Duplicate IP
What is Duplicate IP?
Duplicate IP is a mobile ad fraud tactic where multiple app installs are generated from the same IP address within a short period of time. Fraudsters use this method to artificially inflate install counts, manipulate app store rankings, and generate fraudulent advertising revenue. Because legitimate users sharing a single IP address is uncommon at scale, repeated installs from the same IP are a strong signal of fraudulent activity.
How it works
Duplicate IP fraud operates by directing automated bots or coordinated devices through a single IP address to simulate real user behavior at high volume.
Automated Bots and Scripts
Fraudsters deploy automated software that mimics user actions such as clicking on ads and completing app installs. These bots run repeatedly from the same IP address, producing a large volume of install events that appear to originate from distinct users but share a common network identifier.
Networked Devices and Virtual Private Servers
A group of physical devices or virtual private servers can be routed through a shared IP address. Each device executes install simulations independently, but all traffic originates from one identifiable network point. This allows fraudsters to scale operations while keeping infrastructure costs low.
Secondary Fraud Activities
Beyond inflating install counts, the same infrastructure is used to generate fake reviews, manipulate app ratings, and produce artificial in-app engagement signals. This broader activity makes the targeted app appear organically popular, compounding the damage to advertisers and legitimate marketers.
Why it matters
Duplicate IP fraud directly erodes advertising budgets by attributing real spend to installs that will never convert into genuine users. Advertisers paying on a cost-per-install basis receive no return on fraudulent installs, while app store rankings become distorted by artificially inflated numbers. Detection of duplicate IP patterns is a foundational layer of fraud prevention for any mobile measurement strategy. Mobile measurement partners (MMPs) like Airbridge apply IP-level analysis as part of broader fraud detection pipelines, flagging clusters of installs from identical IP addresses within anomalously short time windows and blocking those installs from counting toward campaign metrics.
How to detect and protect against duplicate IP fraud
Protecting campaigns from duplicate IP fraud requires both proactive setup and ongoing monitoring.
1. Monitor IP-level install clustering. Configure your MMP to flag cases where multiple installs originate from the same IP address within a defined time window. A burst of installs from one IP is a reliable fraud signal.
2. Set install velocity thresholds. Establish limits on how many installs from a single IP address are considered valid within a given period. Installs exceeding that threshold should be quarantined for review or automatically rejected.
3. Cross-reference click-to-install time (CTIT). Fraudulent installs generated from the same IP often share unnaturally short or identical CTIT values. Combining IP analysis with CTIT distribution checks significantly improves detection accuracy.
4. Use blocklists for known fraudulent IPs. Maintain and apply blocklists of IP addresses previously associated with fraudulent activity. MMPs and ad networks often provide updated lists that can be integrated into your campaign setup.
5. Evaluate publisher-level traffic quality. Break down install data by publisher and sub-publisher to identify traffic sources disproportionately associated with duplicate IPs. Pause or terminate relationships with consistently problematic sources.
6. Enable real-time fraud rejection. Work with your MMP to reject duplicate IP installs in real time rather than post-campaign. Real-time rejection prevents fraudulent installs from influencing attribution decisions and campaign optimization signals.
Related concepts
| Term | Relationship | Description |
|---|---|---|
| Click Spam | See also | High-volume fraudulent clicks that share infrastructure patterns with duplicate IP schemes. |
| Install Fraud | Parent | Broader category of fraud that encompasses duplicate IP as one method of faking installs. |
| Phone Farms | See also | Physical device networks sometimes used to generate duplicate IP traffic at scale. |
| Device ID Reset Fraud | See also | Fraud tactic that resets device identifiers to simulate new users, often combined with IP manipulation. |
| Click Fraud | See also | Fraudulent click generation that frequently co-occurs with duplicate IP install fraud. |
Put these concepts into practice
See how Airbridge helps teams implement mobile attribution strategies at scale.