Two Cybercrime Rings and Eight Defendants Indicted for Digital Advertising Fraud
justice.gov
justice.gov
The losers are unsophisticated ad buyers such as the brand advertisers that use ad agencies to fill their ads with garbage traffic. Proctor and Gamble has recently figured that internet display is pretty much worthless. The other losers are legit publishers. I am perfectly happy to pay $0.50 a click with half the traffic being fraud, as I am willing to pay $1.00 a click for legit traffic from legit publishers. I get the same result, buy my money gets split 50/50 between legit publishers and crooks.
I am mostly a dev, but have bought more than $1M in advertising on multiple platforms. The biggest joke I have ever seen was AppNexus. It was like 70% or more fraud, and it was the most obvious crap imaginable. For instance, all clicks coming from 8 month old user agents for evergreen browsers.
Google Adwords and Double Click have been mostly clean. I'd say 85-90%. I do see stuff that is obvious bullshit from time to time, and it goes away pretty quickly and but Google doesn't refund the money. I don't really care... they make it so we can police it pretty well. Facebook ads are completely clean, but they don't run a network.
The simple rule for picking a ad platform is: if it isn't loaded with performance advertisers (CPA), then stay the hell away.
[1] Fraud free doesn't mean bullshit free. They tend to be very liberal with how they calculate billable events from user interactions.
[2] https://www.facebook.com/business/marketing/audience-network
Ad networks value proposition is give us money and an ad and your revenue will rise. If there's fraud that just dilutes the effectiveness of the proposition. Eventually poor quality networks die in the same way that the market winnows fertilizer etc. There is no free lunch
That's... really smart. A lot of companies use services like MaxMind to do this. I wonder how difficult it is to get a GeoIP data correction request approved: https://support.maxmind.com/geoip-data-correction-request/
A /19 would run you about 8k/m and I assume maxmind updates are included in the cost.
I have no citation for this, but SORBS and friends blacklisted /24 by default. If you had enough servers you could send enough email to turn a profit before your /24 was blacklisted. Only until you got to SORBS level 3 was your prefix blocked. Of course they would delist you for 2000/day.
The chance of getting a visa to move out or starting a business, which can only be oriented towards civilized countries if you'd like to make any money at all... Is particularly low.
IT is one of those areas which you can still learn particularly well without any access to textbooks or academia.
I guess, they have one thing in common, a lot never ever thought of traveling abroad. While some people I knew in that scene 10+ years ago had perfect English, in their mind "the abroad" is such a distant place, and obscure place that they think is totally beyond their reach, that they don't even bother toying with an idea of moving abroad.
And also notice, the guys indicted are rather old, and probably were in the scene since the era of first internet ads companies, and doing ad fraud long before even google was a thing
Long story short, he did it because he was really good at it and got better over time. You don't knock something like this out without having done a lot of smaller stuff first, and by the time you get to this level of skill and sophistication, it's because it's easier to do this, and the skills you've built up don't apply well to real world jobs, or if they do at all, they don't pay nearly as much as you can get paid by running the scam, and with all that skill and experience, the risk of getting caught does go down quite a bit.
2. Legitimate business requires more than just talent! If you don't know people in power, don't have the required connections, good luck getting necessary permits etc..
3. Starting capital due to compliance requirements is much higher! It pretty much excludes everyone who isn't coming from an Ivy league.
4. There is a very high probability that even if you've all the resources you might fail.
5. Government officials might as well take over your company anytime. (In former Soviet countries and corrupt third world countries, government officals do takeovers your business)
Simply money, isn't enough in itself. VCs also bring top level connections, including people who will serve as executives in future with intimate connection to Goverment.
These guys don't have anything else other than cheap labor (which will do anything provided it doesn't have to do with messing with the authorities of the countries they are living in) and their own skill.
That's... a not-insignificant number of IPs to have. I wonder how many different blocks were used and across which RIRs?
Here's a list - note that many have been reassigned: http://methbot.s3-website-us-east-1.amazonaws.com/IPs-CIDR.t...
Now I'm thinking through this example,I'm going to try and test for these monkey patched methods (not sure if can do it, but maybe md5(toSting) compare to major browser native hashes?).
Sounds like you work for a verification vendor, if so have you had success with detecting these 'monkey patches'?
As you can imagine, specific techniques used for detecting fraudulent monkey patching (or even whether we attempt to do so) aren't generally something I can talk about.
That said, there are a few slides about the cat-and-mouse games of .toString() here (starting about page 20): https://rya.nc/shmoo17 [PDF]
In short, using .toString() will find naive monkey patches, however it can be overridden to varying degrees of cleverness.
Are you involved with sales or just engineering? My work email is in my profile I might drop you a note though I am just guessing your product is too expensive for our clients (mostly political campaigns).
Eg. "We observed that when the malware created the new desktop, it didn’t create a new instance of explorer.exe. This meant that an analyst wouldn’t be able to easily access their tools, because there wouldn’t be a way to create processes on this desktop due to the absence of a running instance of Explorer."
Is there any malware which creates a new explorer instance on a hidden desktop? Were you hoping to call CreateDesktopExW() and then SwitchDesktop() and just click the start button and open up a screen recorder app? Yet if you wanted to do this, you could easily call CreateProcess() with the lpDesktop pointer set to the hidden desktop to start your tools there...
"Ad Network #2 carried out another digital ad fraud scheme...botnet...more than 1.7 million infected computers...download fabricated webpages...$29 million in ad fraud"
Only part I'm unclear on is whether they were actually operating the network/marketplace, or just falsifying the publisher and user parts of it. Sounds like the latter, in which case, I wonder which ad networks got gamed.
However detecting a dormant botnet isn't easy nor simple. e.g.: DARPA (via HACCS) awarded a $1.2m contract to build a system that can automatically pinpoint botnet-infected devices. https://www.fbo.gov/?s=opportunity&mode=form&id=72de4936f6f4...
Haha! What on Earth is "the system"?! Did he really say that? Bad criminals spoiling our nice advertising system.
Sinkhole?