Novel-reading apps used users’ phones to generate fake ad traffic

A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab.

Papyrus mobile ad fraud

Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab)

While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a browser window hidden from view, clicking on them, and scrolling through them on its own.

“Papyrus is built around BootNova, an orchestration layer that controls hidden browser activity inside the app. When the app runs, BootNova contacts remote command-and-control infrastructure for configuration. The C2 can determine whether the hidden activity should run, where it should run, which URLs should be loaded, how many webviews should be active, and how those webviews should interact with loaded pages,” the researchers explained.

“This remote configuration can control enablement, timing, geographic targeting, retry behavior, the number of webviews to run, destination URLs, and the interaction logic applied to those pages.”

Once BootNova receives its instructions, it hands them to workers called WebViewOut, which open and manage the browser windows the user never sees. A wrapper called CWebViewPlugin keeps those windows attached to the app’s interface while positioning them behind what’s on screen. Some apps layer a cover view on top of that as well.

“The effect is simple but powerful,” the researchers said. “The app can continue showing the expected reading interface while hidden webviews load and interact with web content in the background.”

BootNova also takes steps to keep its own communication out of sight. A module the researchers labeled RsaUtils decodes the hardcoded C2 address, along with the messages exchanged with the server, using Base64 and a character-shifting cipher, so the address doesn’t sit in plain text for anyone inspecting the app.

Papyrus automates hidden browsing

Papyrus drives the hidden browser windows two ways. Some JavaScript is built into the app and can track where a page has been tapped, then replay that as a synthetic touch, click, or scroll. The rest is sent down from the operator’s own servers at runtime, letting them change what the hidden browser does on any page without pushing an app update.

“IAS observed server-delivered JavaScript that can mute media elements and automatically click page elements such as consent dialogs,” the researchers added.

There’s a third layer as well. According to IAS, the apps use “click and scroll modules that pass user taps into hidden webviews, registering clicks in the background.” In other words, a tap someone makes on the visible reading screen can get copied into the hidden browser and counted as a click there too.

Whichever source the automation comes from, it doesn’t move at random.

“The scheme uses ‘movement recipes’ that can define click coordinates, scroll ranges, delays between actions, ad-close coordinates, and navigation behavior,” IAS noted. “These recipes are selected through probability gates, allowing the behavior to vary rather than repeat in a simple fixed pattern.”

Novel-reading apps weren’t chosen at random either. People open them and stay, unlike a utility app someone checks for a few seconds and closes.

“Papyrus converts time spent reading into time available for hidden web monetization,” the researchers explained. “The visible app experience supplies the cover, while hidden browser activity supplies the monetization path.”

Scale of the operation

IAS has linked Papyrus to more than 800 domains and nearly 8,000 unique hostnames. Most are gaming sites, blogs, news-style pages, and GenAI-created content built to receive traffic rather than serve an audience.

The click success rate on this traffic ran nearly 25 times higher than non-Papyrus traffic, with an eCPM about four times higher and attention scores 13 percent above normal, IAS found.

“The fraudulent traffic wasn’t just fake,” IAS found. “It appeared more valuable than legitimate traffic.”

Based on those rates and the portion of Papyrus’s supply IAS could observe directly, the firm estimates the scheme brought in close to $1 million a month at its peak.

“A hidden page load can create invalid traffic,” the researchers warned. “A hidden page load combined with automated clicks and scrolling can distort performance reporting and attention-based evaluation, leading to misinformed campaign optimization strategies.”

That’s the part that reaches past wasted ad spend. If a campaign looks like it’s performing because of numbers generated inside a hidden browser window, an advertiser can end up putting more budget behind the exact traffic that’s defrauding them.

Don't miss