Executive Summary
IAS Threat Lab has identified a new mobile ad fraud scheme, Papyrus, involving a cluster of novel-reading applications that monetize users’ reading sessions by running hidden browser activity in the background. While users believe they're simply reading a story, the apps are secretly using their phone to visit websites, generate clicks, and create fake engagement behind the scenes. The apps present themselves as entertainment products built around long-form fiction and serialized stories, but IAS observed them covertly navigating to web domains under the direction of command-and-control infrastructure.
Sample novel-reading apps associated with Papyrus:
The choice of novel-reading apps is central to the scheme’s monetization model. Unlike utility apps that users may open briefly to complete a task, reading apps are designed for longer, continuous sessions. Those extended sessions create more opportunity for background browser activity to navigate across monetized web properties, allowing the scheme to generate traffic while the user remains engaged with visible in-app content.
Papyrus is anchored by an extensive network of web properties built to receive traffic from the associated apps. IAS has identified more than 800 domains and nearly 8,000 unique host values associated with the scheme. These destinations are largely composed of gaming, blog, news-style, and GenAI-created content domains, reflecting the continued use of synthetic web properties built for monetization rather than real audiences.
Sample Papyrus domains used to receive and monetize hidden browser traffic:
What makes Papyrus especially concerning is that it goes beyond hidden traffic generation and actively manipulates the metrics buyers rely on. The apps use click and scroll modules that pass user taps into hidden webviews, registering clicks in the background. They also receive instructions to scroll pages, inflating attention signals and making the traffic appear more valuable to buyers. That risk showed up clearly in IAS analysis: Papyrus traffic had a nearly 25x higher click success rate, roughly 4x higher eCPM, and about 13% higher attention scores than non-Papyrus traffic. In other words, the fraudulent traffic wasn’t just fake, it appeared more valuable than legitimate traffic. That makes the impact of the metrics immediately obvious. Based on observed eCPM rates and broader supply visibility, IAS estimates that Papyrus may have generated close to $1 million per month in monetization impact at its peak.
Papyrus shows that hidden browser fraud is not limited to a single mobile environment. Schemes that pair legitimate-looking app experiences with covert monetization can emerge wherever fraud operators find the right combination of user attention, embedded browser capabilities, and monetizable web destinations.
IAS clients using IVT avoidance are already protected against Papyrus. IAS Threat Lab identified the scheme, and the associated apps, domains, and hostnames are being filtered as invalid traffic across both avoidance and measurement.
I. Technical Deep Dive
How Papyrus Works
Papyrus is built around BootNova, an orchestration layer that controls hidden browser activity inside the app.
When the app runs, BootNova contacts remote command-and-control infrastructure for configuration. The C2 can determine whether the hidden activity should run, where it should run, which URLs should be loaded, how many webviews should be active, and how those webviews should interact with loaded pages.
This remote configuration can control enablement, timing, geographic targeting, retry behavior, the number of webviews to run, destination URLs, and the interaction logic applied to those pages.
Once BootNova receives instructions, it creates and manages hidden webviews through workers called WebViewOut. These webviews load the destinations provided by the C2 while remaining out of normal user view.
The outbound webviews are concealed primarily through native view layering. A custom wrapper, CWebViewPlugin, allows the webview to remain attached to the view hierarchy while sitting behind the visible app interface. The app can also use a cover view to further obscure the outbound webview without removing it.
The effect is simple but powerful: the app can continue showing the expected reading interface while hidden webviews load and interact with web content in the background.
Embedded and Remote-Controlled Automation
Papyrus uses both embedded and server-delivered JavaScript to automate webview behavior.
The embedded JavaScript can instrument pages, capture click coordinates, and support synthetic touch, click, and scroll activity. The C2 can also deliver JavaScript at runtime, allowing the operator to adjust page-level behavior without updating the app.
IAS observed server-delivered JavaScript that can mute media elements and automatically click page elements such as consent dialogs.
Auto clicking on consent forms
This remote-control model gives Papyrus flexibility. The native app manages the hidden webview lifecycle, while the C2 can change destinations, interaction logic, and page-level behavior dynamically.
BootNova also uses obfuscation to make C2 communication less immediately visible during analysis. The module labeled RsaUtils decodes the hardcoded C2 URL and messages exchanged with the server using Base64 and indexed character shifting.
II. The Threat Landscape
Long Reading Sessions Create More Opportunity
Papyrus’s app category is not incidental. Novel-reading apps are designed for extended user sessions. A user may spend several minutes, or much longer, reading serialized content inside the app.
Long reading sessions create more opportunity for the scheme to operate. While the user is focused on visible reading content, the app can use background webviews to load remote websites, navigate across monetized destinations, and perform automated interactions.
In other words, Papyrus converts time spent reading into time available for hidden web monetization.
This is the core of the scheme: the visible app experience supplies the cover, while hidden browser activity supplies the monetization path.
The Bigger Risk: Manipulated Performance and Attention Signals
Papyrus does more than create hidden traffic. It also manipulates the signals buyers may use to understand whether traffic is valuable.
IAS observed click and scroll behavior controlled through remote configuration. The scheme uses “movement recipes” that can define click coordinates, scroll ranges, delays between actions, ad-close coordinates, and navigation behavior. These recipes are selected through probability gates, allowing the behavior to vary rather than repeat in a simple fixed pattern.
Probability gates for action recipes
Automated scrolling and clicking on game sites
This matters because clicks, scrolling, and time spent with content can influence how performance and attention are interpreted. If those interactions are happening inside hidden webviews, the resulting signals may not represent genuine user intent or engagement.
For advertisers, this is the more serious implication. Papyrus is not only generating hidden traffic; it is also attempting to make that traffic look more valuable by fabricating interaction signals.
That changes the risk profile. A hidden page load can create invalid traffic. A hidden page load combined with automated clicks and scrolling can distort performance reporting and attention-based evaluation, leading to misinformed campaign optimization strategies.
The click and scroll behavior is supported by a mix of embedded app logic and server-delivered scripts.
III. How Advertisers Can Safeguard Against Papyrus
What This Means for Advertisers — and How IAS Helps Protect Them
on its own.
A user may really be spending time inside a reading app. A web property may really receive traffic from a mobile environment. A page may really register scrolls or clicks. But in Papyrus, those signals are connected through hidden webviews and remote automation, not through a normal path from user intent to web engagement.
That distinction matters because Papyrus traffic appeared valuable on the surface. In IAS analysis, Papyrus traffic showed a nearly 25x higher click success rate, roughly 4x higher eCPM, and about 13% higher attention scores compared with non-Papyrus traffic.
IAS estimated the potential monthly impact by combining two views of Papyrus activity. First, IAS used the portion of Papyrus supply it directly observed to calculate the scheme’s eCPM. IAS then used broader supply-path data to estimate a larger view of Papyrus impression volume. Applying the observed Papyrus eCPM to that broader impression footprint indicates the scheme may have generated close to $1 million per month at its peak.
For advertisers, the risk is not only wasted spend on hidden traffic. It is the possibility that fabricated engagement can influence optimization, reporting, and trust in media quality.
IAS clients using IVT avoidance are already protected against Papyrus. IAS Threat Lab identified the scheme, and the associated apps, domains, and hostnames are being filtered as invalid traffic across both avoidance and measurement.
By filtering the associated apps, domains, and hostnames, IAS helps keep Papyrus-associated supply out of protected campaigns and prevents the activity from being counted as valid engagement in measurement. This helps reduce the risk that automated clicks, hidden webview traffic, or inflated attention signals influence campaign delivery, optimization, or reporting.
Papyrus demonstrates why IVT protection must connect signals across the full chain: the app environment, hidden webview behavior, destination domains, hostnames, and the automated clicks and scrolling used to make synthetic engagement appear real.
IV. Methodology
How IAS Confirmed the Behavior
IAS confirmed this behavior during analysis by identifying a server-controlled test mode in the WebViewOut worker. When enabled, this mode brought the normally hidden webview forward, allowing researchers to observe automated scrolling, clicking, consent-form interaction, and the relationship between the visible reading interface and the hidden webview layers.
Showing ebook app open, then revealing hidden masking layers and hidden webviews
This confirmed that Papyrus’s hidden browser activity could run beneath the normal app interface while the user remained focused on the visible reading experience.
Conclusion
Papyrus shows how a legitimate looking mobile app experience can be used to generate hidden web traffic and fabricate signals that make that traffic appear valuable. By combining BootNova-driven C2 instructions, hidden webviews, and automated clicks and scrolling, the scheme attempts to turn long reading sessions into monetizable web activity.
IAS has identified more than 800 domains and nearly 8,000 unique host values associated with Papyrus. IAS Threat Lab will continue tracking the scheme as it evolves, while IAS IVT avoidance filters associated apps, domains, and hostnames as invalid traffic across avoidance and measurement.
Share on LinkedIn
Share on X

