Papyrus is a sophisticated ad fraud operation operating through apps designed for serial fiction reading on smartphones This article explores papyrus traffic users. . This tactic mimics legitimate mobile experiences, allowing operators time to engage in concealed browser activity.

IAS discovered over 800 associated domains and nearly 8,000 unique host values as part of their investigation into this fraud scheme. After launching an app, it communicates with remote infrastructure to determine what tasks should be executed, including selecting destinations for loading content, managing browser view counts, and defining interaction rules. It captures tap coordinates, copies touches into the hidden browser, scrolls through pages, closes ads, and handles consent prompts automatically.

Additionally, they observed a module labeled RsaUtils that uses Base64 encoding and character shifting to obscure the hardcoded command-and-control address and server messages. IAS identified "movement recipes" that can dictate click locations, scrolling ranges, delays, navigation choices, and ad-close coordinates, with probability controls used to alter the patterns. In the research, Papyrus traffic exhibited a nearly 25-times higher click success rate, approximately four times greater eCPM (effective cost per thousand impressions), and about 13 percent more attention scores compared to non-Papyrus traffic.

For users, the practical advice is simpler: install apps from trusted sources, review permissions, and remove those that show unexplained battery drain, data use, or intrusive behavior.