Episode 10

Connected Television (CTV) Device-Spoofing

with Lindsay Kaye and Will Herbig of HUMAN Security

Show Notes

On July 7, 2026, HUMAN’s Satori team exposed NewsJunkie, a massive, coordinated connected television (CTV) device-spoofing operation that generated up to two billion invalid bid requests per day, per seller.

In this episode of Won’t Fix, we go inside the investigation with Lindsay Kaye (VP of Threat Intelligence) and Will Herbig (Senior Director of Media Research) from HUMAN Security to break down how this sophisticated fraud was uncovered.

We then zoom out and broaden the conversation to talk about the connected TV ecosystem in general and how AI and automation are changing the security threat landscape.

Chapter Timestamps

  • 00:00Introduction
  • 01:13Team Backgrounds and Roles at Human Security
  • 03:31Understanding the News Junkie Operation Structure
  • 05:27Key Anomalies That Exposed the Fraud
  • 08:32Scale and Impact of Invalid Traffic
  • 10:14Evolution and Persistence of the Operation
  • 14:15Residential Proxies and Infrastructure Connections
  • 20:24AI-Generated Fake Business Identities
  • 23:44Disruption Strategies and Industry Response
  • 26:48Systemic Gaps and Supply Chain Compliance Issues
  • 31:48Device Attestation and Technical Solutions
  • 34:41AI's Impact on the Security Landscape
  • 41:33Investigation Methodology and Future Outlook

Transcript

There may be transcription errors: we apologize for those in advance.

Rob: Hi, welcome to Won't Fix. On July 7th, 2026, HUMAN's Satori team exposed NewsJunkie, a massive coordinated connected television (CTV) device-spoofing operation that generated up to 2 billion invalid bid requests per day, per seller. In this episode, we'll go inside the investigation with Lindsay Kaye, VP of Threat Intelligence, and Will Herbig, Senior Director of Media Research, from HUMAN Security to break down how the sophisticated fraud was uncovered.

The scammers took advantage of a massive blind spot. Unlike computers or phones, smart TVs don't run the standard security code that tracking tools use to spot fraud. To pull it off, the attackers used two main tricks. First, they hijacked the background systems that networks use to insert commercials. Second, they routed their fake traffic through everyday household internet connections, essentially making their digital footprints look like real families watching TV in their living rooms rather than a server farm. The fraud unraveled through end-to-end supply chain analysis, which flagged massive anomalies. We'll get into it in this discussion. And I really look forward to hearing your feedback, as always. Thanks so much.

Rob: Hi, Lindsay. Will, it's good to be talking to you. How are you all doing today?

Guest: Doing quite well. Excited to speak with you as well.

Rob: Yeah, yeah, awesome. So maybe just to kick off, if you can just tell us a little bit about what you each do at HUMAN and how you got there — maybe start with you, Will, and then we'll talk a whole bunch about the report and what you all found.

Will: Sounds great. Thanks, Rob. My name is Will Herbig. I'm the Senior Director of Media Research at HUMAN Security, so I lead the research and development for our MediaGuard product. What it does — and I'll be talking a bunch about it throughout this podcast — is it aims in real time to give demand-side platforms, supply-side platforms, advertisers, and publishers visibility at time of bid request into what's likely to be invalid traffic. So we always say it's looking 10 milliseconds into the future.

My background is in financial crime, so I've been chasing fraudsters for pretty much my whole career. I spent most of it working in management consulting, helping banks find fraud, money laundering, anti-corruption, all those kinds of different things. So being at the intersection of data and fraud is where I thrive. And as a team, we always joke we like to ruin a fraudster's day. And that's what we did in NewsJunkie, so looking forward.

Rob: We love ruining a fraudster's day for sure. So Lindsay, tell us more about your background.

Lindsay: Thanks. So I'm Vice President of Threat Intelligence here at HUMAN Security. What my team does is work very closely with Will's team on a couple of different things. Anytime there's an OSINT investigation, any sort of reverse engineering — while they have really great visibility into the IVT data, if you ever need investigation into exactly how an app is operating, what the different fraud schemes are, maybe it's part of a larger cybercriminal campaign — we come in and work very closely with them. And ultimately, a lot of the research we do, while we don't publish every single thing, everything we do publish we work to make sure we're adding these detections to our products to make them better. So really complementary functions here.

Rob: That's awesome. So I saw the NewsJunkie report and it was super interesting — the scale just seems immense. So just help me get the basic picture here. As someone who's not as deep in the CTV side of things as perhaps other stuff, the way I understood it is that someone's essentially forging, making up fake televisions and households at massive scale, and then making advertisers pay for ads that nobody ever saw. Is that the right mental model, or am I missing something? Maybe you can unpack it a little bit more for everyone.

Lindsay: Sure. Yeah, that's definitely the right mental model. And I can give you a high-level description of what the campaign involved, and then Will can talk a little bit more about the intricacies of CTV and some of the additional technical details, if that works for you.

Rob: That's great.

Lindsay: Great. So you were pretty much exactly right on the idea that these are not, in fact, real CTVs. Basically, there was a set of apps — a lot of local news apps and premium CTV apps. That's actually part of how we named this operation: NewsJunkie comes from the fact that there were so many of these local news apps. And I'll talk a little bit about why that was so interesting.

We saw clustered, related sellers transacting high-volume, high-IVT inventory, pretending to be premium content — like those news apps and premium CTV apps. And it was largely exploiting the fact that there are limited measurement signals in the CTV ad ecosystem, which I'm sure you're very familiar with. So the supply chain, like you said, was being flooded with all these synthetic bid requests that looked like real household viewers but were not. These are not people that actually saw these ads. They were not real.

At peak, we saw hundreds of millions to nearly 2 billion invalid CTV bid requests per day, per seller. Over a two-month period, for one of the apps, we saw 42.2 billion bid requests, which is a huge amount.

Part of how we were able to figure this out was through a couple of different anomalies. A lot of the ways we start to find cybercriminal campaigns like this, especially with IVT, is by looking for anomalies and picking them out. At a super high level, one of the things we saw was a mismatch. A lot of these local news apps — you have some idea of how many people you'd expect to download the app. One of the ways we can tell is by looking at the number of reviews for a particular app. This one had 185 reviews for a local news app, and it really mismatched with the number of bids we were seeing — those 42.2 billion requests over two months, which suggested a lot more viewership, a lot more people looking at this app, than the number of reviews would imply, because that's something you'd expect in proportion.

An additional anomaly: because this was a Jacksonville local news app, you'd expect most of the people looking at it to actually be in Jacksonville. But when we started to look, it was much more diverse than that. Jacksonville actually ranked 21st in the list of where people were located.

Then, definitely, the latency of the traffic. You'd expect the latency of traffic going to this app to largely match the rest of the latency of traffic — the background apps. But this took a lot longer, which was suggestive of the use of residential proxies, which are generally used by cybercriminals to obscure where their traffic is coming from. Because the traffic was coming through residential proxies, again, it suggested something untoward was going on.

And then finally, the representation of the network origin, which simply means you'd expect the reported IP at the time of the bid request to match the one in HUMAN's IP data — but this was not, in fact, the case. So, if you want to dive into any of those particular details, Will, I'm sure you have something to add as well.

Will: Yeah, there were so many really interesting anomalies in this traffic — there's really not one single thing that pointed us to invalid traffic here. By the way, we'll be using the term "invalid traffic" quite a lot. In the advertising world, we don't necessarily use the word "ad fraud" all the time, because there are often sets of traffic that are violations of agreed-upon industry standards but not necessarily fraudulent. For example, if you have an ad that is 51% off the page, that's an invalid ad that doesn't meet certain requirements, but that's not necessarily ad fraud — it's not malicious. So we use a blanket term, "invalid traffic," that encompasses everything, both fraud-related and not. We also can usually infer intent. So invalid traffic is a much broader term.

I just want to pause for a minute on the scale of this, because when we talk about bid requests, there's this question of what that even means. MediaGuard is designed — to use a metaphor — to stop the bank robbery before it happens. We try to let people know where we think IVT is going to happen in the future and where it's likely to occur. We can't give you a monetary loss figure because, well, if we let the loss happen, then we didn't do our job. But to give some comparison numbers: 2 billion requests a day — that's the total amount of ads viewed by a small city. Think of a city like Hartford, Connecticut. Not a huge city — we're not talking about New York City — but that's a city of people. The total cumulative ads transacted across this operation is of the magnitude of a small city. So when we think about the scale of this misrepresentation, it's pretty staggering. And I'm sure these folks were making quite a lot of money.

Rob: Yeah, that was one of my questions — putting this in the context of the overall CTV space. The other thing you brought up: I always wonder about fraudsters when they just go for a large amount because they think no one's watching, versus even if people were watching, they could probably get away with small amounts for a very long time. So I'm curious how you think about those dynamics in terms of how this compares to the larger market. You've kind of answered that with the "size of a city" point. But how does this compare with the scale of other things you see, and over what time periods do they play out? This seems pretty compressed — is that typical, or are there other patterns you see in these kinds of investigations?

Will: Yeah. It's very possible we'll write a follow-up piece on this, because what we described is one set of invalid traffic associated with this operation. What we didn't describe is all the things that happened afterward. When we started investigating this, it was focused on these specific news channels. This operation still exists today. It's still attempting to gain money from advertisers on traffic that we believe to be not real impressions.

First of all, they have pivoted to every single operating system in CTV. There isn't a single OS they haven't tried to impersonate traffic on. Maybe later we'll zoom out macroscopically into how IVT operates in CTV, but that's one of the big benefits of having fake traffic rather than device farms. Device farms are stuck with whatever device you've got. But when you're impersonating traffic, when you're fabricating traffic, you can pivot from one operating system to the next. And you can pivot from one app to the next. So what we're seeing today is an entirely different set of apps. They've pivoted now to some sports apps — maybe because of the World Cup — fabricating some of that sports traffic. We see some similarity to what we described in this report, but also some very different nuances in how they're trying to emulate this traffic. And that's not uncommon whatsoever — you see different actors in this space trying to pivot from one thing to the next.

And Rob, to your point: what some actors will do is try to impersonate 1,000 apps, hoping that if they can do a small amount of traffic on a thousand apps, they can just go under the radar. But where that really falls apart is that in programmatic advertising — for better or for worse — you have to monetize through something. There should be some amount of traceability. And I'm sure later we'll talk about difficulties in the supply chain, truncated supply chains, and so on. But there is some ability to follow the money. So even if you have a thousand app IDs, you need to monetize those through some kind of supply path. That allows us, in conjunction with Lindsay's team, to more deliberately pinpoint where the money is coming from.

Lindsay: I think one of the particularly interesting things we've seen over the past couple of years is that it's not just ad fraud campaigns that exist on their own to make the threat actors a lot of money. For example, with both of the BADBOX campaigns, we saw the ad fraud portion as part of the larger cybercriminal ecosystem campaign they were running. With the first BADBOX, it was PEACHPIT. I don't remember exactly how many bid requests per day we saw at peak, but it was a pretty substantial portion. And with BADBOX 2.0, again, they were back with the ad fraud. While we don't necessarily know for sure, you could certainly imagine how this could have been part of what they were using to fund the other parts of the operation — putting malware on these devices to set up part of the residential proxy portion and all those other modules.

So if you look at it at the higher level, it's not just about the ad fraud and making money there — it's maybe what are they using it for? Is this part of a larger operation? That's where the teams really work very well together, to say: okay, it's not just about the data here. What else could they be funding? What else could be part of this operation that we need to understand and ultimately try to disrupt?

Rob: I think that's also a good segue into the residential IP part of this, which I think is very interesting. Obviously there are a bunch of quote-unquote legitimate use cases for companies using residential IPs — we could talk more about that in the larger context. But talk a little bit about how residential proxies and residential IPs are being used in this campaign. It doesn't sound like it's the whole thing here, but it also intersects in interesting ways with some of the BADBOX research I know you folks have done. So I'm curious how that part was used here, and then maybe the larger picture of residential proxies.

Will: Yeah, absolutely. Residential proxies are a through line — to Lindsay's earlier point, there are a lot of relationships between different threat actors that we observe. Although it was not the case, to my knowledge, that the residential proxies we identified in this operation are related to BADBOX, the use of residential proxies is a pretty common way for actors to try to add legitimacy to their traffic.

Just to explain the rationale: if you have traffic from a data center — and by the way, there are legitimate reasons why traffic comes from a data center in CTV, around SSAI, which is server-side ad insertion — but generally speaking, it's less reputable, or more questionable, if data comes from a data center. So you could impersonate a residential IP address in programmatic bid traffic. You declare whatever elements you want, but then in post-bid, someone is going to say, "Why don't these IPs match?" And it's fairly obvious. So what you can do is route traffic through a residential proxy. There's going to be a device that either someone knowingly or unknowingly is being used as a residential proxy exit node, and you're quite literally going to route traffic through that. So this gives you higher bits of legitimacy.

Now, the residential proxy traffic is super interesting, because there are sets of threat actors who generate residential proxies — this was one of the items in BADBOX — and then you have folks who consume residential proxies. In NewsJunkie, we did not observe BADBOX residential IPs. But last year, we published Apollo, a very large audio impersonation scheme, which at its peak was about 10% of all audio ads. That one was routed through BADBOX devices. So what we observed is the residential IP addresses from infected BADBOX devices being used as exit nodes for an audio scheme. So absolutely, there's a connection here. And to Lindsay's point, it's a connected web of how folks are generating infrastructure and then using that. We certainly see that this is a persistent problem — it has been for several years. It's not something we can expect to go away.

Lindsay: So folks like Google and law enforcement — I'm sure you saw the recent disruption of the NetNut residential proxy service. That's a fantastic step forward. But the one thing Will was talking about is that this is very commonly used by threat actors to obscure and obfuscate where their traffic is coming from and add that air of legitimacy, because ultimately it makes it harder for us as defenders to disrupt them. So while there is demand from threat actors for these services, people aren't going to stop finding ways to generate them.

A couple of years ago, we worked on an operation called PROXYLIB, which was a whole set of free VPN apps that added your device as a node in the residential proxy network. So there are so many different ways they're building up the — for lack of a better word — inventory, the different IPs for these things. This is something we expect to see more of, potentially with connections to BADBOX or other residential proxy services we've seen, like Apollo. So this will be a persistent issue, at least for the foreseeable future.

Rob: Yeah, I'm sure there are the botnet residential proxies, and then there's the quote-unquote "ethically sourced," which I have lots of questions about in many cases. They all claim to be ethically sourced, but at the end of the day, I don't think we have a lot of insight into what exactly that means, or where the inventory is coming from. So — do with that as you wish.

Will: Well, and Rob, this is a hotly debated topic in adtech: should residential proxy traffic — irrespective of whether it's ethically sourced or not — be flagged as invalid traffic? Right now the answer is generally no, because real people can use it. But what's going on in NewsJunkie is we see high rates of residential proxy traffic, and there's no good explanation for why. And this isn't just limited to NewsJunkie: if a domain has a high rate of residential proxy traffic — maybe you have a security news site where people are especially privacy-conscious, you could make up some hypothetical — but generally speaking, when you see high concentrations of residential proxies, that's not a good sign. It's a pretty good indicator that something else is going on behind the scenes.

Rob: Yeah, I think the whole IP space is very interesting. I recently was using a commercial VPN to access something, and the thing was also auto-detecting where it thought I was coming from. So my supposedly Dallas, Texas IP was detected as coming from China. So I'm assuming that particular commercial provider is being used a lot by folks over there — it's unclear in some cases.

So the other thing I found super interesting that you all talked about in the report was AI-generated employee profiles for the sellers. I'd love you to talk more about that, because the whole theme of spoofing identities, spoofing companies, having enough details so people don't ask too many questions, is obviously a real theme for fraudsters. So I'd love to hear more about that part.

Will: Yeah, absolutely. A very interesting aspect of this operation is the global supply chain, which we can come back to later — because what we observe here is what's called ephemeral sellers. This operation, it appears, made sellers specifically to elongate the supply chain and obfuscate where the traffic is coming from. When you make a new seller, an intermediary in the supply chain, you need a company for it. And that company needs a LinkedIn profile. And in those LinkedIn profiles, there needs to be some connection to some people in adtech, a profile picture, and all these kinds of things.

So what we observed — and I don't remember how much of this is in the report — is both AI-generated profile pictures, where there's this very classic weird-neck look in AI-generated content. We observed that in multiple profiles of employees at these companies, where the proportions of the body just don't look like they should. We also observed images where, when we reverse-image-searched them, we found new LinkedIn profiles of people in completely different countries who seem to have legitimate jobs with full job histories. Maybe those are also fake profiles, but they don't look like it — they look like just random people whose images were stolen. So there's all this circumstantial evidence suggesting these companies were very quickly made, and they were trying to have enough of a paper trail that if someone doesn't look too hard, it's okay. Not having a LinkedIn page is very strange, but having one with a couple of employees on it and some LinkedIn profiles is kind of enough to pass the sniff test.

Lindsay: One of the super crazy parts of it is that if you look at some of these images, you see, "Okay, this is very obviously AI." A couple of years ago, you'd be able to look at a lot of profile pictures — the hands would be funny, things like that. A lot of those indicators would be like, "Oh yes, this is obviously AI." But now these models are getting so much better and more effective that I have to look very closely. So like Will said, it seems like threat actors just have just enough of an air of legitimacy — a little presence on the website. Sometimes you'll see the company's board of directors, and it'll just have first names and then somebody's like "finance" and "CEO," and that's all the employees. So it's pretty low effort, but it's just enough. So we can start to pick those things out as, "Maybe this is not legitimate." But you can certainly see a future where, now that the technology is better at generating these images, and as threat actors catch on to the things we flag as fake, these will start to get better and it might be a little harder for us to pick out, "Okay, is this a real company or not?"

Rob: Yeah. I now look at some of these "This Person Does Not Exist" profile pics — the GAN, generative adversarial network, ones — and those are so easy to pick out now versus the current ones people are using.

You said this operation is still ongoing, though it's been disrupted, as you said in the report. What does a win look like here? Disrupting it and bringing attention to it is good, but what does the next level of disruption look like for this type of operation?

Will: From my point of view, disruption has maybe three different levels. The first is the most baseline: we need to protect our customers. That's my job — to make sure, as much as possible, our customers are not exposed to the risk of this inventory. Our customers control their bidding decisions; they decide what to do with information that we think is probabilistically invalid. But we try to communicate that and, as much as possible, mitigate the risks. So layer one is in our predictive engine in MediaGuard — we try to expose these to customers.

The second layer is education and intelligence exchanges with folks in the industry. At HUMAN, we have what's called the HUMAN Collective, a group of customers and non-customers who are interested in removing as much ad fraud and invalid traffic at its source as we can. We'll send a more detailed advisory than what we published, listing a lot of information on supply paths and how they can identify this traffic in their supply chains. We're trying to go to the root of this. If we only did layer one — only protected via our product — then only customers who work with us, only people who have MediaGuard, would get mitigation. We don't want to punt the problem to people who don't work with us, or concentrate the risk of loss on those folks, because then the bad actors are still making money and there's still an incentive to do this type of ad fraud. So we go to the education level and say: here are sellers with this type of risk, here are indicators of compromise (IOCs) for how you can identify this, and here's what you can do with that information.

The third layer — which we didn't pursue here, but have pursued in things like BADBOX and elsewhere — is trying to disrupt the infrastructure itself. Maybe Lindsay can talk about this in the context of BADBOX, where we try to quite literally get the actors removed from some of their infrastructure components, get their servers taken down, things like that. And there's actually maybe a fourth layer here, which is working with law enforcement, which we did in the case of Methbot, where we ultimately helped the FBI get a conviction. But those are all much harder and much more complex to do.

Rob: Let's zoom out a little. A lot of this exploits the fact that connected TV, or CTV, doesn't have the detection signals or firm identity that other platforms have. So who should be closing that gap? Is it your television maker, your ISP? Who's essentially the group leaving the door open for this kind of stuff? Where are the systemic or systematic gaps in the ecosystem or supply chain?

Will: I think the responsibility is borne at every step of this — from the SSPs to the DSPs to the device manufacturers to the app developers. Everyone can be doing better here.

Let me first start by talking about the least sexy thing that's ever come up on your podcast: ads.txt compliance and sellers.json compliance. What's called supply chain compliance is a very important part of the ecosystem. For those who aren't familiar, this is the general idea that if I own a sports app, I'm going to list on my website who I'm selling to; and if I'm an intermediary supplier, I'm going to list where I'm getting my supply from. That way we have both-sides verification of where ad dollars are flowing, or where they should be flowing.

That's the idea in principle. In practice, you have ads.txt files that aren't updated. You have sellers.json files that aren't updated. You have folks transacting traffic they forgot to add. You have data quality issues that make something look non-compliant when it isn't. And you have folks truncating the supply chain. Truncating the supply chain is when the path goes from the app to seller A to seller B to seller C, and then ultimately to a DSP (demand-side platform), and then the advertiser — and someone along the way, not even maliciously, can truncate the supply path. They can just say, "Anything that happened before me in the supply chain, I'm going to delete out and move forward." This happens more frequently than we'd like, and it's not necessarily something that's invalid.

The reason I bring all this up: in the report, we talk a bit about ephemeral sellers. These are sellers that existed for, say, less than three months — very new sellers that appeared to only transact with some of these culminating sellers before reaching some of our customers. When we look at supply chain compliance, the hop right before it comes to one of our customers is almost always valid — meaning our customer and that seller say they work together. But before that, first of all, the supply chain might be truncated, and beyond that, it's a big question mark. Somewhere along the line, there's some bit of non-compliance. Ultimately, if you go all the way to the beginning, either the apps themselves don't declare that they work with the first seller we see, or the supply chain is truncated and there was some other seller that was ads.txt-verified that we didn't see.

So why does this matter? If these things were held to a higher standard and enforced, this type of traffic would be a lot harder to do. This operation could have been entirely avoided without HUMAN if people were just strictly following supply chain compliance standards — verifying every single hop, every single node in the supply chain. If it had proper compliance checks, this type of operation wouldn't have been possible. And that's also the case in Apollo — we wrote about the same thing nine months ago in the Apollo audio fraud operation, where again, these types of things could have been circumvented.

Now, why don't they do it? Because people will lose money. If you remove anyone who's not on that text file, both the publisher and probably the SSPs, and maybe even some of the DSPs, would lose money. It's hard to keep all these things aligned, but I think it's worthwhile to raise the standard of what's acceptable as an industry and have better enforcement of that. So that's one big thing we can be doing across the entire adtech ecosystem that would help dramatically reduce these types of IVT operations.

Rob: Yeah. I think misaligned incentives is one of the things we talk about on this podcast. I've worked on e-privacy and cookie-notice compliance for Google, so you can't bore me — there's no level of compliance boredom that I will suffer. But that's a great point about the incentives for SSPs and others who are transacting. And ultimately, a lot of times it's the advertiser bearing the costs. The problem of measuring outcomes also plays into this: when it's harder to measure outcomes, you also miss a lot of what's going on in the background.

So are there any other structural fixes? Are there things the ISPs could be doing differently? If you look at the nature of connected TV, it's very difficult if you're just relying on an IP address as an identifier. What are some of the other structural things we should consider as an industry to counter this?

Will: Yeah, it would be remiss of me not to bring up device attestation. I'm using that term very broadly here to also include things like the Roku watermark — that's not technically device attestation, but it's very similar thematically. What these are: at the device level, there's an encrypted token passed to HUMAN or elsewhere, where HUMAN has a private key that we can use to decrypt it and verify that there's an actual device behind whatever traffic we're seeing.

One of the challenges here is server-side ad insertion. For those not familiar, there are a variety of ways CTV traffic can load ads. One is calling an ad server and loading an ad, but you can also, at the content-player level, stitch in the ad through the originating content provider. When that happens, a lot of the information we're getting is through a server — it's not through the endpoint device. And in those cases, device attestation, at least as it's designed today, won't work.

I want to be super clear: device attestation is excellent. I strongly encourage every device manufacturer to pursue this type of work. I think it'll go a long way to mitigating this. But it's not a silver bullet — it's not something that's going to single-handedly stop CTV invalid traffic, though it will make it much harder. And if it causes IVT to concentrate on SSAI servers, that's almost a good thing, because now we can start working with SSAI servers. Maybe there's a world where we have device attestation via SSAI servers — I don't believe there's even a standard hosted for that yet — but that would go a long way toward mitigating this.

Rob: So if you think about which player, industry component, or company could move the needle most in that direction — who do you think that is, or what area might it be?

Will: I would say it's the device manufacturers. And I think they largely are. I don't have the numbers in front of me, but maybe four of the top 10 OSes in CTV have or are building device attestation. So that's a good chunk of traffic that has this. And there's at least some discussion of people toying with it outside of those worlds. So there is movement here. These things are slow — there are a lot of different parties that need to interact to make device attestation or a watermark successful — so it takes time, but it is moving forward.

Rob: That's really helpful. So if we zoom out even further — one of the things I like to ask people about is how they see AI affecting the trust and security landscape. So this is a question for Lindsay: when I see stuff like this, and then I think about AI not only helping create more plausible fake stuff, like a fake employee profile, but also automating more actions — should we be hopeful or terrified about what AI is doing to the security landscape? How do you think about where we're at in this evolution right now?

Lindsay: Sure. Largely, when we look at how AI is used in cyberattacks and cyberthreats — and even in the IVT and media space — what we see is that it's not a new threat landscape. It's not necessarily a new TTP that we need to be aware of. It's more used as a way of augmenting some of the existing threats we see.

On the enterprise side, one of the things HUMAN looks at a lot is things like carding, scalping, scraping, and so on. Where we see AI used there is as another way to use, let's say, agentic AI and AI browsers to conduct carding attacks, to conduct inventory attacks — basically making it more scalable, more efficient. People can more easily get in on doing cybercrime. So it's democratizing cybercriminal threats. Whereas it used to be that people would have to find a tool, maybe an all-in-one toolkit, they can instead now trick and subvert some of these browsers to conduct that kind of attack.

On the media side, to your point, it's again augmenting the number of things like apps and content. With SlopAds, we saw that a lot of the apps had that veneer of AI generation. Some of the campaigns we disrupted in the past couple of years, you'd see 20, 30, 40 apps — a significant number, but not the numbers we're seeing today. I believe it was over 200 for SlopAds, and several hundred for some of the other ones. It's just so much easier for threat actors to generate these apps and get them in the app store to do IVT. And if an app gets taken down, they can just generate another one, keeping these operations going and up to scale. With Pushpaganda, which focused on AI-generated lures that tricked people into downloading additional malware, we saw them using AI to generate these lures — it wasn't necessarily a person behind all of that.

So when we see what threat actors are doing, it's largely to augment the existing threats we know at this point. You asked whether we should be scared or hopeful — I'd say, at this point, cautiously hopeful, that right now the state of things is that it's mostly threats we know and understand, just conducted in a slightly different way. So as defenders, if we're looking to take down these apps, we should expect more of them, potentially with that veneer of AI-generated content. If we're looking to stop things like carding attacks, yes, they're still using the same techniques we know, just conducted slightly differently. So while we as defenders need some element of upskilling to understand that new way they're using these tools, it's not something where we're completely unprepared — if that makes sense.

Rob: Yeah, that makes sense. So it's like these tools are lowering the skill floor, but not necessarily changing the tactics entirely — it's building on top of things we've seen already.

The other thing I'm really interested in your view on — I've seen this myself — is that using off-the-shelf models, there are a lot of refusals for defenders, where they're like, "Oh, it looks like this thing you're trying to do might be related to something bad, and you're trying to tell me it's good," and no, actually, I'm trying to do something good. I also saw recently that malware writers are putting nuclear-related terms into their malware to try to get scanning tools to ignore it. It's kind of spy versus spy. So do you folks run into that kind of issue yourselves in the work you do — seeing defenders get blocked by stuff that's aimed at attackers?

Lindsay: So I know that a lot of the models that attackers are using do have those safeguards. One of the interesting things is that sometimes you'll see them find different ways of subverting it. I think there was some research where they tried to get a model to conduct a little cyberattack on their behalf, just to see, and they said, "Okay, no, no, no, this is just for security purposes, we're just testing." So it's one of those things where AI has those safeguards — and they are putting them in, which is fantastic news for us as defenders — but it's also about understanding how, and whether, it can be tricked. Hopefully it'll continue to get better. But then there are also the jailbroken models out there.

So, really looking at how people are abusing these different things: as soon as you put some block or prevention in the way of threat actors trying to make money through advertising fraud or other cybercriminal fraud, they're going to try to find a way around it. From the defensive side, we see that substantially less, in that most of our focus on AI is not on trying to trick or subvert it — it's mostly on understanding how threat actors are tricking and subverting it, and the different ways they can do so to conduct attacks, at least from the visibility my team and I have. A lot of it is just trying to prevent the different types of attacks that we all know and love, but now some of them are conducted with AI. Maybe threat actors are subverting these models, or maybe they're just using them in a way they were intended to be used, but in a way that's potentially malicious.

Rob: Yeah. So a question for each of you. I'm not going to ask you necessarily how you found this exploit — but feel free to tell me if you want. How do you get inspired and find bad stuff happening, in general terms? What's your process, or how do you think about going and looking for things? I'm curious, to the extent you can share, about things that might be coming up next. It sounds like you have a lot of irons in the fire. But what are the ways you find bad stuff out there? A lot of security investigators are just innately curious, but tell us more about how you think about that.

Will: Yeah, I'll go first. I have a background in fraud, so I take a follow-the-money approach — not always, but often — where we look at supply paths, sellers, people who ultimately make money from it, and ask, "What's weird about this?" In the case of NewsJunkie, there were a few dozen things that were weird. It's not always that clear-cut. But are there instances where we see uncommon traffic patterns? Are there weird JavaScript signals we're collecting, or network telemetry on a seller? Generally speaking, we expect sellers to be insulated from a lot of anomalies — me transacting on a certain website should be completely irrelevant to the amount of Chrome or Firefox or whatever visiting the site. So we can do all these anomaly-detection investigations on a seller and ask, "What's weird about this seller?" And then we just start pulling the string. From there, we might loop in Lindsay's team — "Hey, go see if you can find something about this website or this company." And we'll keep pulling on the string, and then we'll find things like NewsJunkie.

Lindsay: From the other side of the perspective: we've been following the operation BADBOX, for example, since — I believe it was early 2022. The threat actors rebrand, they get new tools, like pretty much any cybercriminal group. But being able to continue to follow that — what are the new residential proxy services, are there new ways they're doing ad fraud — being able to follow those pieces and parts. And sometimes you're able to link particular TTPs to another group that's also related, so then you dig on that if it's of interest. So being able to continue to follow a lot of these operations — and sometimes we uncover new threats doing so — is something that matters, because when we disrupt, say, the ad fraud portion or the residential proxy portion of an operation, that doesn't mean it's over. Being able to continue to follow these as they change and evolve, discover new groups' ties to other groups — like the overlap between Apollo and the BADBOX residential proxy network — it seems like a lot of these things are intertwined in various ways that lead us from threat to threat to threat. And it keeps us very busy — I'm sure Will can attest to that.

Will: Well, and building on that, Lindsay — one of the things we talk about at HUMAN all the time is collective protection. If we go and disrupt the residential proxy IPs of BADBOX, then we get an ancillary benefit: it makes Apollo harder. And when we disrupt Apollo, we're stopping people from purchasing the infected IPs of BADBOX. So all these things are related. Whenever you can make the days more difficult for the fraudsters of one of these rings, undoubtedly there's a cascading effect for all these related parties, where they have to do something different. We're always talking about disrupting the economics of cybercrime — we want to make it harder and harder, make you jump through more hoops, increase the cost per unit that you, as the fraudster, have to go through. And these are a lot of the ways we're trying to do that.

Rob: Love that. One final thing, Lindsay — I believe you've written a book. Is that right? Can you tell us a little bit more about that?

Lindsay: I have, sure. The book is called *Dissecting the Dark Web: Reverse Engineering Tools in the Underground Economy*. It's published by No Starch Press. The basic structure is that we look at a variety of dark web tools — stealers, cryptors, initial access, how vulnerabilities and things are bought and sold. And then, after we discuss how they're sold, why they're sold, and why they're marketed in certain ways, I walk you through the reverse engineering of one of them, so you can see how a lot of the context behind it contributes to how the tool works. Then I turn it over to you as the reader to actually do it on your own. So for people interested in understanding how the cybercriminal ecosystem works, how the dark web works — while also starting to learn a little about reverse engineering and malware analysis — I think it's a great opportunity. You get a little of the context and a little of the technical stuff. We go from initial access all the way through the dropping of ransomware, simply because that's something most people conceptually understand. But I think it's a fun read, personally.

Rob: Yeah, it sounds great. I'm going to get a copy of that. Let me know how you like it.

Lindsay: Yeah, I will — I absolutely will. And maybe we'll have a follow-up at some point and talk more about these kinds of tools.

Rob: Any final thoughts, Will? And then Lindsay — in terms of this investigation, and maybe some of the unexpected things you learned from it, if at all?

Will: Yeah, for me, my closing thought is that IVT on CTV — invalid traffic on CTV — is not a solved problem. It's still there. People are still making wild amounts of money. And although we as an industry have made it harder and have reduced the prevalence of it, it's still there, and it's still something we need to be vigilant about. It's still something we as an industry need to be working on — closing all these different gaps, whether it's supply chain, device attestation, or data quality in CTV. It's not something any one individual can solve; it's something we as an industry need to work on. So I look forward to partnering with all your listeners on improving all those things.

Lindsay: I think that's such a great point, Will — the idea of upping the cost and making it more painful for threat actors to make money off of different types of fraud. That's what companies like HUMAN and other people who work in the defensive landscape are ultimately trying to do. Every disruption is fantastic. None of these are solved problems — residential proxies and ad fraud are never going to go away. But the more expensive and more painful we can make it for threat actors, the closer we get to a safer internet for everybody.

← All Won't Fix episodes