See it live

glossary

Click Injection

Click injection is a sophisticated mobile ad fraud where malicious apps hijack legitimate installs by firing fake clicks milliseconds before the install completes. The fraudster claims the CPI payout. You pay for organic installs you already earned.

Quick Definition

Click injection is a sophisticated mobile ad fraud where malicious apps hijack legitimate installs by firing fake clicks milliseconds before the install completes. The fraudster claims the CPI payout. You pay for organic installs you already earned.

What is Click Injection

Click injection targets Android apps through the “install broadcast” feature. When a user downloads your app, Android broadcasts the install event to all apps on the device. Malicious apps listen for this broadcast, then fire a fake ad click just before the install finalizes.

The attribution system sees the fake click, thinks it drove the install, and credits the fraudster. You just paid for an install that was going to happen anyway.

This fraud scales fast. One malicious app on millions of devices can steal attribution from thousands of legitimate installs daily.

How It Works

Step 1: The Setup User installs a malicious app (flashlight app, game, utility). That app silently monitors for install broadcasts from other apps.

Step 2: The Trigger User downloads your game from an organic source (App Store search, friend recommendation, YouTube video). Android broadcasts the install event.

Step 3: The Hijack The malicious app detects your game’s install broadcast. It fires a fake click attributed to a fraudulent ad network. Timing is precise: milliseconds before your game finishes installing.

Step 4: The Payout Your MMP sees the fake click, then the install. Time between click and install (CTIT) is abnormally short (seconds, not hours). But if fraud filters aren’t tuned correctly, the fraudster gets credited. You pay for an install you didn’t buy.

Click Injection vs Click Spamming

Both steal attribution. The tactics differ.

| Fraud Type | CTIT Pattern | Method | |————|————–|——–| | Click Injection | Abnormally short (seconds) | Fires fake click right before install completes | | Click Spamming | Normal or long (hours/days) | Fires thousands of fake clicks hoping one matches a future install |

Click injection is surgical. It knows an install is happening and hijacks it in real time.

Click spamming is spray-and-pray. It fires random clicks at device IDs hoping to get lucky when those users eventually install apps.

Detection requires different approaches. Click injection shows up in CTIT analysis. Click spamming shows up in abnormal click volume patterns.

Detection Methods

CTIT Analysis (Click-to-Install Time)

The primary signal. Click injection creates impossibly short CTIT windows.

Normal CTIT: Minutes to hours. User sees ad, clicks, downloads, installs. Click Injection CTIT: Seconds. Fake click fires right before install completes.

Red flags:

  • CTIT under 10 seconds
  • Large volume of installs with sub-30-second CTIT
  • Partner showing dramatically shorter CTIT than network average

MMP Fraud Filters

Trusted MMPs (Adjust, AppsFlyer, Branch) run fraud detection algorithms that flag:

  • Abnormal CTIT distributions by partner
  • Device patterns (same device triggering multiple suspiciously timed installs)
  • Click patterns inconsistent with user behavior

Enable these filters. Review flagged traffic weekly.

Post-Install Engagement

Organic installs typically show higher engagement than paid. If a partner’s “conversions” show engagement rates matching your organic baseline, they might be stealing organic attribution.

Track Day 1, Day 7, and Day 30 retention by source. Click injection victims show organic-level engagement but paid attribution.

Prevention Strategies

1. Monitor CTIT Religiously

Pull CTIT reports weekly. Flag any partner with median CTIT under 2 minutes. Investigate immediately.

2. Vet Your Partners

Work with known networks and verified publishers. New partners require extra scrutiny. Start with small test budgets and watch CTIT patterns closely.

3. Enable MMP Fraud Protection

Adjust, AppsFlyer, and Branch all offer click injection filters. Turn them on. Review rejected traffic reports. Block sources flagged repeatedly.

4. Track Post-Install Engagement

Compare retention and LTV by source. Fraudulent traffic often shows engagement mismatches (paid attribution, organic behavior).

5. Contractual Protection

Include fraud clauses in partner agreements. Require refunds for traffic flagged by your MMP. Make fraud a breach-of-contract issue.

Common Mistakes

Ignoring CTIT data You track CPI and ROAS but skip CTIT analysis. Click injection hides in those numbers.

Trusting “too good to be true” partners A new network delivers $0.50 CPI when market rate is $2.00. You scale spend instead of investigating. Six months later your MMP flags 60% of their traffic as fraud.

Disabling fraud filters to hit volume goals Your MMP’s fraud filter rejects 30% of a partner’s traffic. You disable the filter to preserve the partnership. You’re now paying for fraud at scale.

Not checking post-install metrics A partner delivers cheap installs with great CTIT. You celebrate. Three weeks later you notice their Day 7 retention is 3x lower than other sources. You just bought hijacked organic users who would’ve installed anyway.

Related Terms

  • Click Spamming: Firing massive volumes of fake clicks hoping to match future organic installs
  • Attribution Fraud: Umbrella term for all fraud types that steal credit for legitimate conversions
  • Install Hijacking: Alternate term for click injection
  • CTIT (Click-to-Install Time): Time between ad click and app install; primary fraud detection signal
  • MMP (Mobile Measurement Partner): Attribution platform (Adjust, AppsFlyer, Branch)

External Resources

Frequently Asked Questions

What is click injection?

Click injection is mobile ad fraud where a malicious app detects that a real install is about to finish, then fires a fake ad click milliseconds beforehand. The attribution system credits the fraudster for an install that was going to happen anyway.

Is click injection only an Android problem?

Yes. It exploits Android’s install broadcast feature, which tells every app on a device when another app finishes installing. iOS doesn’t broadcast install events to third-party apps, so this specific exploit doesn’t work there.

What’s the difference between click injection and click spamming?

Click injection is surgical: it fires one fake click right before a real install completes, producing an abnormally short click-to-install time. Click spamming fires thousands of fake clicks hoping one eventually matches a future organic install.

How do I detect click injection?

Watch click-to-install time (CTIT). Normal CTIT runs minutes to hours. Click injection produces CTIT under 10-30 seconds. Pull weekly CTIT reports by partner and investigate anyone with a suspiciously short median.