Fake visitors
Residential-proxy bots
Bots route their visits through real households' internet connections so that each fake visitor appears to be a person at home.
How it works
A residential proxy is a relay sitting on an ordinary home or mobile connection. The household may have installed a "free VPN" or app that quietly shares its connection, or the device may be infected. A bot in a data centre sends its browsing through that relay, and the website sees a normal family broadband address.
This defeats the simplest defence, the list of data-centre addresses. It is why the industry treats such traffic as sophisticated invalid traffic (SIVT): finding it needs behavioural and device analysis, not a lookup table.
Who pays for it
Advertisers pay for clicks that pass early filters. Feed partners pay later and harder, because sophisticated traffic tends to be found in retrospective reviews that claw back weeks of revenue at once.
Who does it, and why
Organised fraud groups and the more capable traffic sellers. The extra cost of proxies is worth it because the traffic survives longer before detection.
Warning signs
- Home-network addresses paired with device details typical of servers or automation tools.
- Many "different" visitors whose device fingerprints are identical.
- An IP address whose apparent location, language and time zone disagree.
- Addresses that also appear on proxy or anonymiser reputation lists.
- Normal click rates but zero downstream engagement.
Defences
- Combine IP reputation with device fingerprinting and behaviour; no single signal is enough.
- Use an independent IVT detection service that covers proxy networks.
- Hold new traffic sources at low volume until advertiser-side quality data comes back.
- Keep each source in its own channel so a retrospective deduction can be traced.
An example
Real case: the 3ve operation, taken down in 2018, used malware on home computers to act as relays for data-centre bots. A joint US government alert said it controlled more than 1.7 million unique IP addresses over a ten-day window, each looking like a household.
Documented cases
- 3ve ("Eve") (2018): Ad fraud run through malware-infected home computers and hijacked IP addresses
- Clickbot.A (2006): Botnet click fraud aimed at syndicated search engines
- Microsoft v. Lam (competitor click fraud) (2009): Competitor click fraud on search ads to drain rivals' budgets, combined with lead selling