Papyrus Ad Fraud Campaign Hides WebViews to Generate Fake Mobile Ad Traffic

Security researchers have uncovered Papyrus, a sophisticated mobile ad fraud campaign that abuses novel-reading apps to secretly generate fake advertising traffic. While users read stories, the apps open hidden WebViews in the background to simulate clicks, scrolling, and user interactions without the user's knowledge.

Papyrus Ad Fraud Campaign Hides WebViews to Generate Fake Mobile Ad TrafficPapyrus Ad Fraud Campaign Hides WebViews to Generate Fake Mobile Ad Traffic

The campaign is remotely controlled through command-and-control (C2) servers, allowing attackers to dynamically change browsing behavior, target websites, and interaction patterns. Researchers identified over 800 malicious domains and nearly 8,000 unique hosts, estimating the operation generated nearly $1 million per month in fraudulent advertising revenue while distorting marketing analytics.

Users should install apps only from trusted developers, monitor unusual battery or data usage, and remove suspicious applications. Organizations and advertisers should deploy advanced fraud detection and continuously monitor abnormal click rates, engagement metrics, and hidden browser activity to reduce advertising fraud.


Stay protected from mobile threats, malicious apps, and advanced ad fraud with NPAV Total Security Multi Device