IAS Threat Lab reported that a mobile ad fraud operation dubbed Papyrus was embedded in Android novel-reading apps, where it secretly opened hidden browser views and generated ad traffic while users read serialized fiction. The scheme relied on a command-and-control orchestration layer called BootNova, which fetched remote configuration and instructed the apps which destinations to load, how many concealed WebViews to spawn, and how those views should behave.
Researchers said Papyrus used components including WebViewOut, CWebViewPlugin, and an obfuscation module labeled RsaUtils to automate page loads, clicks, scrolling, ad closing, consent handling, and touch-copying without users' knowledge. IAS linked the operation to more than 800 domains and nearly 8,000 unique hostnames, and estimated the activity generated close to $1 million per month at its peak; the fraudulent traffic also showed unusually high click success rates, eCPM, and attention scores, potentially skewing advertisers' campaign optimization and budget decisions toward invalid supply.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 6, 2026, IAS Threat Lab published a technical analysis of the Papyrus mobile ad fraud scheme. The report linked the operation to more than 800 domains and about 8,000 unique host values, and estimated it generated nearly $1 million per month at peak activity.
IAS Threat Lab identified a mobile ad fraud operation dubbed Papyrus embedded in novel-reading Android apps. The scheme uses hidden WebViews, remote command-and-control via BootNova, and automated clicks and scrolling to generate fraudulent ad traffic and distort advertiser metrics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
zimperium.com
Open sourcecyberveille.ch
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcehelpnetsecurity.com
Open sourceintegralads.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.