Click fraud is a type of mobile advertising fraud where fake clicks are generated on ads with the intent to steal attribution credit, inflate performance metrics or drain advertiser budgets. It is one of the most widespread forms of mobile ad fraud.
Types of Click Fraud
Click Injection
A malicious app installed on the user's device monitors for new app installs. The moment an install is detected, it fires a fake click with the correct device ID, stealing attribution credit just before the install is recorded.
Click Flooding
Also called click spam — fraudsters send massive volumes of fake clicks hoping that some will match real organic installs. The CTIT (Click-to-Install Time) for these installs is abnormally long (hours or days).
SDK Spoofing
Fraudsters simulate app installs and in-app events without real devices or users, using intercepted SDK traffic to fake conversion signals.
How to Detect Click Fraud
| Signal | What it Indicates |
|---|---|
| Very short CTIT (<1 second) | Click injection — click fired after install detected |
| Very long CTIT (>24 hours) | Click flooding — matching organic installs to old clicks |
| High install rate, low engagement | Fake installs with no real users |
| Multiple installs from same IP | Device farm generating fake installs |
AppMeasurely detects click injection, click flooding, SDK spoofing and device farm fraud in real time. Block fraudulent installs before they drain your budget. Get started free →