White Ops has published today the white paper analysing the Methbot Operation, the largest audience fraud and web spoofing operation through bots that any organisation has commited ever.
Estimated financial impact of the Methbot fraud amounts to at least $3 to $5 million in revenue per day as of October 2016
The infrastructure of the Methbot operation comprises 571,904 dedicated IPs, many falsely registered as US ISPs and 800 – 1,200 dedicated servers operating from data centers in the United States and the Netherlands.
The objectie of White Ops is making Mathbot cease operations. Thats why the company releases the white paper Eastwind summarizes in this post.
Websites and market places spoofed with most expensive CPM at $36.72
CPMs (cost per thousnad) ranged from $3.27 to $36.72 with the average at $13.04.
Talking about the volume of the fraud, White Ops estimates between 200 – 300 million video ad impressions generated per day on fabricated inventory.
Around 250,267 distinct URLs were spoofed to falsely represent inventory. The white book calculates that 6,111 premium domains were targeted and spoofed.
Among the victims of this spoofing practice there are high value marketplaces targeted including PMPs (private marketplaces).
Advanced techniques to avoid bot traffic detection
Methbot operation uses advanced techniques to avoid detection.
Among these techniques they find faked clicks, mouse movements, and social network login information to appear as engaged human consumers. They also manipulate geolocation information associated with the IP addresses under their control.

Methbot operation also employs special case countermeasures against code from over a dozen different ad tech companies. They own as well a fully custom http library and browser engine with Flash support, all running under Node.js
A mutation of C3 bot dating back to September 2016
In September 2016, White Ops detected a mutation in a previously low volume bot signature which had been flagged as “C3” since September 2015. The security research team continued to track the evolution of C3 as it innovated and grew into what would become known as “Methbot.”
On October 5, 2016, Methbot began to scale aggressively, reaching as many as 137 million impressions per day by the end of the week.

Following the initial ramp in October, Methbot continued to produce massive amounts of impression volumes while continuing to adapt its codebase daily in an effort to elude fraud detection and viewability vendors and avoid discovery in order to continue the operation.
The Methbot business
Both human audiences and premium publisher inventory are in high demand. Thats why Methbot focuses on manufacturing both of these as its product. By supplying faked audiences and hijacking the brand power of prestigious publishers through faked domains and falsified inventory, Methbot is able to siphon away millions in real advertising dollars.
Specially built infrastructure
Methbot relies on specially buit infrastructure rather than on malware-infected residential coomputers as traditional bot networks.
This is because of the work needed to continually infect new home computers is huge, especially while existing infections are being discovered and cleaned by anti-malware vendors.

Methbot hass opted by investing significant time, research, development, and resources to build infrastructure designed to remove these limitations and provide them with unlimited scale.
Transparency, the only cure
White Ops underscores that in an automatised digital market such as the programatic just “a combination of human best practices and technological vigilance by verification companies can help the industry close ranks against these threats and increase certainty through transparency for everyone across the advertising spectrum.”
White Ops has partnered with The Trustworthy Accountability Group (TAG) tagtoday.net industry associations to facilitate the delivery and propagation of the data necessary to help bring the Methbot operation to a halt.
“We hope the public release of this research will result in a rapid end to this enterprise as White Ops remains on constant watch for new threats on the horizon.”
Image over the headline.- © White Ops.
Related external links:
The White Ops’ Report on Methbot Operation
Download: Spoofed Domains
Download: Full List of URLs
Download: Compromised IP Addresses
Download: IP Ranges (CIDR Format)













