Detection

Device farm detection that finds one operator behind many real phones

A device farm is a rack of real smartphones, or stripped phone boards in one box, controlled by a single operator to fake app installs, engagement, signups, referrals and bonus claims. Because the hardware is genuine, emulator checks pass. Kavra links the phones through the network, behavior and operator patterns they share.

POST /referral/redeemBlocked

Phone 31 of a 40-device cluster

  • Shares exit network with 40 phones
  • Same tap timing as the cluster
  • Real device, fresh app install
Risk91
Your actionHold the referral payout
Who it hits
Mobile apps, iGaming, fintech, marketplaces, social
What it costs
Install budgets, referral payouts, fake engagement
Tools used
Phone racks, farm boxes, group-control software, mobile proxies
Where to stop it
At install, signup and before any reward

What is a device farm?

A device farm, also called a phone farm or click farm, is a collection of physical phones that one person or crew operates as if each phone belonged to a different customer. The classic picture is a wall of shelves with dozens or hundreds of handsets on charging cables. The newer version is a farm box: a single case holding many phone mainboards without screens or batteries, wired to one power supply and one controller.

The point of a device farm is simple. Many fraud checks ask "is this a real phone?" and a farm answers yes every time. The hardware is genuine, the operating system is stock, the apps come from the official store and the device IDs are real. What is fake is the claim that each device is a separate person.

  • Shelf farms: used or refurbished phones on racks, often the same cheap model bought in bulk.
  • Farm boxes: bare phone boards packed into one chassis, controlled from a PC, sold ready to run.
  • Cloud phones: real handsets hosted in a data center and rented by the hour, reached through remote control.
  • Human click farms: rows of phones with low-paid workers tapping by hand, sometimes mixed with scripts.

How operators run a phone farm

The setup is built so that one person can act like a whole crowd of new users.

  1. 01

    Buy hardware in bulk

    The operator buys dozens of identical low-cost phones or ready-made farm boxes. Identical models make the whole rack easier to script.

  2. 02

    Wire up control

    Group-control software mirrors one screen to all devices, or runs scripts that tap, swipe and type on every phone in parallel.

  3. 03

    Give each phone a network

    Phones share one Wi-Fi network, a handful of SIM cards, or a pool of mobile proxies so each device appears to sit on a different carrier IP.

  4. 04

    Reset and repeat

    After a reward is claimed, the phone is wiped or its app data cleared, device identifiers are reset where possible, and it signs up again as a new user.

  5. 05

    Sell the output

    The farm earns from what it produces: paid installs, referral bonuses, welcome offers, followers, reviews, votes or accounts sold in bulk.

What device farms are used for

The same rack of phones can switch targets in an afternoon. What it goes after depends on where the payout is.

SchemeWhat the farm doesWho pays
Install and attribution fraudDownloads and opens the app to trigger paid installsApp marketers and ad budgets
Bonus and promo abuseClaims a welcome offer or free bet on every phoneiGaming, fintech, e-commerce
Referral abuseRefers itself in chains to collect both sides of the rewardApps with invite programs
Fake account creationRegisters accounts in bulk for resale or later useMarketplaces, social apps, fintech
Fake engagementLikes, follows, views, reviews, votes and ratingsPlatforms and honest sellers
Ad and in-app fraudViews and clicks ads inside apps to earn payoutsAdvertisers

Why device farms beat simple checks

Most mobile fraud controls were built to catch fake devices. Emulator detection looks for a phone that is really software on a desktop. Root and jailbreak checks look for modified systems. Device attestation asks the platform whether the app and device are genuine. A device farm passes all of them, because nothing about each phone is fake.

Per-device limits do not help either. "One bonus per device" works against a person with one phone, but a farm has a hundred devices, and resets let each one come back as new. Carrier IPs look like ordinary customers, and when farms sit behind residential and mobile proxies, their traffic spreads across many towns. The only thing a farm cannot easily hide is that one operator runs all of it.

Signals that give a device farm away

One phone rarely looks suspicious. A group of phones acting the same way does.

  • Shared network paths

    Many devices leave through the same Wi-Fi, the same small set of SIMs or the same proxy provider, even when their IP addresses differ.

  • Identical hardware in bulk

    The same model, operating system build, language and app set appear across dozens of new accounts in a short window.

  • Synchronized behavior

    Taps, scrolls and form entries land at the same moments with the same timing, because one script or one mirrored screen drives them all.

  • Phones that never move

    Devices are always charging, never tilt or shift, and sit in one place around the clock, unlike a phone carried in a pocket.

  • Reset patterns

    The same device returns again and again as a fresh install with cleared data, often right after claiming a reward.

  • Shift-like schedules

    Activity starts and stops on a fixed schedule, runs through the night, or follows the working hours of a farm in another time zone.

A real app user vs a farm phone

Real app user

  • One phone with a long, varied history of apps and usage
  • Moves around: home, commute, work, different networks
  • Uneven taps, pauses, typos and scrolling back
  • No link to dozens of other new accounts

Farm phone

  • Same model and build as the rest of its rack
  • Stationary, always charging, on the same network path
  • Actions in lockstep with other devices
  • Resets and returns as a new user after each reward

Avoiding false positives

Plenty of legitimate traffic shares a network or a phone model. Office Wi-Fi, university campuses and mobile carriers that put thousands of customers behind one address all look crowded. Retail stores use demo devices, and families hand down the same phone model. QA teams and app developers use real-device test labs, which are device farms by design.

Good detection treats a shared network as context, not a verdict. It looks for several links at once: the same network path and the same hardware and synchronized behavior and a reward at stake. Known test labs can be allowlisted by project, and observe-only mode shows which clusters would be flagged before anything is blocked.

How to stop device farms: a checklist

The goal is to see the farm as one actor. Once you do, you can stop paying it without touching real users who happen to share a network.

  • Assess installs, signups and reward claims on mobile and web with the same risk engine, so a farm cannot switch channels.
  • Link devices by shared network paths, hardware patterns and timing, not by IP address alone.
  • Treat reset devices that return as new users as the same actor with a history.
  • Look at clusters over time. A farm is obvious in a week of data even when each device looked clean on day one.
  • Hold referral and bonus payouts until the account shows independent, human use.
  • Rate-limit rewards per cluster, not per device, so buying more phones stops paying off.

Sources

  1. Android Developers: Play Integrity API overview
  2. Apple Developer: Establishing your app's integrity (App Attest)
  3. Google Play Console Help: Advertising ID
  4. IETF RFC 6888: Common Requirements for Carrier-Grade NATs

How Kavra helps

How Kavra detects device farms

Kavra analyzes 3,000+ data points on every visit from web and native apps, and groups devices that share one operator into a single cluster you can act on.

  • Native iOS and Android SDKs

    The same assessment runs inside your app, so installs, signups and reward claims are checked where farms work.

  • Device and identity linking

    Returning devices are recognized across resets and accounts, so a phone that comes back as new keeps its history.

  • Network context from the edge

    Kavra's own edge network sees the real connection, and its proxy intelligence maps the mobile and residential proxy pools farms route through.

  • Coordinated campaign detection

    Surges of new devices, shared infrastructure and velocity anomalies are grouped into one campaign instead of many small alerts.

  • AI/ML risk engine

    Behavior, device and network evidence are weighed together, and models keep learning as farms change hardware and scripts.

  • Explained, per-project decisions

    Each assessment says what linked the device to a farm. Allow, verify or block with your rules, and allowlist your own test labs.

FAQ

Frequently asked questions

Something else? Talk to our team.

What is a phone farm used for?

Phone farms are used to make one operator look like many real users. Common uses are fake app installs for paid install campaigns, referral and welcome bonus abuse, bulk account creation, and fake engagement such as likes, follows, reviews and votes. The same hardware switches between schemes depending on which one pays best that week.

Are device farms illegal?

Owning many phones is legal, and real-device test labs are a normal part of app development. Using them to collect install payouts, bonuses or referral rewards under false pretenses breaks platform terms and can amount to fraud, depending on the country and the scheme. Platforms usually respond by closing accounts and withholding rewards.

Can emulator detection catch a device farm?

No. Emulator detection looks for a phone that is really software running on a computer. A device farm uses real handsets with stock systems, so it passes that check every time. Catching a farm means linking the devices to one operator through shared network paths, synchronized behavior, identical hardware and reset patterns.

What is a farm box?

A farm box is a compact device farm: many phone mainboards without screens or batteries, packed into one case with shared power and a controller. Each board behaves as a separate real phone. Farm boxes are sold ready to run with group-control software, which makes large farms cheap, quiet and easy to host anywhere.

How is a device farm different from a botnet?

A botnet is made of devices infected without their owners knowing. A device farm is owned and run on purpose by one operator. Botnets tend to hide inside real households, while farms concentrate many devices in one place on shared networks, which is exactly the pattern that links them together.

Will device farm detection flag users on shared Wi-Fi?

It should not. Offices, campuses and carriers put many real people behind one network, so a shared address alone is only context. Kavra looks for several links at once, such as identical hardware, synchronized behavior and resets around rewards, before recommending action, and you can run in observe-only mode first.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.