Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
Key Takeaways Papyrus is a sophisticated mobile ad fraud operation embedded within seemingly innocuous novel-reading applications. The scheme leverages hidden webviews to simulate user engagement,...
Key Takeaways
- Papyrus is a sophisticated mobile ad fraud operation embedded within seemingly innocuous novel-reading applications.
- The scheme leverages hidden webviews to simulate user engagement, including clicks, scrolls, and visits to monetized websites, all while the user interacts normally with the app.
- This operation, controlled remotely, has impacted over 800 domains and nearly 8,000 unique hosts, potentially generating close to $1 million in monthly fraudulent revenue at its peak.
- The fabricated engagement metrics distort advertiser data, leading to misallocated marketing budgets and an inaccurate understanding of genuine user interaction.
- Users are advised to download apps only from trusted sources and monitor for unusual battery drain or data usage, while advertisers should employ robust invalid traffic controls and scrutinize performance data.
Papyrus: A Deceptive Mobile Ad Fraud Network
A new mobile ad fraud operation, dubbed Papyrus, has been uncovered, utilizing a stealthy approach to generate artificial user engagement. This sophisticated scheme operates through seemingly benign applications designed for reading serialized fiction. While users are engrossed in their stories, these apps surreptitiously open websites in the background, fabricating traffic and user interactions.
Table Of Content
The fraudulent activity capitalizes on extended reading sessions, providing ample time for the hidden browser processes to run undetected. This method mirrors other known hidden browser fraud operations, where legitimate-looking mobile applications serve as a front for automated advertising fraud.
Unveiling the Papyrus Operation
Analysts at Integral Ad Science (IAS) identified Papyrus within a collection of novel-reading applications. Their investigation revealed that the operation is orchestrated by remote command-and-control (C2) servers. The primary objective of Papyrus is to load monetized web destinations, simulate clicks, and mimic scrolling behavior, all while the foreground application appears to function normally to the user. This advanced manipulation allows the fraudsters to generate revenue without any genuine user interaction, as detailed in an in-depth report by IAS.
The scale of Papyrus is significant. IAS estimates that the operation, at its peak, may have generated nearly $1 million in monthly fraudulent revenue. It encompasses more than 800 associated domains and close to 8,000 unique host values. Critically, as IAS said in a report, this fraud also corrupts the performance data that advertisers rely on to make critical budgeting decisions, leading to inefficient and misdirected ad spend.
Papyrus Mobile Ad Fraud Uses Hidden WebViews
The technical backbone of the Papyrus operation is an orchestration layer named BootNova. Upon app launch, BootNova establishes contact with remote infrastructure to receive instructions. These instructions dictate whether the fraud module should activate, which web destinations to target, the number of hidden browser views to open, and how these views should behave. This remote control allows operators to dynamically adjust parameters such as timing, geographical targeting, retry attempts, and interaction rules without requiring an app update.
The Mechanics of Deception
BootNova employs a component called WebViewOut to generate browser views that are concealed behind the app’s visible user interface. Another crucial element, CWebViewPlugin, ensures these views remain attached to the screen’s structure while staying out of sight, sometimes hidden beneath an additional opaque layer. This means users can be actively reading their book while, unbeknownst to them, multiple web pages are loading and interacting in the background.
The fraud operation further utilizes embedded app code and server-provided scripts to interact with these hidden web pages. It can accurately capture tap coordinates from the user’s visible interaction and replicate them within the concealed browser. Furthermore, it can simulate page scrolling, close advertisements, and automatically manage consent prompts, making the fraudulent activity appear remarkably authentic. This approach to automated Android click fraud, leveraging invisible browser windows, effectively transforms legitimate device activity into fabricated ad interactions. The remote control model is key, enabling operators to modify destinations and page-level behaviors in real-time.
IAS also noted the presence of an RsaUtils module, which obfuscates the hardcoded C2 addresses and server communications using Base64 encoding and character shifting, adding a layer of stealth to the operation.
Fabricated Signals Can Mislead Advertisers
Papyrus goes beyond merely inflating website visits; its sophisticated click and scroll modules are designed to generate signals that are typically interpreted as genuine user attention. IAS researchers observed “movement recipes” that precisely define click locations, scrolling ranges, delays, navigation choices, and ad-closure coordinates. Probability controls are then applied to introduce variation, making the automated patterns less predictable and thus more convincing.
Despite this variation, the activity remains entirely artificial. IAS’s research indicated that Papyrus traffic exhibited a nearly 25 times higher click success rate, approximately four times higher effective Cost Per Mille (eCPM), and about 13 percent higher attention scores compared to non-Papyrus traffic. This skewed data creates a distorted view of actual user engagement, leading advertisers to misinterpret where their audiences are genuinely interacting.
The implications are significant for advertisers, as campaign optimization systems often prioritize traffic that appears to yield the best performance. Fabricated clicks and scrolls can lead to misdirected spending, inaccurate reporting, and future ad delivery being steered towards fraudulent sources. The emergence of Papyrus, alongside other recent mobile app fraud campaigns, underscores the critical need for scrutiny of seemingly harmless applications, especially when their behavior deviates from their stated purpose.
What You Should Do
- For Advertisers:
- Rigorously examine any unusual spikes in click rates, attention signals, or perceived value originating from specific app and web sources.
- Validate traffic across all layers: app, browser, destination, and hostname.
- Implement robust invalid-traffic controls to block known fraudulent supply, rather than solely relying on superficial engagement metrics.
- For Users:
- Only download reading and entertainment applications from reputable and trusted app stores.
- Carefully review the permissions requested by any app before installation.
- Be vigilant for unexplained battery drain, excessive data usage, or any intrusive behavior from installed applications, and promptly remove any suspicious apps.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.