Home Mobile Oracle Data Cloud Companies Expose ‘DrainerBot’ App Fraud Scheme

Oracle Data Cloud Companies Expose ‘DrainerBot’ App Fraud Scheme

SHARE:

Oracle has uncovered an ad fraud operation it calls “DrainerBot,” which siphoned off ad dollars and monthly data packages.

Oracle’s internet infrastructure business Dyn originally discovered the operation after it picked up suspicious activity among some mobile apps using an SDK from Tapcore, a Dutch mobile monetization company. The apps obscured web data with proxy servers and loaded suspicious ads.

AdExchanger reached out to Tapcore via its website, but hasn’t received a response.

Tapcore’s SDK is supposed to run in the background of an app and only activate if the user downloads a pirated version of the original app. It would allow the original developer to serve ads into the pirated app if the user downloaded a ripped-off, ad-free version of a mobile game, for example.

But Tapcore was also using its SDK to generate fake ad impressions, using a bogus browser it side-loaded into the app that wasn’t visible to the user.

“The side-loading phenomenon is something we have to keep an eye on,” said Dan Fichter, the data cloud’s VP of software engineering and former CTO of Moat, another Oracle business that was enlisted by Dyn to understand the dubious server activity. “As a general pattern it’s a way in which fraudsters can get well-intentioned developers to work on their behalf.”

The DrainerBot ads may have been hard to identify as illegitimate, but the software directly affected people’s phones and monthly data rates. With the fake browser running in the background, phones with the Tapcore SDK drained battery and data, Fichter said.

Oracle worked with the Trustworthy Accountability Group (TAG) and Google, which housed some of the affected apps on its Android operating system and Play Store, to mitigate ad spend on Tapcore apps while it scrutinized the operation.

“This is becoming a nice trend where some of these more sophisticated tech companies are now able to identify and track major botnets,” said Mike Zaneis, TAG president and CEO. “It takes time though, and we’re developing this ability to make our members aware of the issue and protect the market while a botnet is being tracked.”

Previously, exposing ad fraud operations was like nailing smoke to a wall. But with better technology and more players in the ecosystem willing to collaborate on fraud prevention, companies like White Ops, Google and DoubleVerify – not to mention the FBI – have exposed a string of ad fraud schemes in recent months.

“People are good at tracking fraud but see different slices of the ecosystem,” Zaneis said.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Fichter said the combination of Moat and Dyn was critical for exposing the DrainerBot operation and for Oracle’s fraud prevention approach. Dyn focuses on infrastructure-level internet security threats while Moat addresses transparency and ad fraud.

“Having the threat research teams making discoveries like [DrainerBot] that use advertising is hugely useful,” he said. “And it works the other way as well. Computers and devices that are compromised and used for ad fraud could be used for something else tomorrow.”

Must Read

The Arena Group's Stephanie Mazzamaro (left) chats with ad tech consultant Addy Atienza at AdMonsters' Sell Side Summit Austin.

For Publishers, AI Gives Monetizable Data Insight But Takes Away Traffic

Traffic-starved publishers are hopeful that their long-undervalued audience data will fuel advertising’s automated future – if only they can finally wrest control of the industry narrative away from ad tech middlemen.

Q3: The Trade Desk Delivers On Financials, But Is Its Vision Fact Or Fantasy?

The Trade Desk posted solid Q3 results on Thursday, with $739 million in revenue, up 18% year over year. But the main narrative for TTD this year is less about the numbers and more about optics and competitive dynamics.

Comic: He Sees You When You're Streaming

IP Address Match Rates Are a Joke – And It’s No Laughing Matter

According to a new report, IP-to-email matches are accurate just 16% of the time on average, while IP-to-postal matches are accurate only 13% of the time. (Oof.)

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Comic: Gamechanger (Google lost the DOJ's search antitrust case)

The DOJ And Google Sharpen Their Remedy Proposals As The Two Sides Prepare For Closing Arguments

The phrase “caution is key” has become a totem of the new age in US antitrust regulation. It was cited this week by both the DOJ and Google in support of opposing views on a possible divestiture of Google’s sell-side ad exchange.

create a network of points with nodes and connections, plain white background; use variations of green and grey for the dots and the connctions; 85% empty space

Alt Identity Provider ID5 Buys TrueData, Marking Its First-Ever Acquisition

ID5 bought TrueData mainly to tackle what ID5 CEO Mathieu Roche calls the “massive fragmentation” of digital identity, which is a problem on the user side and the provider side.

CTV Manufacturers Have A New Tool For Catching Spoofed Devices

The IAB Tech Lab’s new device attestation feature for its Open Measurement SDK provides a scaled way for original device manufacturers to confirm that ad impressions are associated with real devices.