IAS Threat Lab has identified Papyrus, a sophisticated mobile fraud operation that masks legitimate browsing sessions within popular novel-reading apps This article explores ebook apps aware. . This scheme transforms prolonged reading periods into deceptive sources of fraudulent web traffic, keeping users unaware of the underlying activity.

The apps appear as serialized fiction and long-form story offerings but secretly open browser components called webviews behind their visible interfaces. Papyrus poses significant concerns due to its ability to not only drive page views but also induce artificial interactions such as clicks, scrolling, consent dialogues, and other indicators that advertisers might interpret as high-value engagement. This server can decide whether to activate hidden activities, select destination URLs, control timing, set retry rules, and determine how many browser windows should be launched.

This allows individuals to read chapters inside ebook apps without being aware of website loading and advertising interactions occurring in the background. The sites include gaming, blog, news-style, and generative AI content platforms aimed at generating traffic rather than serving meaningful audiences. Papyrus employs embedded and remotely delivered JavaScript scripts that capture click coordinates, trigger synthetic touches, scroll pages, mute media, and dismiss or accept consent forms automatically.