By Lia Bader, Lead Fraud Analyst, DV Fraud Lab
Connected TV (CTV) represents the industry’s final frontier of premium, high-trust inventory. Advertisers are paying exorbitant, "living room" CPMs to secure a spot on the big screen, banking on the high-engagement levels that television provides. Yet, beneath this premium surface lies a systematic poisoning of the supply chain. This "ghost in the machine" allows sophisticated botnets to engage in premium CPM arbitrage, siphoning off billions in high-value spend. Advertisers are increasingly paying for impressions that never reach a human eye, let alone a television.
The following examples demonstrate how fraud schemes, now heavily aided by AI and vibe-coding practices, keep stumbling on mistakes made by the earlier generations of attacks. From the 2022 examples of “Refrigerator Fraud,” to the 2025 and 2026 examples of ShadowBot, rotating from old cathode ray tube (CRT) screen resolutions to fake iPod Touch falsifications; fraud signals are sprinkled all around the CTV ecosystem. This is where the DV Fraud Lab is here to help.
Over the years, the DV Fraud Lab has uncovered dozens of fraud operations that target digital video. Most schemes weaponized Server-Side Ad Insertion (SSAI) spoofing to manufacture counterfeit inventory spanning an unlimited number of apps and IP addresses. In this scheme, fraudsters exploit SSAI as a "blind spot.”
SSAI servers sit between the ad server and the device to facilitate seamless streaming. Therefore, they provide the perfect cover for criminals to inject fraudulent signals that bypass standard detection. Any piece of data can be spoofed when passing through a fake SSAI server, so fraudsters can get away even with absurd lies, such as attributing impression volume to a device discontinued years ago: the iPod Touch (as seen below, even in 2019 it was already considered a piece of nostalgia).
As seen below, with SSAI fraud schemes, everything is fake. They typically involve the fraudster spoofing legitimate devices and apps that are not harmful on their own. These schemes take place in three phases. First, the fraudsters gather the details of legitimate users (i.e., the IP addresses or app bundle IDs). Next, they copy these details to mask their activity from being detected. Finally, they use the spoofed details of legitimate users to send fraudulent ad requests into the ecosystem.
As SSAI fraud expanded into the Internet of Things (IoT) ecosystem, it hit a wall of human logic known as the "device-to-content mismatch.” While the botnet cycled through thousands of randomized device hardware profiles to appear diverse, it began claiming that thousands of hours of premium, long-form CTV content were being consumed on smart appliances.
The Self-Explanatory Truth: Nobody watches long-form premium streaming content on their refrigerator. Even in rare cases, where a smart fridge might have a screen for checking the weather or a recipe, human beings do not stand in their kitchens for two hours to binge-watch a drama series on a refrigerator door.
When the "ShadowBot" operation first emerged in late 2024, it was a massive but surprisingly clumsy attempt at siphoning premium budgets. This operation functioned as a high-volume, low-effort "bot farm" masquerading as premium inventory, generating over 3 million fraudulent device signatures per day.
However, the operation was initially betrayed by a tell-tale signature of technical laziness. The "premium streaming traffic" it was selling was linked to device signatures with screen resolutions associated with old-school cathode ray tube televisions, the bulky, glass-screen models that flat-screen technology made extinct nearly two decades ago.
This reveals a fundamental truth about bot operators: in their rush to achieve massive scale, they often rush towards AI-driven / vibe-coded alterations in their attack. Also, they often rely on outdated or randomized data sets. These "ghosts of technology past" serve as an immediate forensic red flag for anyone looking closely at the telemetry.
Even as we look toward 2026, the DV Fraud Lab continues to catch schemes making remarkably low-sophistication errors. One of the most persistent "identity crises" involves fraudsters attributing high-value living-room television traffic to handheld music players, such as the iPod Touch. This is only another step in a long chain of spoofed devices. As seen in the following timeline, bot schemes over the years have picked random device types to funnel falsified traffic:
The Self-Explanatory Truth: Nobody watches long-form premium streaming content on their iPod Touch. Even in rare cases, where an iPod Touch can be mirrored to a larger screen, its telemetry would reflect this situation. Fraud schemes simply make a mistake fueled by an AI hallucination which measurement vendors must catch.
To combat these persistent fraud variants, buyers must look beyond the surface level of a reported impression and demand independent, multi-signal measurement. To catch these sophisticated "mismatches," ad verification must monitor specific forensic signals:
We must always brace for the days when simple CRT-resolution errors will fade as ShadowBot and its variants evolve.
Likely aided by AI, newer iterations of these bots have begun to develop "adaptive patterns" that allow them to mimic modern device profiles with chilling accuracy. This increased sophistication allows "super-bots" to falsify up to 200 million monthly impressions.
By mimicking the specific technical signatures of modern smart TVs and high-end streaming sticks, these bots can evade many standard filters used by advertisers who lack proper, multi-signal protection. Most concerning is that these variants are no longer confined to the dark corners of open exchanges. They are successfully infiltrating the inventory of reputable platforms and even finding their way into direct deals, dispelling the myth that buying directly from a source is an inherent safeguard against fraud.
The evolution from the "lazy" CRT spoofs to AI-powered super-bots proves that the CTV landscape is under constant assault. As fraudsters use increasingly sophisticated tools to refine their deception, relying on a single data point is no longer a viable defensive strategy.
Advertisers must remain hyper-vigilant and demand transparency into the device-level telemetry behind their "premium" buys. In an era of AI-driven bots and spoofed servers, you must ask yourself: do you truly know which device is consuming your spend, or are you simply paying for a rom-com being "watched" by an iPod Touch, or a refrigerator?