CTIT fingerprinting exposed a sub-source faking installs: 23% clawed back
A buyer's MMP showed clean aggregate fraud scores, but one sub-publisher's click-to-install-time histogram was bimodal — a normal hump plus a hard spike under 10 seconds.
That sub-10s spike is the signature of install hijacking: the fraudster fires a click the instant a real install begins.
Isolating that sub-publisher and appealing recovered 23% of its installs as rejected.
✓ Sub-source CTIT beats account-level fraud scores for granularity
✓ Hijacking has a distinct, repeatable time signature
✗ Requires raw-data export and your own histogram tooling
✗ Networks dispute click-hijack claims harder than click-spam
Verdict: pull CTIT per sub-publisher; aggregates hide the fraud.
Best for: anyone buying via blind sub-publisher networks.
In-App Bench
@InAppBench
CTIT fingerprinting exposed a sub-source faking installs: 23% clawed back
Этот пост опубликован в Telegram-канале In-App Bench. Подписаться можно по ссылке: @InAppBench.