A large headless-browser operation named PaperPhone is demonstrating why IP reputation and location blocks are no longer enough to separate automated traffic from real users. During a two-week observation period, researchers linked the network to 75,000 IP addresses across 230 network blocks and 43 countries.
The activity was characterized as large-scale scraping rather than a confirmed malware infection or data breach. No specific victims, stolen datasets or financial losses were identified. Even so, the infrastructure’s size and its ability to imitate mobile visitors show how operators can overwhelm defenses that treat every address or user-agent string independently.
A global footprint that does not add up
CrowdSec researchers began identifying the cluster after a detection update on August 31 and published their findings on September 29. The apparent geography initially suggested a highly distributed population of devices. Closer examination showed that traffic peaks from distant countries moved together despite major time-zone differences.
Requests attributed to Japan and the United States rose at closely related times, as did traffic supposedly originating in Australia and Canada. That synchronized behavior points to central coordination rather than independent human browsing. Registration, management and claimed location data for some ranges also indicated different parts of the world, creating a misleading map of the network.
The 230 blocks were largely /24 ranges spread over 80 networks, with many associated with data-center infrastructure rather than household connections. More than a fifth of the cluster used M247 as a transit provider even though the listed blocks did not belong to that company. Researchers cautioned that this relationship does not establish who operated the system.
Fabricated phones share the same fingerprint
PaperPhone rotated through 13 claimed device identities, including Android handsets and multiple iOS versions. Yet every observed bot reported a viewport of 375 by 812 pixels. That dimension resembles an iPhone 10 or 11 display area and conflicts with the varied devices presented in the browser headers.
The sessions also exposed Google SwiftShader in their WebGL renderer information. SwiftShader performs graphics work in software and is commonly seen in environments without hardware acceleration. Its presence is difficult to reconcile with the recent flagship phones claimed by the traffic, including Pixel 9 and Samsung Galaxy S25 Ultra devices.
Taken together, identical screen dimensions, software rendering and implausibly varied device labels reveal Chrome-based automation rather than thousands of genuine phones. The browsers changed their external identity, but the underlying execution environment remained consistent.
Rotation weakens one-address-at-a-time blocking
Researchers saw addresses change after repeated challenge failures led to bans. That cycling helps explain why the detected population grew: expanding telemetry and operator rotation both contributed to the count. Early sightings should therefore not be treated as the network’s creation date.
Some address blocks were used at or near full capacity during scraping. Blocking one IP at a time allows the operator to return from an adjacent address, while country-level restrictions can affect legitimate users without stopping infrastructure whose location labels are unreliable.
Defenses need correlated signals
Organizations facing similar automation should combine network, timing and browser evidence:
- Group behavior by address range and network ownership instead of evaluating isolated IPs only.
- Compare claimed device models with viewport dimensions, WebGL renderers and hardware features.
- Track synchronized request patterns across regions that should have different daily activity cycles.
- Measure address rotation after challenge failures and bans.
- Apply rate limits and behavior-based challenges while monitoring false positives for real users.
PaperPhone’s central lesson is that apparent diversity is easy to manufacture. A rotating address, plausible mobile user agent and foreign geolocation may all describe the same automated browser farm. Defenders gain a more reliable picture when they correlate those claims with characteristics that are harder to vary consistently.
The findings also argue for keeping conclusions proportional to the evidence. The infrastructure supports coordinated scraping, but it does not by itself prove that the servers were compromised or identify the operator. Effective response should focus on observable behavior rather than unsupported attribution.
Source: Cyber Security News, based on research attributed to CrowdSec.
Leave a Reply
You must be logged in to post a comment.