Live data from Hacker News

How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

buzzfeednews.com

81–90 of 108 posts

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#81
post #75

Earlier quoted context omitted.

There are two distinct areas of online advertising: performance marketing, and brand advertising. I'm a performance marketer. I make a profit only when ads result in conversions - usually sales or signups for trial offers, but in some cases we do lead generation campaigns for clients as well. We spend high 5/low 6 figures per month, mostly on Facebook ads, with a monthly ROAS (return on ad spend) that beats Berkshire…

And without doing experimental setup (RCTs), how do you know you are not just paying for organic conversions? I had this presentation a few months ago: https://www.slideshare.net/mobile/gregak/if-youre-not-measur... I would be interested to know what you think.

Very interesting presentation. The question your research is attempting to answer is certainly a valid one for major sites, where people might be on the site anyway without having clicked on a given ad. In my specific case, most of the sites/offers we market through Facebook ads wouldn't have attracted many organic visitors, let alone conversions, on their own, so it's not a question I need to answer. These sites rely almost entirely on paid traffic, and if they don't get it they are out of business.

The importance of being able to figure out what actually led to conversions is not lost on me though. One unique technology I created allows us to do something that I have never seen anyone else in the online marketing world do: track conversions back to the initial click and ad campaign, even if someone just texts, emails, or uses an instant messenger to send the URL to a friend. So let's say someone visits the site, sees that the offer isn't for them but texts it to a friend. A month later, that friend finally gets around to looking at it, but decides it isn't for them either but knows someone else who might be interested, and they email it to someone else, who ultimately converts. We can track that conversion and all the steps in between back to the initial click and attribute it to the initial ad campaign, which gives us a much better sense of what each ad campaign is actually producing. The technology also lets us create custom Facebook audiences of anyone that has shared a link from the site - regardless of how they shared - text, email, Facebook - doesn't matter. We can then customize campaigns to encourage those people to share again.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#82

That article is an example of outstanding journalism. It probably required tremendous amounts of writing ability, knowing the subject matter, spending hours and hours of research, being familiar with the industry, etc. Doesn't see this much these days. Too bad a lot of journalism died in 2008/2009 when journalists lost their jobs and newspapers were either bought by big players or simply went out of business.

Well, it's Buzzfeed. They have the relative unique business model with their listicles and other clickbait crap financing their high-quality investigative journalism.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#83

So, to summarise online advertising: 1. It has been a vector for viruses / malware / cryptocoin mining 2. It tracks users activities on the internet without their knowledge to form a picture of their 'online personality' 3. It can invade a users privacy by keeping records of personal and / or intimate details of their online activities 4. It often uses more bandwidth than the content of the site it's on 5. auto-play…

Half serious suggestion: Could we somehow enable individuals themselves conduct auctions to allow advertisers to access? Imagine being able to say: "I will accept 10 ads today - you guys figure out what you want to show me".

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#84
post #8

This is Mathijs from AppBrain. The app mentioned at the start of the article used Admob and Adcolony it seems: https://www.appbrain.com/app/emoji-switcher-root/com.stevens... and was taken down on October 2nd. Another app implied in this scheme used 15 ad networks (including Admob, Facebook Audience Network and Twitter's Mopub) and was just taken down 6 days ago: https://www.appbrain.com/app/wheel-of-surprise-eggs/co…

We updated our SDK signatures and now have a public page that shows stats about apps that contain this malware: https://www.appbrain.com/stats/libraries/details/techsnab-co...

If you want to check your own device if you have any apps that contain the code used by this botnet, the latest release of our AppBrain Ad Detector app will scan for it. It's available on Google Play here: https://play.google.com/store/apps/details?id=com.appspot.sw...

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#85
Wow, it's like the way I move my mouse isn't a legit Turing test. What a shocker.

The real problem is using stupid methods to identify real users. This adversarial run is reaching it's end state, and you can't tell apart humans from machines there.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#86

That article is an example of outstanding journalism. It probably required tremendous amounts of writing ability, knowing the subject matter, spending hours and hours of research, being familiar with the industry, etc. Doesn't see this much these days. Too bad a lot of journalism died in 2008/2009 when journalists lost their jobs and newspapers were either bought by big players or simply went out of business.

I bet BuzzFeed has a lot of really skilled digital ad guys on staff, maybe the Author is an expert in the field already.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#87
post #25
post #11

Google's blog about it: https://security.googleblog.com/2018/10/google-tackles-new-a...

a security blog you can only read after enabling javascript for a dozen domains. Nice one google.

How silly of you to assume one can deliver 2kb of text without running thousands of lines of blackbox-javascript on your device and contacting dozens of servers. Besides, do you have anything to hide? Not running JS would suggest so, and possible help identify you online as the one guy that doen't run JS from your IP range. Welcome to the future.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#88
post #83

So, to summarise online advertising: 1. It has been a vector for viruses / malware / cryptocoin mining 2. It tracks users activities on the internet without their knowledge to form a picture of their 'online personality' 3. It can invade a users privacy by keeping records of personal and / or intimate details of their online activities 4. It often uses more bandwidth than the content of the site it's on 5. auto-play…

Half serious suggestion: Could we somehow enable individuals themselves conduct auctions to allow advertisers to access? Imagine being able to say: "I will accept 10 ads today - you guys figure out what you want to show me".

Assuming we erect such a system, what's my incentive to not use an ad blocker anyway? I don't want to see ten ads a day, I want to see zero.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#90

> More than 15 additional websites involved in the scheme reused the same TrackMyShows.tv SSL certificate Anyone shed light on this? How does one website use another website's SSL cert?

At least the one example they link is delivered over HTTP. If you request HTTPS instead, the server presents the certificate for TrackMyShows.tv.
Post reply on HN