DoubleVerify Uncovers ShadowBot Scheme Involving 35 Million Spoofed Mobile Devices
DV’s Fraud Lab detected amateur-level fraudster mistakes behind a
The DV Fraud Lab identified ShadowBot targeting mobile and Connected TV (CTV) environments using rudimentary automation techniques, including mobile emulators and spoofed app IDs. While the scheme was widespread, it was riddled with amateur-level mistakes, making it detectable for advertisers protected by DV’s advanced fraud-detection systems.
“ShadowBot shows that fraud doesn’t need to be sophisticated to be costly,” said Gilit Saporta, VP Product, Fraud & Quality at DoubleVerify. “It’s alarming to see
DV Fraud Labs identified five key red flags that uncovered ShadowBot:
-
Basic Automation Methods: ShadowBot used emulators that defaulted to screen resolutions (e.g., 800x600). This resolution is not typical for mobile devices.
-
Overly Aggressive Traffic Generation: The operation produced abnormally high impression volumes that didn’t align with seasonal trends.
-
Suspicious IP Activity: Fraudsters relied on anonymizing IP proxies, provided by long tail entities. The digital footprint of these proxy providers was riddled with fake testimonials, broken URLs, and known abuse reports.
-
Lack of Behavioral Diversity: Devices showed identical impression counts, lacking the variability expected from real users.
- Improbable Engagement Patterns: Devices appeared to open 10 spoofed apps in just 9 minutes – behavior impossible for actual users.
“We’ve found that emerging media types, including mobile and CTV environments, are especially susceptible to fraud due to limited visibility and rapid growth,” added Lisa Toledano, who leads one of DV’s fraud detection teams. “Without consistent monitoring and adaptation, these high-value environments become easy targets. Protecting ad spend from these types of schemes requires an always-on approach.”
“As the digital ecosystem continues to scale through automation, the emergence of sophisticated fraud schemes like ShadowBot reinforces the critical importance of transparency, quality, and accountability in media,” said Wayne Tassie, Group Director –
The DV Fraud Lab continues to monitor and shut down evolving fraud schemes across the open web, mobile apps, and streaming environments. With proprietary analytics tools, impression-level monitoring, and a global fraud lab, DV endeavors to ensure that brands and agencies can confidently protect their media investments.
Read the full breakdown here: https://doubleverify.com/shadowbot-slip-ups-dvs-guide-to-fraudster-mistakes/
About DoubleVerify
DoubleVerify (“DV”) (NYSE: DV) is the industry’s leading media effectiveness platform that leverages AI to drive superior outcomes for global brands. By powering media efficiency and performance, DV strengthens the online advertising ecosystem, preserving the fair value exchange between buyers and sellers of digital media. Learn more at www.doubleverify.com.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250625040922/en/
Chris Harihar
chris@crenshawcomm.com
Source: DoubleVerify