Illustration: Rebecca Zisser/Axios

A new ad fraud scheme targeting premium publishers on connected TVs (CTV) and mobile has been uncovered by DoubleVerify, an ad fraud analytics company. The botnet, called MultiTerra, was stealing roughly $1 million per month from publishers by spoofing their ad inventory.

Why it matters: Premium publishers were particularly vulnerable to this particular attack because their ad rates (CPMs) are so high, making them an efficient target. CTV is any TV set that streams video over the internet.

Details: The botnet has been named MultiTerra because of the complex multi-device targeting scheme it used to trick publishers and brands.

  • At its peak between June and August, the botnet was generating over three million fake ad requests per day.
  • One of the distinctive features of the MultiTerra botnet was that it targeted publishers at the IP-address level, allowing it to generate intense bursts of thousands of fake impressions very quickly.
  • For example, in just 20 minutes, a single IP in the botnet impersonated 16 different smart phones, requesting nearly 50 fake impressions to at least 9 different premium publisher apps.
  • "What was interesting here is that it mutated sometimes in days or within hours," says Roy Rosenfeld, Head of DoubleVerify's Fraud Lab. "That's very aggressive."
  • "That's something that you usually see in cybercrime."

The big picture: CTV is one of the fastest growing advertising mediums alongside mobile, but it's vulnerable to ad fraud because its rates are the most expensive in the industry and the demand for CTV ad inventory is currently greater than the supply.

  • "In an environment where supply is scarce, fraud deprives reputable and trustworthy publishers of their monetization opportunities because lots of fake impressions negatively affect the demand of the real ad inventory," says Dan Slivjanovski, CMO of DoubleVerify.
  • CTV ad fraud is up 161% year over year, the highest of any type of ad inventory out there. DoubleVerify has identified 1,300 fraudulent CTV apps in 2020 alone.

The bottom line: "It's one of the most aggressive ad fraud schemes that we've seen recently," says Rosenfeld.

Go deeper

Mike Allen, author of AM
Oct 7, 2020 - Politics & Policy

Former bipartisan top officials use $4 million ad buy to build faith in elections

Screenshot via YouTube

The National Council on Election Integrity, a bipartisan group of 40 former U.S. officials trying to promote faith in elections, will launch a $4 million TV and digital ad buy on Thursday.

What they're saying: "While this election may feel different, we all call America home," says the ad, titled "Americans."

Updated 29 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Annelise Capossela/Axios

  1. Politics: Trump says if Biden's elected, "he'll listen to the scientists"Trump calls Fauci a "disaster" on campaign call — Fauci says he's "absolutely not" surprised Trump got coronavirus.
  2. Health: Coronavirus hospitalizations are on the rise — 8 states set single-day coronavirus case records last week.
  3. Business: Consumer confidence surveys show Americans are getting nervousHow China's economy bounced back from coronavirus.
  4. Sports: We've entered the era of limited fan attendance.
  5. Education: Why education technology can’t save remote learning.

Trump calls Fauci a "disaster" on campaign call

Photo: Stephen Lam/Getty Images

During a campaign call on Monday, President Trump slammed infectious disease expert Anthony Fauci, calling him a "disaster," and that "people are tired of COVID," according to multiple reporters who listened to the call.

Driving the news: CBS's "60 Minutes" aired an interview Sunday night with the NIAID director, where he said he was "absolutely not" surprised Trump contracted COVID-19 after seeing him on TV in a crowded place with "almost nobody wearing a mask."

Get Axios AM in your inbox

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Subscription failed
Thank you for subscribing!