Papyrus, a mobile ad fraud operation, cleverly disguises itself within apps designed for serialized fiction reading. While users are absorbed in stories, these apps secretly open web pages in the background, generating artificial traffic.
Exploiting Reading Sessions for Fraud
The Papyrus scheme capitalizes on lengthy reading sessions, allowing time for covert browser activities to occur. This mirrors other hidden browser fraud models where legitimate mobile interfaces hide automated ad interactions.
Investigators at IAS discovered Papyrus within several novel-reading apps, all controlled remotely by command-and-control servers. These apps, while appearing normal, execute actions such as loading monetized content, simulating clicks, and mimicking user scrolling.
Significant Financial and Performance Impact
The ramifications of Papyrus go beyond a few unnoticed page loads. IAS identified over 800 domains and nearly 8,000 unique host values linked to the operation, estimating its peak impact at nearly $1 million monthly. Such activities distort performance data crucial for advertisers in budget allocation.
An integral component of Papyrus is BootNova, an orchestration layer that communicates with remote infrastructure to execute fraudulent activities. This includes opening hidden browser views, manipulating location targeting, and adjusting interaction rules without app updates.
Misleading Advertisers with Fabricated Engagement
Papyrus doesn’t just inflate web traffic; it manufactures engagement signals like clicks and scrolls, which are typically indicators of user interest. IAS observed that this activity led to a 25-fold increase in click success rates and significantly higher attention metrics compared to genuine traffic.
The deceptive appearance of high engagement can mislead campaign systems into optimizing for seemingly better-performing traffic, ultimately diverting spending and impacting future ad delivery.
Protecting Against Mobile Ad Fraud
To combat fraud like Papyrus, advertisers need to scrutinize anomalies in click rates and validate traffic sources. Implementing invalid-traffic controls to filter out known fraudulent sources is crucial.
For users, vigilance is key: install apps from reputable sources, monitor app permissions, and uninstall apps exhibiting unusual behavior like excessive battery drain or data usage. The lesson from Papyrus underscores the need to question seemingly benign app experiences that may mask fraudulent activities.
