USENIX Security2016Top-tier venue
Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software
Kurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod, Cait Phillips, Marc-André Decoste, Chris Sharp, Fabio Tirelo, Ali Tofigh, Marc-Antoine Courteau, Lucas Ballard, Robert Shield
Abstract
In this work, we explore the ecosystem of commercial pay-per-install (PPI) and the role it plays in the proliferation of unwanted software. Commercial PPI enables companies to bundle their applications with more popular software in return for a fee, effectively commoditizing access to user devices. We develop an analysis pipeline to track the business relationships underpinning four of the largest commercial PPI networks and classify the software families bundled. In turn, we measure their impact on end users and enumerate the distribution techniques involved. We find that unwanted ad injectors, browser settings hijackers, and "cleanup" utilities dominate the software families buying installs. Developers of these families pay 1.50 per install-upfront costs that they recuperate by monetizing users without their consent or by charging exorbitant subscription fees. Based on Google Safe Browsing telemetry, we estimate that PPI networks drive over 60 million download attempts every week-nearly three times that of malware. While anti-virus and browsers have rolled out defenses to protect users from unwanted software, we find evidence that PPI networks actively interfere with or evade detection. Our results illustrate the deceptive practices of some commercial PPI operators that persist today.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 72f9b3ac-84e9-42a9-8e13-df5a8d6a1291Cited by top-tier papers20
- The Spyware Used in Intimate Partner ViolenceRahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron et al.S&P 2018 · 167 citations
- A Lustrum of Malware Network Communication: Evolution and InsightsChaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero et al.S&P 2017 · 86 citations
- Measuring PUP Prevalence and PUP Distribution through Pay-Per-Install ServicesPlaton Kotzias, Leyla Bilge, Juan CaballeroUSENIX Security 2016 · 74 citations
- Surveylance: Automatically Detecting Online Survey ScamsAmin Kharraz, William K. Robertson, Engin KirdaS&P 2018 · 73 citations
- Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Tudor DumitrasCCS 2017 · 64 citations
Builds on1
Related papers
- How Did That Get In My Phone? Unwanted App Distribution on Android DevicesPlaton Kotzias, Juan Caballero, Leyla BilgeS&P 2021 · 37 citations
- AdLens: Efficient Detection of Deceptive Software AdsRitik Roongta, Marwan Adnan Darwish, Masoud Poorghaffar Aghdam, Rachel Greenstadt et al.CCS 2026
- A Large-scale Temporal Measurement of Android Malicious Apps: Persistence, Migration, and Lessons LearnedYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniUSENIX Security 2022
- A Needle is an Outlier in a Haystack: Hunting Malicious PyPI Packages with Code ClusteringWentao Liang, Xiang Ling, Jingzheng Wu, Tianyue Luo et al.ASE 2023 · 15 citations
- You've Changed: Detecting Malicious Browser Extensions through their Update DeltasNikolaos Pantelaios, Nick Nikiforakis, Alexandros KapravelosCCS 2020 · 34 citations
