Detection

Emulator detection that knows a real phone from a desktop copy

An emulator is software that imitates a phone on a desktop computer, most often an Android device, so apps and mobile websites run as if on a real handset. Fraud teams run dozens of instances at once to fake new phones for every account. Kavra spots the desktop behind the phone by checking sensors, hardware and network against the device claimed.

POST /referral/claimBlocked

Emulated phone, one of 22 on one PC

  • Android emulator, no real sensors
  • Desktop graphics in a phone
  • Linked to 21 referral accounts
Risk95
Your actionWithhold the referral reward
What it is
Software that runs a virtual phone on a PC or Mac
Attacks it enables
Fake signups, referral and promo abuse, app bot farms
Common setups
Developer emulators, gaming emulators, multi-instance managers
Where to check
App install and signup, OTP, promo claim, payouts

What is a mobile emulator?

A mobile emulator is a program that runs a virtual phone inside a desktop computer. The best-known kind emulates Android: the operating system boots in a window, apps install from an app store or a file, and a mouse stands in for a finger. Some are official developer tools. Others are built for playing mobile games on a PC and ship with features for running many phones side by side.

Apple's iOS Simulator is a related but narrower tool. It runs only on a Mac, inside Apple's developer tools, and runs apps built for testing rather than regular App Store apps. That limits it for abuse inside iOS apps, but it can still load mobile websites in a Safari that reports itself as an iPhone. Desktop browsers also have a mobile preview mode that changes screen size and user agent. That is not a full emulator, but fraudsters use it the same way: to look like a phone without owning one.

Emulators vs virtual machines vs real devices

The three are easy to mix up. They leave different traces.

EmulatorVirtual machineReal device farm
What it fakesA phone, on a desktopA computer, on a server or PCNothing: real phones, one operator
Hardware underneathDesktop processor and graphics, simulated phone partsVirtual hardware of the same kind as the hostGenuine phone hardware
Typical targetMobile apps and mobile websitesDesktop websites and web appsApps that check for real devices
Cost per extra deviceAlmost nothing: another instanceLow: another cloneHigh: another handset
Main tellsMissing or flat sensors, desktop graphics, no carrierVirtual graphics, generic hardware, cloud networkMany phones, one location, one behavior
Learn moreThis pageVirtual machinesDevice farms

How emulator farms are used for fraud

An emulator farm is one or a few desktops running many virtual phones at once, controlled by scripts.

  1. 01

    Launch instances

    A multi-instance manager starts dozens of Android phones on one machine, each cloned from a prepared image with the target app installed.

  2. 02

    Spoof each phone

    The operator changes the model name, device IDs, phone number, location and language of each instance, so every one claims to be a different handset.

  3. 03

    Route the traffic

    Each instance gets its own mobile or residential proxy to look like a phone on a carrier network. See residential and mobile proxies.

  4. 04

    Script the app

    Macros or automation tools tap through signup, request the SMS code, enter referral codes and claim offers, identically on every instance.

  5. 05

    Wipe and repeat

    Instances are reset or recreated. Each new run shows up as a phone your app has never seen before.

Which attacks emulators enable

Mobile-first businesses often trust the app more than the website. Emulators exist to exploit that trust at desktop prices.

  • Fake account creation in apps that give each new install a reward.
  • Referral and promo abuse: one person inviting themselves dozens of times.
  • Bonus abuse in betting and gaming apps, where each emulated phone claims its own welcome offer.
  • SMS pumping: scripted OTP requests from app signup screens.
  • Game and ride-hailing fraud: faked locations, farmed in-game rewards and fake drivers or riders.
  • Install and ad fraud: emulated installs and in-app events that trigger marketing payouts.

The tells of an emulated phone

An emulator can copy the model name of any phone. Copying the physics of a real phone in someone's hand is much harder.

  • Sensors that are missing or too perfect

    No motion sensors, or readings that are flat, repeated or perfectly still. A real phone in a hand is never completely still.

  • A desktop inside the phone

    A desktop processor architecture or desktop graphics chip behind a device that claims to be a mid-range Android phone.

  • Battery and power

    Always plugged in, always the same level, or no battery at all. Real phones drain, charge and vary.

  • Device details that do not match

    The claimed model, screen size, pixel density and system build do not line up with how that handset ships.

  • Network that is not mobile

    A phone with no carrier, on home broadband or a datacenter, or on a proxy whose location disagrees with its settings.

  • Mouse-shaped touches

    Taps with no pressure or contact size, pixel-perfect positions and swipes that move like a mouse drag.

Why emulators are hard to catch

Older emulators were obvious: a generic model name, a telltale build tag, a fixed phone number. Modern gaming emulators and fraud tooling change all of these, and root-level tools can rewrite almost any value an app asks for. Checks that read one property and compare it to a list are defeated in a single update.

What operators cannot easily fake is a coherent physical device. Sensors, battery, graphics, processor, touch input and network all have to agree with each other and with the model claimed. Across twenty instances on one PC, they also tend to agree with each other far too well. Detection that compares layers, and links instances that share an underlying machine, holds up when single checks fail.

A gamer on a PC emulator vs an emulator farm

Gamer or developer on an emulator

  • One instance, the same one every session
  • Home broadband that matches the settings
  • One account with a real play or test history
  • Does not pretend to be a specific handset

Emulator farm

  • Dozens of instances from one machine
  • A different proxy exit for each instance
  • Fresh accounts heading straight for rewards
  • Spoofed models and IDs that contradict the hardware

Legitimate emulator users and false positives

Emulators are everyday tools. App developers and QA teams test on them constantly. Gamers play mobile titles on a PC for a bigger screen and a keyboard, and in some markets that is a large share of a game's audience. Some people use an emulator for accessibility or to run an app that has no desktop version.

Blocking every emulator would lose those customers. A better policy separates being an emulator from pretending not to be one, and weighs both against the action.

  • Allow emulators for low-risk actions such as browsing and play; decide at rewards, referrals and payouts.
  • Treat an honest, stable emulator that returns with its own account as low risk.
  • Treat spoofed device details, rotating identities and many instances on one machine as high risk.
  • Mark your own test devices and emulators as trusted, so QA never trips your rules.
  • Protect both your app and your mobile website: farms move to whichever is weaker.
  • Start in observe-only mode and review emulator traffic before enforcing anything.

Sources

  1. Android Developers: Run apps on the Android Emulator
  2. Apple Developer: Testing and Debugging in Simulator
  3. Android Developers: Play Integrity API overview
  4. Chrome for Developers: Simulate mobile devices with device mode

How Kavra helps

How Kavra detects emulators

Kavra analyzes 3,000+ data points on every visit, in your mobile website and through native iOS and Android SDKs, and tells your backend when a phone is not a phone.

  • Native iOS and Android SDKs

    In-app checks see device details a web page cannot, so emulated handsets are caught inside your app as well as on your mobile site.

  • Physical consistency

    Sensors, power, graphics, processor and touch input are compared with each other and with the claimed model.

  • Instances linked to one machine

    Many phones that share one underlying desktop are grouped as one actor, so a farm shows up as a cluster, not as strangers.

  • Rotation is a signal

    An instance that resets and returns with new IDs is kept as the same actor with each rotation counted.

  • Mobile network checks

    Kavra measures real exit IPs of commercial mobile and residential proxies, so a fake carrier connection does not pass as a real one.

  • Room for real users

    Emulators are weighed, not auto-blocked. Set rules per action and let honest gamers and developers keep playing and testing.

FAQ

Frequently asked questions

Something else? Talk to our team.

Can apps detect if they are running on an emulator?

Yes. An app can read far more than a web page: sensors, battery, hardware, system build and how touches arrive. Emulators differ from real phones on many of these at once. Tools that spoof one value, such as the model name, rarely fix the rest, so an in-app SDK that compares them catches most emulated devices.

Is using an Android emulator illegal?

No. Android emulators are legal and widely used by developers, testers and gamers. Using one to break a service's terms, for example creating many accounts to claim referral rewards or faking a location, can lead to bans, withheld rewards and in some cases fraud claims. The tool is neutral; the use decides.

How do fraudsters run many phones from one computer?

They use multi-instance emulator managers that start dozens of virtual Android phones on one PC, each cloned from a prepared image. Scripts or macros then tap through the same flow in every instance, while each one exits through its own proxy. The result looks like many new phones in many places.

Can emulators fake GPS location?

Yes. Emulators let the user set any location, and the app receives it as if it came from GPS. That is why location alone should never be trusted. Compare it with the network, timezone, language and the device's own history. A phone in one city on a proxy from another, with no motion at all, is a strong warning.

Can you detect the iOS Simulator on a website?

Often. The iOS Simulator runs on a Mac, so the page is really rendered by a desktop with Mac graphics and no phone sensors, even though it reports an iPhone. Screen, graphics, touch and motion details reveal that mismatch. Most iOS app abuse uses real devices instead, which is where device farm detection comes in.

Should I block all emulators in my app?

Usually not. You would lose developers, testers and gamers who play on PC, and a determined operator would move to real phones anyway. Detect emulators, then decide per action: allow browsing and play, and step up or refuse at signup rewards, referrals, promos and withdrawals when the emulator also hides what it is.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.