HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Mobile Ad Fraud Scheme “Papyrus” Hijacks Novel‑Reading Apps to Generate Fake Ad Traffic

IAS Threat Lab discovered that the Papyrus campaign embeds a hidden orchestration layer in novel‑reading apps, launching invisible browsers that click and scroll ads. The activity is driven by a remote C2 server and can be re‑programmed without app updates, exposing advertisers and app publishers to fraudulent revenue streams and highlighting the need for robust third‑party risk controls.

LiveThreat™ Intelligence · 📅 August 06, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Mobile Ad Fraud Scheme “Papyrus” Hijacks Novel‑Reading Apps to Generate Fake Ad Traffic

What Happened — Researchers at IAS Threat Lab uncovered a new mobile ad‑fraud campaign, dubbed Papyrus, that embeds a hidden orchestration layer (BootNova) inside popular novel‑reading apps. The layer silently launches hidden WebView browsers, clicks and scrolls ads, and even mutes consent dialogs, all while the user reads a story. The malicious activity is driven by a command‑and‑control server that can be re‑programmed without an app update.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the risk of third‑party mobile SDKs and bundled code that can subvert user devices and generate fraudulent revenue – a scenario SOC 2 vendor‑management controls are designed to detect and document.
  • Continuous monitoring of third‑party app behavior provides audit‑ready evidence that your organization performed due‑diligence on the software supply chain.
  • Aligns with Verisq’s Vendor Risk capability, which automates the collection of security attestations and real‑time risk scores for app providers.

Who Is Affected – Mobile app publishers, ad‑tech platforms, advertisers, and any organization that integrates third‑party SDKs into consumer‑facing applications (tech/SaaS, media, advertising).

Recommended Actions

  • Conduct a vendor‑risk assessment of all third‑party SDKs and libraries used in your mobile apps.
  • Deploy runtime monitoring to detect hidden WebView activity or unexpected network traffic from your apps.
  • Update contracts to require security attestations, code‑review evidence, and continuous compliance reporting from SDK providers.

Source: Help Net Security

Technical Notes – The scheme uses a custom orchestration layer (BootNova) that contacts a C2 server, decodes the address with a Base64 + character‑shift cipher, and spawns “WebViewOut” workers to drive hidden browsers. JavaScript delivered at runtime can mute media, auto‑click consent dialogs, and replay user taps as synthetic clicks. No CVE is disclosed; the threat is a malicious code injection via third‑party app distribution. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →