Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Fraud & invalid traffic

Botnet

A botnet is a network of malware-infected computers or phones, controlled remotely, that can be made to visit pages and click ads without their owners knowing.

The short answer, from the The Arbitrage Desk glossary

When malware infects an ordinary person's device, the attacker can add it to a "net" of thousands or millions of machines and give them all instructions at once. Used for ad fraud, the infected devices quietly load pages and click ads in the background.

Botnets are dangerous for search feeds because the traffic comes from real homes, real internet providers and real browsers with real histories. To a simple filter it looks like a normal household. Google lists botnets among its named types of invalid activity and says it has dedicated teams that hunt them.

From the arbitrageur's seat, botnet traffic usually arrives indirectly, through a cheap source that resells it. The signals are subtle: activity while the device owner is plainly asleep, many "users" behaving in near-identical ways, and a complete absence of advertiser conversions.

No single arbitrageur can dismantle a botnet. The realistic defences are to avoid unvetted sources, watch conversion quality per source and use IVT detection that recognises known infected devices and behavioural patterns. The legal and financial exposure falls on whoever passed the clicks into the feed.

Think of it like this

Imagine a burglar who secretly copies the keys to thousands of homes and uses each family's phone at night to ring a premium-rate number he owns.

Related terms

Sources: Google Ad Traffic Quality: invalid activity, MRC Invalid Traffic Detection and Filtration Standards Addendum (June 2020 update)