Papyrus Mobile Ad Fraud Uses Hidden WebViews to Fake Clicks, Scrolls and Attention

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Papyrus is a mobile ad fraud operation hiding behind apps built for reading serialized fiction. While people turn pages and follow stories, the apps can quietly open websites in the background and create traffic.

The scheme takes advantage of long reading sessions, giving operators time to run concealed browser activity.

That model echoes other hidden browser fraud operations, where legitimate-looking mobile experiences mask automated advertising activity.

Analysts at IAS identified Papyrus in a cluster of novel-reading applications and found that it was directed by remote command-and-control servers.

Sample novel-reading apps associated with Papyrus (Source – IAS)

The operation is designed to load monetized destinations, make clicks, and simulate scrolling while the visible app continues to look normal.

The impact reaches beyond a few unwanted page loads. IAS found more than 800 associated domains and nearly 8,000 unique host values, and estimated the operation may have produced close to $1 million in monthly monetization impact at its peak.

IAS said in a report shared with Cyber Security News (CSN) that the fraud can also warp the performance data advertisers use to decide where budgets go.

At the center of Papyrus is an orchestration layer called BootNova. After an app starts, it contacts remote infrastructure for instructions on whether to run, which destinations to load, how many browser views to open, and how they should behave.

Operators can also alter timing, location targeting, retry settings, and interaction rules without issuing an app update.

BootNova uses workers called WebViewOut to create browser views hidden behind the app’s normal interface.

Sample Papyrus domains used to receive and monetize hidden browser traffic (Source – IAS)

A component named CWebViewPlugin keeps the views attached to the screen structure but out of sight, sometimes beneath an additional cover layer. The reader sees a book, while web pages can load underneath it.

The operation then uses code embedded in the app and scripts supplied by its servers to interact with those pages.

It can capture tap coordinates, copy touches into the concealed browser, scroll pages, close ads, and automatically handle consent prompts.

Similar automated Android click fraud has shown how invisible browser windows can turn device activity into artificial ad interactions. The remote model lets operators change destinations and page-level behavior dynamically.

Work flow (Source – IAS)

It also observed a module labelled RsaUtils that obscures the hardcoded command-and-control address and server messages using Base64 encoding and character shifting.

Papyrus does not simply inflate visits. Its click and scroll modules are built to manufacture the signals often treated as evidence of user attention.

IAS observed “movement recipes” that can set click locations, scrolling ranges, delays, navigation choices, and ad-close coordinates, with probability controls used to vary the patterns.

That variation makes the activity look less repetitive, but it does not make it real.

In the research, Papyrus traffic recorded a nearly 25-times higher click success rate, roughly four-times higher eCPM, and about 13 percent higher attention scores than non-Papyrus traffic. The result is a distorted picture of where people are actually engaging.

This risk matters because campaign systems may optimize toward traffic that appears to perform best.

Probability gates for action recipes (Source – IAS)

A fabricated click or scroll can steer spending, reporting, and future delivery in the wrong direction.

Recent mobile app fraud campaigns also underline why harmless-looking apps deserve scrutiny when their behavior does not match their stated purpose.

Advertisers should examine unusual jumps in click rates, attention signals, or value from particular app and web sources, and should validate traffic across the app, browser, destination, and hostname layers.

They should also use invalid-traffic controls that can block known bad supply, rather than relying only on surface-level engagement metrics.

For users, the practical warning is simpler: install reading and entertainment apps from trusted sources, review permissions, and remove apps that show unexplained battery drain, data use, or intrusive behavior.

The wider lesson from Papyrus and the Android ad fraud threat is that a convincing front-end experience can conceal activity that benefits someone else.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world