POST /bonus/claimVerifyFresh VM claiming a new-player bonus
- Virtual graphics, claims laptop
- Cloud hosting network
- No link to other accounts yet
Detection
A virtual machine is a software computer running on a physical host, with its own operating system, browser and fake hardware. Fraudsters clone and reset VMs to present a brand-new device for every account or attempt. Kavra detects the virtual hardware underneath and checks it against what the device claims to be, so real office desktops are not punished.
POST /bonus/claimVerifyFresh VM claiming a new-player bonus
A virtual machine (VM) is a complete computer simulated in software. A program called a hypervisor splits one physical machine into many guests, and each guest gets its own operating system, disk, memory and network card. From inside, it feels like a normal PC. You can install a browser, log in and browse like anyone else.
For fraud, the appeal is that devices become cheap and disposable. An operator builds one clean Windows image, clones it a hundred times and resets each copy to a fresh snapshot after every account. Every signup appears to come from a new computer with empty storage, no history and no cookies. Rented cloud desktops go further: the operator never touches hardware at all and can start machines in any region in minutes, then delete them when the job is done.
The pattern is the same whether the target is a sportsbook, a fintech app or an AI product with free credits.
One VM is set up with a browser, extensions, scripts and sometimes an antidetect tool, then saved as a template.
Copies are started from the template. Some operators randomize the machine name, screen size, language and timezone of each copy to look less alike.
Each VM exits through its own proxy or VPN, because the host's datacenter IP would give the game away. See residential and mobile proxies.
A person or a script signs up, claims the offer or tests credentials. Headless automation often runs inside the VM. See headless browsers.
The VM is reverted to its snapshot. All traces are gone from the guest, and the next account starts on a device that looks new.
VMs rarely are the attack. They are the device factory that makes volume attacks affordable.
A VM can hide its name. It is much harder to hide the simulated hardware it runs on, and even harder to make that hardware match the device it claims to be.
The graphics adapter is a virtual display driver or a software renderer instead of a real graphics card from a laptop or desktop maker. Rendering output and speed follow.
The browser says it is a gaming laptop or a MacBook, but the processor count, memory, graphics and fonts point to a generic virtual server.
Many visitors share the same default screen size, the same stock fonts and the same install fingerprint, with only surface values changed.
No battery on a machine that claims to be a laptop, no audio hardware, no touch or media devices where a real device would have them.
Traffic from cloud hosting ranges, or a proxy exit whose location disagrees with the VM's timezone and language settings.
Clock and performance quirks from shared hardware, and a device that is always "first seen" because its history is wiped by each rollback.
Most VM detection advice comes from desktop software: look for a known driver name or a telltale hardware ID. In a browser, a page sees much less, and what it sees can be rewritten. Antidetect tools running inside a VM can report any graphics card name they like. Cookie and storage checks fail because each rollback clears them. IP checks fail once a proxy is attached.
What survives is consistency. A VM can relabel its graphics adapter, but it cannot make a software renderer draw like a real graphics chip. It can claim a laptop, but the rest of the machine still behaves like a server. Contradictions between the claimed device and the real environment, and between the device and its network, are what give a well-dressed VM away.
Plenty of honest customers sit behind a virtual machine every day. Being virtual is a risk signal, not a verdict.
| Who | Why they use a VM | How to treat them |
|---|---|---|
| Corporate VDI users | Employers deliver desktops from a data center or the cloud for security and remote work | Expect virtual graphics and shared company IPs; judge by behavior, account history and device consistency |
| Mac users running Windows | A desktop hypervisor for one app that needs Windows | Stable device that returns with the same account; low risk |
| Developers and QA teams | Testing builds on several operating systems | Mark known test environments as trusted through the API |
| Security researchers and privacy-minded users | Isolation from their main system | Allow browsing; step up only on high-value actions |
| Fraud operators | Disposable devices at scale | Watch for resets, template sameness, proxy exits and links to other accounts |
How Kavra helps
Kavra analyzes 3,000+ data points on every visit and separates honest virtual desktops from disposable devices built to farm your offers.
Virtual graphics, software rendering and simulated hardware are identified from how the device behaves, even when its reported names are rewritten.
Kavra compares the device a browser claims to be with the environment it actually runs in, and with the network it uses.
A device that resets and returns as new is kept as one actor with many rotations, not counted as many new visitors.
Accounts that come from clones of the same image and network patterns are grouped into one cluster you can review.
Cloud hosting ranges and commercial proxy exits are recognized using Kavra's own measurements plus 30+ reputation feeds.
Virtual is weighed, not auto-blocked. Use observe-only mode and cautious, balanced or strict presets to fit your audience.
FAQ
Something else? Talk to our team.
Often, yes. A page can see how the device renders graphics, what hardware it reports and how it performs. Virtual machines usually use virtual or software graphics and generic hardware that differ from physical laptops and desktops. Detection gets more reliable when those details are compared with what the browser claims and with the network it connects from.
No. Many companies deliver desktops through virtual desktop infrastructure, and developers, testers and privacy-minded users run VMs every day. A VM becomes suspicious when it pretends to be a different device, resets to look new on every visit, exits through a proxy or links to other accounts claiming the same offer.
Operators try, by renaming hardware, passing a real graphics card through to the guest or running an antidetect browser inside. That hides the easy markers, but hiding everything is costly and still leaves contradictions between the device, its behavior and its network. The harder a VM works to look physical, the more it tends to disagree with itself.
Because they are cheap, fast and disposable. A cloud desktop can be started in any region in minutes, cloned from a prepared image and deleted when the job is done, leaving no physical hardware to replace. That lets one operator present hundreds of new devices without buying any.
It should not if it is done properly. Corporate virtual desktops return day after day as the same device, on the same company network, with a consistent account history. Good detection weighs those signals, treats virtual hardware as one input and keeps blocks for VMs that also contradict themselves or behave like disposable devices.
A virtual machine runs a full computer on the same kind of processor as its host, usually Windows or Linux on a PC or server. An emulator imitates a different kind of device, most often an Android phone on a desktop. Fraudsters use VMs to fake new computers and emulators to fake new phones.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.