AI Driving Rising Levels Of Manipulative Ad Fraud

Advertising industry executives are calling on Apple, Google, Microsoft and others with an app store to do more to protect brands and consumers from ad fraud, which has exploded because of artificial intelligence (AI).

Integral Ad Science's IAS Threat Lab on Thursday published a study titled The Papyrus Report, which details a cluster of reading apps that appeared to offer digital novels but once installed, used users' phones to visit websites, generate ad clicks, and create fraudulent engagement in the background, without user knowledge.

The Papyrus Report is named after the Papyrus virus. Papyrus is a sophisticated mobile ad-fraud scheme identified by Integral Ad Science that uses compromised novel-reading apps to generate fraudulent ad clicks and engagement from user devices. 

The operation spanned more than 800 domains and nearly 8,000 unique host values, creating a large-scale ad-fraud network powered by consumers rather than traditional bot traffic. 

advertisement

advertisement

The destinations were mostly gaming, blog, news-style, and generative AI-created content domains, reflecting the continued use of synthetic web properties built for monetization rather than real audiences.

The mobile scheme generated approximately $1 million per month for fraudsters, revealing a hidden economy from reading apps.

"What makes Papyrus especially concerning is that it goes beyond hidden traffic generation and actively manipulates the metrics buyers rely on," IAS wrote in a blog post. "The apps use click and scroll modules that pass user taps into hidden web views, registering clicks in the background."

The app also received instructions to scroll pages, inflating attention signals and making the traffic appear more valuable to buyers.

Papyrus traffic had a nearly 25x higher click success rate -- roughly 4x higher eCPMs, and about 13% higher attention scores than non-Papyrus traffic, making it appear more valuable than legitimate traffic, according to the report.

DoubleVerify's Fraud Lab also recently found what it calls “AfterCall” ad fraud that it took to Google to discuss.

The growing wave of AfterCall-infected apps manipulate users into granting special permission, then display ads immediately after each phone call.

The apps are difficult to identify and remove, and the company currently detects dozens of these apps monthly that are responsible for hundreds of millions of ad impressions.

DoubleVerify calls this type of advertising malware “AfterCall.” The ads appear at the end of a phone call, outside the app’s normal context. App platforms have always been fighting these out-of-context apps and have implemented different and increasingly effective protection mechanisms.

The apps trigger out-of-context ads, Gilit Saporta, vice president of product for the Fraud Lab at DoubleVerify, told MediaPost.

The AfterCall virus tricks users into granting permission to serve out-of-context ads, making it more difficult for the user to use their device.

Saporta suggests people look at their phones and delete any app they do not recognize, ones they did not download from any app store.

“Sometimes they will make the logo of the app invisible, making it more difficult to find, Saporta said.

Sometimes it will be a legitimate app like a calculator, explained Nisim Tal, CTO of DoubleVerify.

“The malware hidden in an app on the person’s phone monitors the use of the phone, whether the user initiates the call or someone else calls the phone’s user,” Tal said. “It’s a high attention moment when the call ends, and this is why the ad comes after the phone call disconnects. Disconnecting the phone call triggers the ad.”

Tal believes it is the responsibility of the app stores to check these apps, not the responsibility of the consumer who downloads apps from reportable stores.

“We are working with vendors and publishers to inform them after these apps,” he said. “This week we have a call with the Google Play store to discuss these finding. We plan to share what we see and how we found it.”

Next story loading loading..