They only have to do the very minimum to recover from detection. The incentive is for them to keep the largest possible bag of tricks ready to deploy every time they get a dip in revenue due to fraud detection to milk the fraud. Besides, most of the countermeasure takes the form of javascript to be executed by the client, since the fraudsters control the client, they can alter the operating environment of the fraud detection as needed.