendors are unwilling to do that. In many cases because they still make money on fraudulent traffic / arbitrage that goes through their platform. Or because they tend to be more accepting of bad data, because adtech is so duct tapped together. People setup their tags/campaigns incorrectly, adservers re-wrap urls, other incorrect rewrapping (fraud/viewablity/attribution), bad javascript, bad publisher sites and hostile browser environments. So they default to be more accepting to not lose on that revenue.
Thank you.
http://www.legalmatch.com/law-library/article/click-fraud.ht...
Maybe this will make the video ad industry unprofitable. One can only hope.
[1] https://krebsonsecurity.com/2016/12/report-3-5m-in-ad-fraud-...
They are not in true ad fraud. Those guys are not in PPV, but in counter stuffing and "viralizing". They are former ebanners/ advmaker and cyberonix/telemaster ad fraud detection people.
Their ops model is this: they sell promo service for content producers; after upfront cost producers pay comission from monetisation revenue.
So how did these people make money? Are they for hire? Did they offer services to spoof the publisher domain and make revenue out of thin air, taking a cut from the pub?
I'm not sure if it's a similar arrangement here. The linked report makes it sound like they own the publisher sites too, but it's hard for me to fathom how they could maintain "legitimate" relationships with SSPs when they're funnelling out millions of dollars per day. It goes without saying that it's much harder to fake your way through the financial system.
I think I only clicked on an ad once in the past 10 years; it was because my mouse was about to fall off the edge of the table and, in my moment of panic, I accidentally pressed the left button.
Thankfully, my other hand saved the day with a swift 'Ctrl + W' movement.
The 300x250 un-muted video in the upper left really irks me big time.
Garbage publishers are garbage.
Who on earth pays that kind of price to have someone watch their ad video? Serious question.
>> those bots "watched" as many as 300 million video ads a day, with an average payout of $13.04 per thousand faked views.
I thought the usual payout was an order of magnitude lower than that.
Something like 1$ per thousand views
I'd really like someone with monetized videos to give some real input on this.
Their usual pay is around 5 USD per hour here in Russia
CPM = Cost Per Thousand Impressions (not views)
The catch is that almost all fields in said offer can be faked by a malicious adversary due to lack of security/competence from the exchange.
Our company is already getting asked to provide full reports by IP address to see how far this goes.
Personally, I feel that a publisher of technology is responsible for ensuring there are no "holes". If someone finds a hole and pokes around and uses it for any reason, it should not be criminal.
If I found a way to methodically purchase all the pieces to win McDonald's monopoly game, would that be criminal fraud? Or would it be negligence by McDonald's? My view is the latter.
To counter with another analogy. Robbing a casino, criminal. Counting cards, severely frowned upon but not criminally illegal. When you create a system that users can game to their advantage, you are responsible for enforcing your rules - it doesn't (or shouldn't) make it a crime when your rules are broken.
Isn't this the definition of victim blaming?
Have they been convicted of any crime?
Is what they are doing illegal in Russia?
I hope these guys also sue this publisher for some extra income.
How were they getting $13.04 per view?
"The article has since been updated, now it mentions $13.04 per 1000 views:" (niklaslogren) [1]