POST /referral/redeemBlockedPhone 31 of a 40-device cluster
- Shares exit network with 40 phones
- Same tap timing as the cluster
- Real device, fresh app install
Detection
A device farm is a rack of real smartphones, or stripped phone boards in one box, controlled by a single operator to fake app installs, engagement, signups, referrals and bonus claims. Because the hardware is genuine, emulator checks pass. Kavra links the phones through the network, behavior and operator patterns they share.
POST /referral/redeemBlockedPhone 31 of a 40-device cluster
A device farm, also called a phone farm or click farm, is a collection of physical phones that one person or crew operates as if each phone belonged to a different customer. The classic picture is a wall of shelves with dozens or hundreds of handsets on charging cables. The newer version is a farm box: a single case holding many phone mainboards without screens or batteries, wired to one power supply and one controller.
The point of a device farm is simple. Many fraud checks ask "is this a real phone?" and a farm answers yes every time. The hardware is genuine, the operating system is stock, the apps come from the official store and the device IDs are real. What is fake is the claim that each device is a separate person.
The setup is built so that one person can act like a whole crowd of new users.
The operator buys dozens of identical low-cost phones or ready-made farm boxes. Identical models make the whole rack easier to script.
Group-control software mirrors one screen to all devices, or runs scripts that tap, swipe and type on every phone in parallel.
Phones share one Wi-Fi network, a handful of SIM cards, or a pool of mobile proxies so each device appears to sit on a different carrier IP.
After a reward is claimed, the phone is wiped or its app data cleared, device identifiers are reset where possible, and it signs up again as a new user.
The farm earns from what it produces: paid installs, referral bonuses, welcome offers, followers, reviews, votes or accounts sold in bulk.
The same rack of phones can switch targets in an afternoon. What it goes after depends on where the payout is.
| Scheme | What the farm does | Who pays |
|---|---|---|
| Install and attribution fraud | Downloads and opens the app to trigger paid installs | App marketers and ad budgets |
| Bonus and promo abuse | Claims a welcome offer or free bet on every phone | iGaming, fintech, e-commerce |
| Referral abuse | Refers itself in chains to collect both sides of the reward | Apps with invite programs |
| Fake account creation | Registers accounts in bulk for resale or later use | Marketplaces, social apps, fintech |
| Fake engagement | Likes, follows, views, reviews, votes and ratings | Platforms and honest sellers |
| Ad and in-app fraud | Views and clicks ads inside apps to earn payouts | Advertisers |
Most mobile fraud controls were built to catch fake devices. Emulator detection looks for a phone that is really software on a desktop. Root and jailbreak checks look for modified systems. Device attestation asks the platform whether the app and device are genuine. A device farm passes all of them, because nothing about each phone is fake.
Per-device limits do not help either. "One bonus per device" works against a person with one phone, but a farm has a hundred devices, and resets let each one come back as new. Carrier IPs look like ordinary customers, and when farms sit behind residential and mobile proxies, their traffic spreads across many towns. The only thing a farm cannot easily hide is that one operator runs all of it.
One phone rarely looks suspicious. A group of phones acting the same way does.
Many devices leave through the same Wi-Fi, the same small set of SIMs or the same proxy provider, even when their IP addresses differ.
The same model, operating system build, language and app set appear across dozens of new accounts in a short window.
Taps, scrolls and form entries land at the same moments with the same timing, because one script or one mirrored screen drives them all.
Devices are always charging, never tilt or shift, and sit in one place around the clock, unlike a phone carried in a pocket.
The same device returns again and again as a fresh install with cleared data, often right after claiming a reward.
Activity starts and stops on a fixed schedule, runs through the night, or follows the working hours of a farm in another time zone.
Plenty of legitimate traffic shares a network or a phone model. Office Wi-Fi, university campuses and mobile carriers that put thousands of customers behind one address all look crowded. Retail stores use demo devices, and families hand down the same phone model. QA teams and app developers use real-device test labs, which are device farms by design.
Good detection treats a shared network as context, not a verdict. It looks for several links at once: the same network path and the same hardware and synchronized behavior and a reward at stake. Known test labs can be allowlisted by project, and observe-only mode shows which clusters would be flagged before anything is blocked.
The goal is to see the farm as one actor. Once you do, you can stop paying it without touching real users who happen to share a network.
How Kavra helps
Kavra analyzes 3,000+ data points on every visit from web and native apps, and groups devices that share one operator into a single cluster you can act on.
The same assessment runs inside your app, so installs, signups and reward claims are checked where farms work.
Returning devices are recognized across resets and accounts, so a phone that comes back as new keeps its history.
Kavra's own edge network sees the real connection, and its proxy intelligence maps the mobile and residential proxy pools farms route through.
Surges of new devices, shared infrastructure and velocity anomalies are grouped into one campaign instead of many small alerts.
Behavior, device and network evidence are weighed together, and models keep learning as farms change hardware and scripts.
Each assessment says what linked the device to a farm. Allow, verify or block with your rules, and allowlist your own test labs.
FAQ
Something else? Talk to our team.
Phone farms are used to make one operator look like many real users. Common uses are fake app installs for paid install campaigns, referral and welcome bonus abuse, bulk account creation, and fake engagement such as likes, follows, reviews and votes. The same hardware switches between schemes depending on which one pays best that week.
Owning many phones is legal, and real-device test labs are a normal part of app development. Using them to collect install payouts, bonuses or referral rewards under false pretenses breaks platform terms and can amount to fraud, depending on the country and the scheme. Platforms usually respond by closing accounts and withholding rewards.
No. Emulator detection looks for a phone that is really software running on a computer. A device farm uses real handsets with stock systems, so it passes that check every time. Catching a farm means linking the devices to one operator through shared network paths, synchronized behavior, identical hardware and reset patterns.
A farm box is a compact device farm: many phone mainboards without screens or batteries, packed into one case with shared power and a controller. Each board behaves as a separate real phone. Farm boxes are sold ready to run with group-control software, which makes large farms cheap, quiet and easy to host anywhere.
A botnet is made of devices infected without their owners knowing. A device farm is owned and run on purpose by one operator. Botnets tend to hide inside real households, while farms concentrate many devices in one place on shared networks, which is exactly the pattern that links them together.
It should not. Offices, campuses and carriers put many real people behind one network, so a shared address alone is only context. Kavra looks for several links at once, such as identical hardware, synchronized behavior and resets around rewards, before recommending action, and you can run in observe-only mode first.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.