A cluster of mobile apps sold as digital novels was quietly using readers' phones as browsers, loading web pages behind the reading screen and clicking through them without anyone noticing.
Integral Ad Science published research on August 6, 2026 describing a mobile fraud operation its Threat Lab has named Papyrus. The scheme is built on applications that present themselves as entertainment products for long-form fiction and serialized stories. Behind that interface, according to IAS, the apps open hidden browser windows and navigate to web destinations chosen by remote command-and-control infrastructure.
The company said it has associated more than 800 domains and nearly 8,000 unique host values with the operation. An indicator list published alongside the research contains 812 individual domains. IAS estimates the scheme may have generated close to $1 million per month in monetization impact at its peak.
What separates Papyrus from the standard hidden-traffic playbook is what the apps did once the pages loaded. The report describes modules that pass a reader's real taps into the concealed browser window, registering clicks on pages the reader never saw, and separate instructions that scroll those pages to inflate engagement signals. The resulting traffic did not merely pass as legitimate. On the metrics buyers use to grade inventory, it graded better.
The signal distortion
IAS compared Papyrus traffic against non-Papyrus traffic across three measures. Click success rate ran nearly 25 times higher. Effective cost per mille came in roughly four times higher. Attention scores landed about 13 percent above baseline.
That combination is the substantive finding. A hidden page load produces invalid traffic, which measurement systems have been catching for years. A hidden page load combined with synthetic clicks and scrolling produces something different: inventory that appears, on every downstream indicator, to be performing unusually well. Campaign optimization systems that shift budget toward stronger click and attention signals would move budget toward it.
The movement recipes governing that behavior are configurable. According to IAS, the recipes can specify click coordinates, scroll ranges, delays between actions, coordinates for closing ads, and navigation behavior. Rather than executing one fixed pattern, the app selects among recipes using probability gates, so the automated interaction varies from session to session. Fixed repetition is what detection systems look for. Varied repetition is harder.
Inside the technical stack
The orchestration layer is called BootNova. When an app launches, BootNova contacts remote infrastructure for its configuration. That configuration determines whether the hidden activity runs at all, where it runs, which URLs load, how many browser windows operate concurrently, and how those windows interact with the pages they load. Timing, geographic targeting and retry behavior are all set remotely.
Once instructions arrive, BootNova creates and manages the concealed windows through workers the report identifies as WebViewOut. Concealment is handled primarily through native view layering. A custom wrapper named CWebViewPlugin keeps the browser window attached to the app's view hierarchy while positioning it behind the visible interface. The app can also draw a cover view over the top for additional obscuring, without removing the window from the hierarchy.
The design point is that nothing needs to be hidden from the operating system, only from the person holding the phone. The reading interface renders normally. The browser window sits underneath it, fully functional.
Automation delivered at runtime
Papyrus uses two layers of JavaScript. Embedded scripts inside the app can instrument loaded pages, capture click coordinates, and support synthetic touch, click and scroll events. A second layer arrives from the command-and-control server at runtime, which allows the operator to change page-level behavior without shipping an app update.
IAS observed server-delivered JavaScript capable of muting media elements on loaded pages and automatically clicking page elements including consent dialogs. Muting matters because an unmuted autoplay video inside a concealed window would betray the whole arrangement through the phone's speaker. The consent dialog handling is more consequential in a different direction: a consent management platform recording an acceptance in this scenario is recording an action taken by a script, not by a reader who never saw the page. The IAS research does not address the regulatory implications of that behavior.
Communication with the server is obfuscated. A module the report labels RsaUtils decodes a hardcoded server URL and the messages exchanged with it, using Base64 encoding combined with indexed character shifting. The technique does not defeat determined analysis, but it removes the plain-text strings that make a hidden endpoint obvious on first inspection.
Why novels
The app category is a design decision rather than an accident. Utility applications get opened for a task and closed. Reading applications are built for duration, and a reader working through serialized fiction may stay inside the app for many minutes at a stretch.
Every one of those minutes is available for background navigation across monetized destinations. The scheme converts reading time into browsing time, with the visible content supplying both the reason to keep the app open and the cover for what runs beneath it. It is a straight trade of user attention on one surface for fabricated attention on another.
The destination network
The 812 domains on the published indicator list are dominated by gaming and casual-play properties. Analysis of the list shows 207 entries containing the string "game" and 51 containing "play", alongside blog-style, news-style and lifestyle names such as expressnewschronicle.com, quicknewspapers.com and viewernews.com. IAS characterizes the destinations as largely gaming, blog, news-style and content generated by artificial intelligence, consistent with synthetic web properties built for monetization rather than for readers.
Registration patterns reinforce that reading. Only 380 of the 812 domains sit on .com. The remainder cluster on low-cost alternatives: 123 on .top, 89 on .site, 40 on .xyz, 26 on .lol, 24 on .pro and 22 on .space. Several appear in numbered series, including seven bjsvp variants, eleven puzzgo variants and five szgame variants on the .lol extension, the signature of bulk registration rather than independent publishing.
The ratio between the two figures IAS disclosed is worth noting on its own. Nearly 8,000 unique host values spread across more than 800 domains implies roughly ten hostnames per domain, meaning the operation was generating subdomains at scale rather than relying on the domains themselves as the unit of supply.
How the behavior was confirmed
IAS documented the mechanism through a feature the operators built for themselves. The WebViewOut worker contains a server-controlled test mode which, when enabled, brings the normally concealed browser window to the front. With that mode active, researchers could watch the automated scrolling, the clicking, the interaction with consent forms, and the relationship between the visible reading interface and the layers hidden behind it.
The revenue estimate rests on a two-step calculation the company describes in the report. IAS first used the portion of Papyrus supply it observed directly to derive the scheme's eCPM, then applied broader supply-path data to estimate total impression volume, and multiplied one by the other. The figure carries the hedges that method implies: IAS says the scheme may have generated close to $1 million per month at its peak. The report does not disclose the observation window, the length of that peak, the share of supply directly observed, the number of applications involved, or the app stores through which they were distributed. It also declines to name the mobile operating system, noting only that hidden browser fraud is not confined to a single environment.
The research carries no individual byline. It is credited to the IAS Team, and no named researcher or executive is quoted in it.
What it means for buyers
IAS said clients using its invalid traffic avoidance are already protected, with the associated apps, domains and hostnames filtered across both avoidance and measurement products. That is the standard disclosure pattern for vendor threat research, and it means the practical exposure sits with campaigns running without that filtering.
The wider significance is about which metric got manipulated. Attention measurement moved from experiment to currency over the past year. The Media Rating Council and the IAB finalized attention measurement guidelines in November 2025, establishing minimum requirements for comparability across vendors while explicitly cautioning that attention is not itself an outcome measure. IAS and Stellantis built one of the largest attention datasets in advertisingacross 13 billion impressions in 19 countries, published in June 2026. The company's March 2026 partnership with Mastercard cited 246 percent higher sales lift for impressions with stronger attention scores.
A 13 percent inflation in attention scores lands directly on that machinery. Where attention feeds bidding decisions, budget allocation and post-campaign sales attribution, fabricated scroll events do not just waste impressions. They corrupt the signal that other decisions are built on.
The finding also complicates a set of numbers the industry has been reading as progress. DoubleVerify reported at the end of July 2026 that fraud and invalid traffic violation rates fell 41 percent year over year in North America and 45 percent in EMEA. Aggregate violation rates falling and individual schemes becoming better at passing quality checks are not contradictory outcomes. A scheme that clears verification is not counted as a violation.
Papyrus arrives in a crowded month for mobile fraud research. DoubleVerify's engineering team published its AfterCall analysis in July 2026, describing dozens of Android applications discovered monthly that display advertisements immediately after phone calls end. HUMAN Security disrupted the NewsJunkie connected television operation the same month, a device-spoofing scheme running up to two billion invalid bid requests a day. Structurally, Papyrus sits closest to Konfety, the 2024 operation that used counterfeit applications built on the CaramelAds software development kit, though Konfety monetized fake in-app inventory while Papyrus routes value out to the open web.
That routing is the part with the longest tail. The destinations Papyrus feeds resemble the synthetic content networks that DoubleVerify documented in AutoBait, a March 2026 investigation into more than 200 made-for-advertising domains producing clickbait with large language models at roughly $2.25 per article. Research published on July 28, 2026 by TAG, the ANA and Fiducia found that AI-generated content wins premium quality grades about 70 percent of the time. Papyrus supplies traffic; the synthetic content networks supply the pages that traffic lands on; the grading systems in between rate the combination favorably.
For programmatic buyers, the practical detail is that none of the individual components of Papyrus are exotic. Hidden browser windows, remote configuration, synthetic touch events and bulk domain registration have all appeared separately in prior schemes. The assembly is what produced traffic that outperformed the legitimate kind on every metric a buyer would check.
Timeline
- Mid-2024 - HUMAN Security's Satori team uncovers Konfety, a mobile fraud operation using counterfeit applications built on the CaramelAds SDK
- June 25, 2025 - DoubleVerify discloses ShadowBot, which spoofed more than 35 million mobile devices at an estimated cost of $2.5 million
- September 25, 2025 - DoubleVerify reports a surge in AI-powered fraudulent mobile applications mimicking legitimate games
- November 2025 - The MRC and IAB issue final attention measurement guidelines
- March 4, 2026 - DoubleVerify's Fraud Lab publishes the AutoBait investigation into a 200-plus domain made-for-advertising network
- March 26, 2026 - IAS and Mastercard link media quality signals to purchase data, citing 246 percent higher sales lift for high-attention impressions
- June 2026 - IAS and Stellantis publish attention research spanning 13 billion impressions across 19 countries
- June 10, 2026 - AppsFlyer finds organic traffic carries the majority of mobile install fraud
- July 2026 - The 21st edition of the IAS Media Quality Report records four times higher made-for-advertising rates on mobile web display
- July 11, 2026 - HUMAN Security disrupts NewsJunkie, a CTV spoofing scheme reaching two billion bid requests daily
- July 13, 2026 - DoubleVerify Engineering publishes the AfterCall analysis on Android applications serving ads after calls
- July 28, 2026 - TAG, the ANA and Fiducia size AI-generated content in programmatic spend, finding premium grades awarded about 70 percent of the time
- July 29, 2026 - DoubleVerify reports fraud and invalid traffic rates down 41 percent in North America and 45 percent in EMEA
- August 6, 2026 - IAS Threat Lab publishes the Papyrus report and an indicator list of 812 associated domains
Related PPC Land coverage
- DoubleVerify finds dozens of Android apps a month showing ads after calls - Reporting on the AfterCall analysis of Android applications that display advertisements immediately after phone calls end.
- HUMAN Security kills NewsJunkie CTV fraud scheme hitting 2 billion bids daily - Coverage of a July 2026 connected television device-spoofing operation disrupted by the Satori research team.
- Massive Mobile Ad Fraud Operation Konfety Uncovered by HUMAN's Satori Team - The 2024 mobile scheme built on counterfeit applications and an exploited advertising SDK.
- DoubleVerify uncovers $2.5M ShadowBot fraud targeting mobile and CTV - A 2025 device-spoofing operation that researchers described as containing amateur-level automation errors.
- DoubleVerify exposes AutoBait, an AI slop network costing advertisers millions - Investigation into more than 200 made-for-advertising domains generating clickbait with large language models.
- MRC and IAB release attention measurement guidelines for advertisers - The November 2025 standards governing how attention metrics are defined and compared across vendors.
- Stellantis and IAS built one of advertising's largest attention datasets - Case study covering 13 billion impressions across 19 countries and the use of attention as a planning metric.
- Advertisers face 4 times higher MFA rate on mobile web display, IAS finds - The 21st edition of the IAS Media Quality Report and its mobile inventory quality findings.
- DoubleVerify: ad fraud drops 41% in North America, 45% in EMEA - Aggregate violation rate declines reported days before the Papyrus disclosure.
- AI slop wins premium grades 70% of the time, TAG and ANA analysis finds - Statistical sizing of AI-generated content in programmatic spend and how quality systems grade it.
- Organic traffic is now mobile advertising's biggest fraud blind spot - AppsFlyer analysis across 246,000 applications on where mobile install fraud concentrates.
Summary
Who: Integral Ad Science, through its Threat Lab, identified and named the scheme. The research is credited to the IAS Team with no individual researcher named. The affected parties are advertisers and agencies buying mobile in-app and open web inventory without invalid traffic filtering, plus the readers whose devices carried the hidden activity.
What: Papyrus, a mobile advertising fraud operation running inside novel-reading applications. The apps open concealed browser windows behind the reading interface, load pages supplied by command-and-control infrastructure, and execute synthetic clicks and scrolls on them. IAS associated more than 800 domains and nearly 8,000 host values with the scheme, published an indicator list of 812 domains, and measured Papyrus traffic at nearly 25 times the click success rate, roughly four times the eCPM and about 13 percent higher attention scores than non-Papyrus traffic.
When: IAS published the research on August 6, 2026. The company estimates the scheme may have generated close to $1 million per month at its peak, without specifying when that peak occurred or over what period the analysis ran.
Where: Across mobile applications and a network of web destinations composed largely of gaming, blog, news-style and AI-generated content domains. IAS did not name the operating system or app stores involved, stating that hidden browser fraud is not limited to a single mobile environment.
Why: Long reading sessions provide extended windows during which background browser activity can run undetected, converting genuine user attention on one surface into monetizable traffic on another. The commercial significance is that the fabricated interactions did not simply mimic valid traffic but outperformed it on click rate, eCPM and attention scoring, placing the distortion inside the optimization and measurement systems buyers use to allocate budget.
Discussion