Seatext library / BotRefund evidence
How Click Injection Works in Android Mobile Ad Fraud
Click injection is a mobile ad fraud technique where a malicious app listens for Android system broadcasts and fires a fake click just before a legitimate app install, stealing attribution credit from other ad...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Click injection is a mobile ad fraud technique that exploits Android's broadcast system to steal credit for app installs. A malicious app installed on a device waits for a legitimate install to happen, then fires a fake click milliseconds before the install is recorded. Attribution platforms see the fake click as the source, and the fraudster gets paid as if they drove the install.
This article explains the exact process, why Android is vulnerable, how to detect it, and what you can do about it.
What is Click Injection?
Click injection is a type of mobile ad fraud where a bad actor intercepts or triggers a click event that looks legitimate to mobile measurement partners (MMPs). The goal is to claim attribution for an install that came from another source. Unlike click spamming—which sends many random clicks to cover a range of sources—click injection is surgical: it waits for a real install and then pretends that the install came from a fake click.
This fraud primarily targets Android devices because of how the operating system handles broadcasts and install events.
How Click Injection Works on Android
The process follows a specific sequence.
- A malicious app is installed. It could be a flashlight app, a game, or any program that asks for reasonable permissions. It often comes from outside Google Play, but may also slip into the official store.
- The app registers for system broadcasts. Android broadcasts events like
INSTALL_REFERRER,PACKAGE_ADDED, andBOOT_COMPLETED. Malicious apps listen for these to know when another app is being installed. - The app fires a fake click. When it detects that the target app is about to be installed (or just after), it launches an intent that carries the target app's package name, a click ID, and other attribution data. This often happens within milliseconds of the install.
- The MMP records the click as the source. The fake click arrives just before the install is confirmed, so the attribution platform credits that click with driving the install. The fraudster gets paid for a user it never acquired.
This works because Android's broadcast system does not require the receiving app to be active or for the sender to have a user-visible action. The malicious app can run in the background and trigger the click without the user noticing.
Why Android is Especially Vulnerable
Android is open by design. Apps can declare intent filters for system broadcasts and receive them without needing special permissions. On top of that, users can sideload apps from unknown sources, which makes it easy for fraudsters to distribute malicious apps outside of the Play Store's controls.
Even when apps do come from Google Play, Google's verification is not foolproof. Fraudsters have repeatedly found ways to circumvent review processes and publish apps that contain hidden click injection logic.
How Click Injection Differs from Click Spamming
Click spamming sends a large volume of clicks to many publishers, hoping some will line up with real installs. Click injection is targeted. It only acts when a real install is detected, so it produces a much higher false-attribution rate. For advertisers, this means every install attributed to a malicious source is money wasted.
Another difference is the timing. Click spamming clicks often arrive hours or days before an install, while click injection clicks arrive seconds or milliseconds before the install event. Detection systems look for this extremely short time gap as a red flag.
How to Detect Click Injection
You can spot it by examining the click-to-install time. If the gap is consistently under one second, it is a strong signal. Other signs include:
- Clicks from the same device or IP that also generate many other unexplained installs
- Clicks occurring at unusual hours or in bursts
- A high rate of installs from a single source with no corresponding ad exposure
- Installs that happen without any prior impression or click from the claimed network
Using an MMP with built-in fraud detection helps, but you should also review your raw data and set up custom alerts for short install windows.
How to Prevent and Respond
Prevention starts with controlling which apps can listen for broadcasts. In your own app, you can specify that the INSTALL_REFERRER broadcast only be sent to your app or to trusted partners. You can also use services that verify the referrer server-side and reject any click that arrives after the install has begun.
If you already have attributed installs from click injection, you can:
- Gather evidence of the fraud (timestamps, device IDs, and broadcast logs)
- Submit invalid traffic disputes to the ad platform (Google, Facebook, etc.)
- Work with a fraud mitigation service that can prove the fraud and negotiate refunds
Many advertisers recover a significant portion of wasted spend by filing detailed refund requests with evidence. Services like BotRefund can automate proof collection and negotiations.
Key Facts About Click Injection and Ad Fraud
| Metric | Fact |
|---|---|
| Budget loss | Bot clicks steal up to 20% of your Google and Meta ad budget. |
| Refund approval | Approved rate across client refund claims submitted to ad platforms shows real recovery is possible. |
| Setup time | Typical time to add BotRefund to your website and start a free bot audit is about one minute. |
| Accuracy | BotRefund uses 106 independent checks and claims 99% accuracy in identifying bot vs. human. |
Limitations and When This Advice Doesn't Apply
Click injection is not the only mobile ad fraud. SDK spoofing and device farms also steal attribution. The detection methods above work best for click injection because they rely on timing and click behavior. If fraud uses other methods, you may need different tools.
Also, not every short click-to-install gap is fraud. Some clicks come from users who click an ad and then install the app within a second because they were already planning to do so. Always look at patterns across many events rather than a single incident.
FAQ
What does click injection cost advertisers?
It can cost a significant portion of mobile ad budgets. Industry sources estimate that mobile ad fraud, which includes click injection, diverts millions of dollars each year.
Can click injection happen on iOS?
Rarely. iOS restricts how apps can observe installs and broadcasts. Most click injection targets Android due to its open broadcast model.
How do I know if my app is being hit by click injection?
Check your attribution data for a pattern of very short click-to-install times, especially from sources that are not credible or that you have not heard of. A sudden spike of installs from one source can also be a clue.
Can I get my money back from Google or Facebook for click injection?
Yes, you can file invalid traffic disputes with the ad platforms. You need to provide clear evidence in the form of click and install logs that show the injection pattern. Some platforms will issue refunds if the evidence is strong.
What is the difference between click injection and click spamming?
Click injection acts only when a real install is about to happen, while click spamming sends many clicks regardless. Injection is more precise and harder to detect.
Does BotRefund work for mobile installs?
BotRefund focuses on website and app ad spend from Google and Meta. It detects bots that click ads and helps recover refunds. For mobile click injection, you may need a separate mobile measurement partner.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.