Home
ClikBy

Case: how a large international brand got +30% real app installs

Case: +30% real app installs

Context: a large brand, a large budget, unclear results

A large international brand with dozens of locations nationwide was actively investing in promoting a mobile app. UA (User Acquisition) budgets ran to tens of thousands of dollars a month. Numbers in the ad cabinets looked weak, but there was no understanding of why this was happening.

When the team started looking deeper — at retention, in-app activity, real orders — the picture became even more alarming. A significant share of «installs» turned into no target action at all, and conversion from ad-to-app hops produced weak sales. Users seemed to vanish...

«We saw that the ads were set up and shown to users, thinking everything was working correctly. When we started looking into why conversion to the first order was so low, it became clear: a significant share of traffic was low-intent or not targeted at all, and our real customers almost never saw the ads».
— Product Manager of the project

Diagnosis: what exactly was happening with the traffic

Step 1. Funnel analysis by cohorts

The first step was a detailed cohort analysis by ad-traffic sources, cost, and completion of target actions. Installs from different channels were compared not by volume but by quality: Day 1, Day 7, Day 30 retention, conversion to first order, average order value, conversion to app install.

The gap was enormous. Organic users converted to a first order at about 40%. Users from some paid channels — less than 3%. That could not be explained by audience quality differences alone.

Step 2. Identifying fraud schemes

Detailed traffic analysis at the individual-visit level revealed several classic fraud schemes running at once.

  • Click Injection. Malicious apps on real users' devices tracked the moment of an organic install and, milliseconds before it completed, generated a «last click» on behalf of a paid source. The brand paid a partner network for users who had come on their own. The share of such traffic was more than 2.4%.
  • Device Farm traffic. Some installs were generated from device farms — real smartphones controlled automatically. The devices went through the whole install process, launched the app, and imitated the first actions — but went no further. The share of such traffic was more than 12%.
  • Ad click fraud (Click Fraud). Competitors and automated services systematically clicked ads, artificially exhausting the daily budget. Ads turned off in the middle of the day — exactly during peak activity of the target audience — and the budget went to empty hops without a single target action. The share of such traffic exceeded 17%.

Step 3. Estimating the scale of losses

After detailed attribution it turned out that more than a third of all paid installs were either direct fraud or zero-value users acquired via incentivized traffic disguised as organic.

Real CPI — the cost of acquiring a user who placed at least one order — was 2.3 times higher than the ad cabinets showed.

Numbers before the work started

Conversion to first order from paid channels: less than 3%

Share of fraudulent and low-quality installs: more than 30%

Real CPI vs declared: ×2,3

Day 7 retention of paid users: critically below organic

Solution: multi-level protection at every funnel stage

Level 1. Filtering before the click

At the first level, a system for analyzing traffic sources was deployed before the click is counted by the platform. Each ad hop was checked against a base of suspicious IPs, device parameters, and source behavior patterns.

Clicks from known botnets, VPN addresses without history, and devices with suspicious fingerprint parameters were cut off immediately — budget was not charged for them.

Level 2. Behavioral biometrics after install

The second level ran on the landing page users reached before installing the app. The pixel recorded visits but did not distinguish real people from bots. The system analyzed on-page behavior: scroll depth, time to click the install button, cursor-movement patterns, repeat visits from one device.

Sessions with non-human behavior were excluded from optimization audiences — platforms stopped treating them as the benchmark of a «good user».

Level 3. Audience cleanup and algorithm retraining

Fraud profiles were removed from all retargeting audiences and lookalike segments. Facebook and Google algorithms received a clean training sample — real users who actually placed orders.

This changed not only the quality of new campaigns, but also the effectiveness of already running automatic strategies: they stopped optimizing toward «ideal» bots. The cost of acquiring a real user became lower.

Level 4. Revisiting partner agreements

Based on detailed data on traffic quality from each partner, the terms of cooperation were revised. Sources with a high fraud share were turned off. Budget was redistributed toward channels that showed real conversion to orders.

Results: what changed after 60 days

Key metrics after protection was rolled out
  • +30% real installs on the same ad budget. Money that previously went to fraud started attracting live users.
  • Conversion to first order grew 4 times — from less than 3% to more than 12% on paid channels.
  • Real CPI fell 40% — by excluding fraudulent installs from the calculation and redistributing budget.
  • Day 7 retention grew 22% — platform algorithms started bringing an audience similar to real buyers, not bots.
  • Budget savings were more than 25% — funds previously paid for fraudulent traffic were redirected to working channels.

Why the result turned out this way

The key insight of this case — fraud in mobile UA inflicts double damage. The first, obvious: you pay for installs that do not exist. The second, hidden: data from fraudulent traffic poisons the algorithms that then optimize your campaigns. By removing fraud, you do not just save — you fix the compass that guides your entire ad budget.

That is why the result was disproportionately large relative to the changes: the same money, almost the same channels and the same team — but fundamentally different traffic quality and different data for training algorithms.

The case's main takeaway

«The problem was not that we spent too little on ads. The problem was that a third of the budget went to the wrong place. When we fixed that — the numbers grew on their own, without increasing investment».

Intelligent protection of your online advertising with ClikBy

We built AI Selena not just as a filter, but as a behavioral biometrics system. The platform analyzes more than 130 explicit and implicit signals (from cursor speed to network-protocol specifics) in real time.

  • Ensemble machine learning: we combine 5+ ML models to recognize synthetic identities and Device Farm traffic.
  • Zero-Trust Attribution: we verify every install, excluding Click Injection and SDK Spoofing.
  • Adaptive thresholds: the system automatically lowers filter strictness during sale periods, minimizing False Positives.

Read more about how ad-fraud protection works in our article: how antifraud works in modern advertising.


Order antifraud for ads (Yandex.Direct, Google Ads, Meta Ads, and other platforms)

Contacts

Still have questions?

Questions about ClikBy? Let's talk.

See also клика

Don’t guess who your customers are — know them. Our AI detects high-intent behavioral patterns to protect your ads and automatically scale revenue.