Home Mobile Oracle Data Cloud Companies Expose ‘DrainerBot’ App Fraud Scheme

Oracle Data Cloud Companies Expose ‘DrainerBot’ App Fraud Scheme

SHARE:

Oracle has uncovered an ad fraud operation it calls “DrainerBot,” which siphoned off ad dollars and monthly data packages.

Oracle’s internet infrastructure business Dyn originally discovered the operation after it picked up suspicious activity among some mobile apps using an SDK from Tapcore, a Dutch mobile monetization company. The apps obscured web data with proxy servers and loaded suspicious ads.

AdExchanger reached out to Tapcore via its website, but hasn’t received a response.

Tapcore’s SDK is supposed to run in the background of an app and only activate if the user downloads a pirated version of the original app. It would allow the original developer to serve ads into the pirated app if the user downloaded a ripped-off, ad-free version of a mobile game, for example.

But Tapcore was also using its SDK to generate fake ad impressions, using a bogus browser it side-loaded into the app that wasn’t visible to the user.

“The side-loading phenomenon is something we have to keep an eye on,” said Dan Fichter, the data cloud’s VP of software engineering and former CTO of Moat, another Oracle business that was enlisted by Dyn to understand the dubious server activity. “As a general pattern it’s a way in which fraudsters can get well-intentioned developers to work on their behalf.”

The DrainerBot ads may have been hard to identify as illegitimate, but the software directly affected people’s phones and monthly data rates. With the fake browser running in the background, phones with the Tapcore SDK drained battery and data, Fichter said.

Oracle worked with the Trustworthy Accountability Group (TAG) and Google, which housed some of the affected apps on its Android operating system and Play Store, to mitigate ad spend on Tapcore apps while it scrutinized the operation.

“This is becoming a nice trend where some of these more sophisticated tech companies are now able to identify and track major botnets,” said Mike Zaneis, TAG president and CEO. “It takes time though, and we’re developing this ability to make our members aware of the issue and protect the market while a botnet is being tracked.”

Previously, exposing ad fraud operations was like nailing smoke to a wall. But with better technology and more players in the ecosystem willing to collaborate on fraud prevention, companies like White Ops, Google and DoubleVerify – not to mention the FBI – have exposed a string of ad fraud schemes in recent months.

“People are good at tracking fraud but see different slices of the ecosystem,” Zaneis said.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Fichter said the combination of Moat and Dyn was critical for exposing the DrainerBot operation and for Oracle’s fraud prevention approach. Dyn focuses on infrastructure-level internet security threats while Moat addresses transparency and ad fraud.

“Having the threat research teams making discoveries like [DrainerBot] that use advertising is hugely useful,” he said. “And it works the other way as well. Computers and devices that are compromised and used for ad fraud could be used for something else tomorrow.”

Must Read

For Super Bowl First-Timers Manscaped And Ro, Performance Means Changing Perception

For Manscaped and Ro, the Big Game is about more than just flash and exposure. It’s about shifting how audiences perceive their brands.

Alphabet Can Outgrow Everything Else, But Can It Outgrow Ads?

Describing Google’s revenue growth has become a problem, it so vastly outpaces the human capacity to understand large numbers and percentage growth rates. The company earned more than $113 billion in Q4 2025, and more than $400 billion in the past year.

BBC Studios Benchmarks Its Podcasts To See How They Really Stack Up

Triton Digital’s new tool lets publishers see how their audience size compares to other podcasts at the show and episode level.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Comic: Traffic Jam

People Inc. Says Who Needs Google?

People Inc. is offsetting a 50% decline in Google search traffic through off-platform growth and its highest digital revenue gains in five quarters.

The MRC Wants Ad Tech To Get Honest About How Auctions Really Work

The MRC’s auction transparency standards aren’t intended to force every programmatic platform to use the same auction playbook – but platforms do have to adopt some controversial OpenRTB specs to get certified.

A TV remote framed by dollar bills and loose change

Resellers Crackdowns Are A Good Thing, Right? Well, Maybe Not For Indie CTV Publishers

SSPs have mostly either applauded or downplayed the recent crackdown on CTV resellers, but smaller publishers see it as another revenue squeeze.