Characterizing Large-Scale Click Fraud in ZeroAccess

Click fraud is a scam that hits a criminal sweet spot by both tapping into the vast wealth of online advertising and exploiting thatecosystem’s complex structure to obfuscate the flow of money to itsperpetrators. In this work, we illuminate the intricate nature of thisactivity through the lens of ZeroAccess—one of the largest clickfraud botnets in operation. Using a broad range of data sources, including peer-to-peer measurements, command-and-control telemetry, and contemporaneous click data from one of the top ad networks, we construct a view into the scale and complexity of modernclick fraud operations. By leveraging the dynamics associated withMicrosoft’s attempted takedown of ZeroAccess in December 2013,we employ this coordinated view to identify “ad units” whose traffic (and hence revenue) primarily derived from ZeroAccess. Whileit proves highly challenging to extrapolate from our direct observations to a truly global view, by anchoring our analysis in the datafor these ad units we estimate that the botnet’s fraudulent activitiesplausibly induced advertising losses on the order of $100,000 perday.


