Install hijacking
What is Install hijacking?
Install hijacking is a type of mobile ad fraud in which an attacker intercepts or fabricates signals during the app install process to falsely claim attribution credit for a legitimate install. The goal is to divert advertising commissions away from the legitimate traffic source that drove the install. Install hijacking affects both Android and iOS platforms and uses techniques ranging from click injection to device emulation.
How it works
Install hijacking exploits the window between a user initiating an app install and the attribution system recording it. Because mobile measurement partners (MMPs) typically attribute an install to the last qualifying click before the install event, attackers race to insert a fraudulent click into that window, displacing the legitimate source.
Click Injection
Click injection is one of the most prevalent forms of install hijacking on Android. Malware installed on a user's device listens for broadcast signals that indicate an app is being downloaded. When the signal fires, the malware injects a fake click, timestamped just before the install completes. This manufactured click wins last-touch attribution, redirecting the commission to the fraudster.
Click Spoofing
Click spoofing involves generating large volumes of fake clicks that impersonate real users. Attackers use bots or scripts to simulate device behavior and ad interactions, flooding the attribution system with fraudulent signals. When a real user genuinely installs the app, one of the pre-seeded fake clicks is close enough in time to claim credit.
Device Emulation
Attackers use emulators or virtual machines to simulate physical devices at scale. These emulated devices generate fake install events that appear legitimate to ad networks and attribution platforms. Because the signals mimic real device fingerprints, detection requires deep behavioral and technical analysis.
Click Farms
Click farms deploy real people using real devices to manually interact with ads and trigger installs. Because actual hardware and human behavior are involved, these operations are harder to filter using purely automated detection signals. The installs themselves may be genuine, but they are manufactured solely to generate fraudulent attribution credit.
Why it matters
Install hijacking directly damages advertiser return on investment by routing commissions to fraudulent sources rather than the publishers or channels that genuinely drove user acquisition. Advertisers pay for installs that were already going to happen organically or that were driven by a different legitimate source, meaning budget is wasted with no incremental value delivered.
Beyond financial loss, hijacked attribution corrupts campaign data. Advertisers who rely on attribution data to optimize spend, compare channel performance, or forecast lifetime value are working from a distorted picture. Publishers and ad networks that legitimately drove performance lose credit and revenue, creating misaligned incentives across the ecosystem.
MMPs play a central role in defending against install hijacking. Airbridge, for example, applies click-to-install time (CTIT) analysis and behavioral validation to identify anomalous attribution patterns. Installs attributed to clicks with implausibly short CTIT values, or clicks that cluster around Android install broadcast events, are strong signals of click injection and are flagged accordingly.
How to protect against install hijacking
Protecting against install hijacking requires a combination of partner validation, attribution hygiene, and ongoing monitoring.
Analyze click-to-install time (CTIT). Legitimate user journeys have a natural time gap between ad click and app install. CTIT distributions that show a large spike of installs occurring within seconds of a click are a reliable indicator of click injection. Configure your MMP to flag or reject installs with CTIT values outside expected ranges.
Work with verified ad networks and publishers. Partner with ad networks that enforce app-ads.txt and supply-path transparency standards. Use blocklists to exclude known fraudulent sources and sub-publishers with suspicious traffic patterns. Regularly audit your publisher list and review sub-publisher performance.
Monitor for duplicate IP and device anomalies. A high volume of installs originating from the same IP address or device ID cluster points to emulator-based fraud or click farm activity. Set threshold alerts in your analytics dashboard and investigate outliers promptly.
Enable fraud protection at the MMP level. MMPs such as Airbridge provide built-in fraud detection that evaluates attribution signals in real time, including CTIT, device integrity checks, and behavioral scoring. Leveraging these tools ensures fraudulent installs are filtered before they distort your campaign data or trigger payouts.
Audit attribution windows regularly. Overly broad attribution windows increase exposure to install hijacking by giving attackers more time to insert a fraudulent click. Review your lookback window settings and tighten them where the data supports doing so.
Validate installs with receipt validation where applicable. For installs tied to in-app purchase flows, receipt validation adds a layer of verification that confirms the install occurred on a real device through a legitimate storefront transaction.
Related concepts
| Term | Relationship | Description |
|---|---|---|
| Click Injection | Method | The primary technique used in install hijacking, inserting fake clicks just before an install completes to steal attribution. |
| Click Fraud | Parent | The broader category of fraud involving fabricated click events, of which install hijacking is a targeted variant. |
| SDK Spoofing | Variant | A related fraud technique that fabricates entire install and event signals at the SDK level without a real device. |
| Click-to-Install Time (CTIT) | Detection | The primary signal used to detect install hijacking by identifying suspiciously short gaps between click and install. |
| Install Fraud | Parent | The overarching category of fraud targeting the install event, encompassing install hijacking and related schemes. |
Put these concepts into practice
See how Airbridge helps teams implement mobile attribution strategies at scale.