Sophisticated 'SkyWalk' ad fraud scheme evades standard mobile measurement tools
DoubleVerify has identified a sophisticated iOS ad fraud scheme dubbed 'SkyWalk' that uses a framework called UniSkyWalking to load hidden websites within mobile games. The scheme circumvents Open Measurement SDK detection by misrepresenting in-app traffic as web traffic to generate fraudulent ad impressions.
Key Takeaways
- Fraudulent iOS app volume in early 2025 is triple the average reported over the previous five years.
- The SkyWalk scheme uses hidden WKWebView objects to render over 80 fake gaming websites invisibly.
- Cybercriminals employ GenAI to populate 'cashout' websites with content to bypass manual audits.
- Touch hijacking technology translates user interaction in games into clicks on background ad triggers.
Why It Matters
This discovery highlights a significant technical vulnerability in the Open Measurement SDK, as fraudsters successfully mask in-app impressions as browser-based traffic to avoid detection. For advertisers, this means premium CPMs are being paid for 'vignette' formats that are never rendered on-screen, skewing performance data and wasting spend. The use of a coordinated C2 server to synchronize 'cashout' sites with app-level frameworks suggests ad fraud is becoming increasingly commoditized as a service. Market participants should monitor for updates to the IAB Tech Lab’s Open Measurement standards to see how they address background WebView manipulation.
Additional Context
The surge in sophisticated mobile ad fraud coincides with a broader industry shift toward more aggressive bot detection. Per Juniper Research in early 2024, global ad spend lost to fraud was projected to reach $172 billion by 2028, with mobile and CTV environments being the primary targets due to higher CPMs. This aligns with recent findings from Pixalate, which reported in February 2025 that 'spoofing'—where a low-value app pretends to be a high-value one—remains the most prevalent form of mobile ad fraud, affecting nearly 15% of unverified programmatic traffic. Simultaneously, the IAB Tech Lab has been pushing for wider adoption of ads.cert and updated app-ads.txt protocols to combat the specific type of server-side and framework-based manipulation seen in SkyWalk. Per a March 2025 report from AdExchanger, Google and Apple have both faced increased regulatory pressure to purge 'zombie' or malicious apps from their respective stores, yet the ability for developers to embed hidden browsers within legitimate-looking games remains a persistent technical challenge. Industry observers note that as generative AI makes it easier to create plausible 'slop' sites, the cost of entry for creating a fraud network's front-end has plummeted.
Read full article at doubleverify.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source