Playbook: Triage an In-App Fraud Spike in Under an Hour
Dashboards screaming? Work top-down, not random:
— Segment installs by sub-publisher and sort by anomaly, not volume — fraud hides in mid-tier IDs
— Check click-to-install time (CTIT): a wall of installs under 10 seconds = click injection
— Look at the CTIT long tail too — installs days after click = click flooding / spam
— Pull new-device-rate per source; over 90% brand-new device IDs is device farming
— Cross-check IP concentration and datacenter ASNs against install clusters
— Inspect in-app event timing — events firing in identical intervals are scripted
— Freeze payouts on the worst sub-publishers before deeper analysis
✓ Isolates the bad source fast without pausing good traffic
✓ Uses signals every MMP already exposes
✗ CTIT alone mispredicts on slow-download geos
✗ Sophisticated fraud mimics human timing — needs deeper tooling
Verdict: Use CTIT + new-device-rate for the 80% case; escalate to a dedicated fraud tool when patterns look human.
Best for: UA and ad-ops triaging suspicious in-app volume in real time.
In-App Bench
@InAppBench
Playbook: Triage an In-App Fraud Spike in Under an Hour
Этот пост опубликован в Telegram-канале In-App Bench. Подписаться можно по ссылке: @InAppBench.