Inside a scam campaign: how a link shortener operator caught and tracked ad fraud
The operator of a small free link shortener discovered a suspicious destination that had accumulated nearly 90,000 clicks in just 48 hours, far exceeding all other traffic on the platform combined. After deleting the offending links, the scammer re-registered them within minutes, prompting a cat-and-mouse deletion cycle. Investigation revealed the destination URL served different content depending on who requested it — redirecting automated scanners harmlessly to Yahoo, while delivering a 42,000-byte fingerprinting payload to real Android users arriving via Facebook's in-app browser. The payload checked for bot indicators, ad blockers, GPU data, and even cursor movement, silently discarding any visitor it deemed non-human with a fake success animation. The scheme relied on a high-authority domain with a Domain Rating of 50, built on a vast network of inbound links from pirate streaming sites, indicating a well-resourced and persistent ad fraud operation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in