Click redirection is a type of mobile ad fraud where a user is automatically redirected to an advertisement or app store page without intentionally clicking on it. It is also known as automatic redirection.
This technique uses hidden scripts that force a redirection when someone visits or clicks on a link within a website. The user often has no idea that this action occurred, but the fraudster receives credit for the click or app install that follows.
In mobile marketing, click redirection allows bad actors to steal credit for legitimate user actions, inflating their performance metrics and taking payouts that should belong to genuine media sources.
Click redirection typically happens through scripts embedded in a website or advertisement. When a user clicks anywhere on the page, or sometimes even just loads it, a hidden script triggers a redirect to a third-party landing page or app store listing.
For example, imagine a user browsing for sports highlights. They open a low-quality mobile website and tap on a link to watch a video. Instead of immediately seeing the video, the page opens a new tab that sends them to an app store page for a random app. Only after closing that page does the original content play.
That is click redirection in action. The fraudster’s goal is simple: trick attribution systems into believing a genuine user clicked on their ad, so they can claim the reward when the user later installs the app.
Fraudsters exploit weaknesses in ad attribution systems to make money. Since many advertising models reward the source of the “last click” before an install, redirecting users artificially creates that last click.
This makes the fraudster appear responsible for the install, even though the user’s real intent came from another channel. The result is misattributed installs, wasted ad spend, and distorted performance data for legitimate marketers.
Click redirection can also damage user trust, as it interrupts the browsing experience and can even lead to malicious sites.
Click redirection is often hard to detect because it happens instantly and invisibly. However, several indicators can help identify this type of fraud:
1. Unexpected traffic spikes
If your campaign reports large click volumes from specific publishers with very low engagement or conversion rates, this may indicate redirection.
2. Abnormal click-to-install times
When installs are linked to clicks that happen long before the user’s actual download, it suggests that a redirection script may have planted fake click data.
3. Multiple clicks from the same device or IP
Redirection scripts often generate several click events in seconds, which can appear as repeated clicks from a single source.
4. Poor user engagement metrics
Users acquired through redirected clicks often show very low retention because they never intended to engage with the app in the first place.
1. Use trusted ad networks
Work only with verified networks that have transparent traffic sources. Avoid unfamiliar publishers with poor domain reputations.
2. Employ fraud detection tools
Fraud prevention solutions can analyze click data to detect redirection patterns and flag suspicious IPs or traffic sources.
3. Monitor attribution data closely
Regularly check click-to-install times (CTIT), conversion rates, and publisher performance to spot irregularities.
4. Block automatic redirection scripts
Web security tools and browser settings can detect and block redirect attempts before they reach users.
Consistent monitoring and proper attribution tracking are the best defenses against this type of fraud.
Click redirection is when a user is automatically redirected to an ad or app store page without choosing to click it. The purpose is to fake ad engagement and steal credit for app installs.
It violates advertising network policies and can be considered fraudulent, but its legal status varies depending on the region. It is always unethical and harmful to advertisers.
By watching for spikes in clicks, long click-to-install times, and very low engagement or retention rates among new users.
While less common, even legitimate sites can be compromised by malicious ad scripts that trigger redirects.
Use verified ad networks, track campaign performance carefully, and rely on advanced anti-fraud tools that analyze behavior patterns and traffic quality.