PaperPhone Scraping Cluster Has Used 75,000 IPs

Security analysts uncovered a massive bot network that simulated mobile traffic across 43 different countries.

Updated on Sept. 30, 2026 in Cybersecurity

PaperPhone Scraping Cluster Has Used 75,000 IPs

Live Poll

Do you trust that online services are effectively blocking sophisticated bot traffic from your experience?

Security analysts have identified a large-scale scraping cluster named PaperPhone that utilized 75,000 unique IP addresses to mimic authentic mobile user traffic. The sophisticated network operated across 43 countries to disguise its activity.

Why it matters

The discovery highlights the increasing complexity of bot operations that employ distributed infrastructure to bypass security filters. By mimicking human behavior on a massive scale, such clusters can harvest data while remaining undetected by standard monitoring tools.

The PaperPhone cluster leveraged 230 distinct IP address blocks to distribute its operations globally. It specifically used browser-fingerprinting and network-analysis signals to blend in with legitimate mobile user patterns.

The players

PaperPhone

This is a sophisticated, centrally coordinated scraping cluster that simulated mobile traffic using tens of thousands of IP addresses.

The details

The bot network maintained infrastructure across 43 countries to create the appearance of a distributed, organic mobile user base. By integrating advanced network signals, the operators effectively shielded their high-volume scraping activities from routine cybersecurity detection systems.

Timeline

  1. September 30, 2026: Analysts published a report detailing the discovery of the PaperPhone cluster.

The Tech Race

This cluster represents an evolution in the ongoing arms race between automated data scrapers and cybersecurity defense systems. By scaling to 75,000 IP addresses, the operation demonstrates a shift away from simple bot scripts toward complex, distributed network infrastructures.

Large-scale scraping operations like PaperPhone can lead to degraded service for legitimate users as servers struggle to handle bot traffic. Additionally, the sophisticated fingerprinting techniques used by such bots complicate privacy and data security measures for standard mobile browsers.

The takeaway

Large bot networks are increasingly indistinguishable from human traffic due to their global, multi-country infrastructure. Users should remain cautious of privacy settings and utilize security-focused browser extensions to mitigate the risk of browser-fingerprinting.

Further reading

Learn more about the latest threats in the Cybersecurity section.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you trust that online services are effectively blocking sophisticated bot traffic from your experience?