Business

DoubleVerify Uncovers ShadowBot Scheme Involving 35 Million Spoofed Mobile Devices

NEW YORK, June 25, 2025--DoubleVerify ("DV") (NYSE: DV), the leading software platform to verify media quality, optimize ad performance, and prove campaign outcomes, today released the discovery of ShadowBot, a fraudulent bot scheme that generated over 35 million spoofed mobile devices in Q1 2025 and cost unprotected advertisers an estimated $2.5 million since the start of 2025.

articleDoubleverify Holdings, Inc.June 25, 20253/company/doubleverify-holdings-inc/news/doubleverify-uncovers-shadowbot-scheme-involving-130000594
DoubleVerify Uncovers ShadowBot Scheme Involving 35 Million Spoofed Mobile Devices

About this update from Doubleverify Holdings, Inc.

[{"type":"text","content":"DV’s Fraud Lab detected amateur-level fraudster mistakes behind a $2.5M fraud operation targeting CTV and mobile inventory","length":122,"tagName":"p","attribs":{}},{"type":"text","content":"NEW YORK, June 25, 2025--(BUSINESS WIRE)--DoubleVerify ("DV") (NYSE: DV), the leading software platform to verify media quality, optimize ad performance, and prove campaign outcomes, today released the discovery of ShadowBot, a fraudulent bot scheme that generated over 35 million spoofed mobile devices in Q1 2025 and cost unprotected advertisers an estimated $2.5 million since the start of 2025.","length":408,"tagName":"p"},{"type":"text","content":"The DV Fraud Lab identified ShadowBot targeting mobile and Connected TV (CTV) environments using rudimentary automation techniques, including mobile emulators and spoofed app IDs. While the scheme was widespread, it was riddled with amateur-level mistakes, making it detectable for advertisers protected by DV’s advanced fraud-detection systems.","length":345,"tagName":"p"},{"type":"text","content":""ShadowBot shows that fraud doesn’t need to be sophisticated to be costly," said Gilit Saporta, VP Product, Fraud & Quality at DoubleVerify. "It’s alarming to see $2.5M lost to bots using resolutions of an old CRT screen we all used back in the 1990s. The fraud scheme operator didn’t even bother to match its fake device signals to a proper mobile device. We’re happy to know that DV clients remain safe, thanks to DV’s AI-powered Fraud Lab, which catches subtle deviations from normal user behavior. That’s how we uncover the most sophisticated schemes out there, as well as the easier cases like ShadowBot."","length":634,"tagName":"p"},{"type":"text","content":"DV Fraud Labs identified five key red flags that uncovered ShadowBot:","length":69,"tagName":"p"},{"type":"list","items":[{"val":[{"type":"text","content":"Basic Automation Methods: ShadowBot used emulators that defaulted to screen resolutions (e.g., 800x600). This resolution is not typical for mobile devices.","length":155,"tagName":"p","attribs":{}}]},{"val":[{"type":"text","content":"Overly Aggressive Traffic Generation: The operation produced abnormally high impression volumes that didn’t align with seasonal trends.","length":135,"tagName":"p","attribs":{}}]},{"val":[{"type":"text","content":"Suspicious IP Activi...

More updates from Doubleverify Holdings, Inc.

ShadowBotDoubleVerifyFraudstersmobile devicesmedia qualityenvironmentsfraud schemeConnected TV