The worst thing about the ad fraud scheme IAS published this week is not that it stole money. It is that the stolen traffic looked better than the real traffic.
IAS Threat Lab has named a mobile operation called Papyrus, running through a cluster of novel-reading apps. Someone installs an app to read romance or fantasy chapters. While they read, the app opens browser windows they never see, loads websites into them, and clicks and scrolls through those pages on its own.
How it works
The apps are built around an orchestration layer IAS calls BootNova. When the app runs, it contacts a remote command server that decides whether the hidden activity runs at all, in which countries, which URLs to load, how many hidden browser windows to open, and how those windows should behave on the page. Those instructions go to workers that open the windows and keep them positioned behind the visible reading interface.
Two details are worth pausing on. First, some of the automation is delivered from the operator’s servers at runtime, so the behaviour can change without an app update. IAS observed server-delivered JavaScript that mutes media elements and automatically clicks consent dialogs. Second, the apps pass real taps from the visible screen into the hidden window, so a person turning a page can register as a click on an ad they never saw.
The scheme also varies itself on purpose, using what IAS describes as movement recipes with defined click coordinates, scroll ranges and delays, selected through probability gates so the pattern does not repeat in an obvious way.
Novel-reading apps were not a random choice either. People open them and stay, unlike a utility app checked for eight seconds and closed. Reading time is time available for hidden monetisation.
The numbers
IAS linked Papyrus to more than 800 domains and nearly 8,000 unique hostnames, mostly gaming sites, blogs, news-styled pages and AI-generated content built to receive traffic rather than serve a reader. At its peak the firm estimates the operation was earning close to a million dollars a month.
Then the part that should bother anyone running automated bidding. According to the IAS Threat Lab findings on Papyrus:
- Click success rate roughly 25 times higher than non-Papyrus traffic
- eCPM around four times higher
- Attention scores 13 percent above normal
Fake traffic that underperforms gets optimised away on its own. Fake traffic that outperforms gets more budget.
What this means if you run a small ad account
Picture a homeware brand spending £6,000 a month with a smart bidding strategy running across display and app inventory. The algorithm’s job is to find cheap clicks that look engaged. Papyrus supply is cheap clicks that look engaged. Nothing in the system flags it. The campaign appears to be improving while orders stay flat, and the natural response, more budget into the best-performing placements, is precisely the wrong move.
The check is not complicated:
- Pull the placement report for the last 90 days and sort by click-through rate descending. Anything with an implausible click rate and no conversions is worth excluding on sight.
- Look specifically at mobile app inventory. If you cannot name the apps, exclude the category for a fortnight and watch what happens to conversions. Usually nothing happens, which is the answer.
- Compare the trend in clicks against the trend in orders. When the two lines separate, the click number is the one lying.
- If your reporting includes attention or viewability scores, stop treating a high score as proof of quality. This scheme produced above-average attention scores deliberately.
Where this advice stops
Excluding all app inventory is a blunt instrument and it will cost some brands real reach, particularly in gaming and entertainment. If app placements are genuinely converting for you, the answer is a tighter allowlist, not a shutdown.
It is also worth being honest about scale. A campaign spending a few hundred pounds a month is not the target here and probably cannot detect this pattern in its own data. The exclusions are still cheap to apply, but the real defence for a small advertiser is measuring outcomes rather than clicks, which would be true even if Papyrus had never existed.
And specific schemes get shut down. This one has been exposed and its supply cut off. The technique will reappear under another name in another app category, so the durable fix is a reporting habit rather than an exclusion list you write once and forget.
The thing to take away
Most fraud advice assumes bad traffic looks bad. This traffic was engineered to look excellent, because the buying systems it targeted reward whatever looks excellent. If your optimisation loop cannot tell a good signal from a manufactured one, the loop will find the manufactured one and spend more on it.
That is not a fraud problem you solve with a tool. It is a measurement problem you solve by deciding, before the campaign starts, which number counts as success, and then refusing to let clicks be it.
