Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Fake visitors

Headless browsers and automation

Real browser software is driven by a script with no screen and no person, producing visits that pass basic "is this a browser?" checks.

The short answer, from The Arbitrage Desk fraud map

How it works

A headless browser is a normal browser, such as Chrome, running without a window. Developers use it legitimately for testing. Fraudsters use it because it loads pages, runs scripts and stores cookies exactly as a person's browser would, so a feed page's code runs normally and an ad click registers.

The difference is in what a person adds: irregular mouse paths, hesitation, scrolling back up, typing errors. Automation either lacks these or produces them too neatly. Detection therefore looks at small technical traces left by automation tools and at whether the behaviour varies the way human behaviour does.

Who pays for it

Advertisers, when the clicks are billed; then feed partners through deductions and lost quality standing.

Who does it, and why

Bot operators supplying traffic sellers, and occasionally publishers running automation against their own pages. Automation scales at almost no cost once written.

Warning signs

  • Browser properties that reveal automation tools or a missing display.
  • Identical window sizes and fonts across thousands of supposed users.
  • Perfectly straight or instant pointer movement, or none at all.
  • Sessions that always take the same number of seconds from landing to click.

Defences

  • Run automation checks on the page before the feed is requested.
  • Look at the spread of behaviour across a source: real audiences are messy.
  • Rotate and update detection; automation tools change to hide their traces.
  • Do not rely on a CAPTCHA alone; it harms real users and solving services exist.

An example

Illustrative: 5,000 sessions from one source all show a 1,280 by 720 window, the same font list, and a first click between 4.0 and 4.2 seconds after load. A real audience of 5,000 would show dozens of screen sizes and click times spread from two seconds to several minutes. The uniformity, not any single visit, is the evidence.

Documented cases

  • 3ve ("Eve") (2018): Ad fraud run through malware-infected home computers and hijacked IP addresses

Sources