PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
CrowdSec says the PaperPhone scraper used 75,000 IPs in 43 countries to impersonate mobile users.
CrowdSec analyzed PaperPhone, a scraping cluster that used roughly 75,000 IP addresses in 230 blocks across 43 countries to look like tens of thousands of mobile users. Request bursts were synchronized in UTC, including across regions many time zones apart, and registry, WHOIS, and geolocation records conflicted. Clients rotated 13 claimed Android and iOS identities, including Pixel 9 and Galaxy S25 Ultra, but all reported a 375 by 812 viewport and Google SwiftShader. M247 provided transit for more than 20 percent of the traffic. CrowdSec did not name the operator or targets and said most ranges were already known data-center infrastructure.
- PaperPhone used about 75,000 IPs in 230 blocks across 43 countries.
- UTC-synchronized bursts indicated one operator rather than local users.
- Every client used a 375 by 812 viewport and SwiftShader WebGL.
- M247 transited over 20 percent of traffic but was not the operator.
- Most ranges were data-center space, not confirmed residential proxies.
Full article772 words · extracted from gbhackers.com · click to collapse
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users across dozens of countries.
The operation used roughly 75,000 IP addresses across 230 address blocks in 43 countries. However, browser-fingerprinting and network-analysis signals pointed to a centrally coordinated infrastructure rather than a genuinely global population of mobile users.
The discovery followed the August 31 release of CrowdSec 1.8.0, which introduced an alpha bot-detection capability to its Web Application Firewall.
While CrowdSec’s Security Engine and WAF traditionally emphasized IP behavior such as scanning, brute-force attempts, and abusive HTTP activity the new feature collected client-side signals that helped researchers assess what was running behind an address.
Production deployments generated enough telemetry to link traffic that initially appeared unrelated.
That distribution could frustrate conventional geographic blocking policies, which are often ineffective once an actor can source traffic from numerous regions.
However, the traffic did not behave like independent users in those countries. CrowdSec observed activity peaks at implausible local times, including around 05:00 in Japan, 01:00 in India, 03:00 in Mexico, and 02:00 in Lithuania.
More significantly, request bursts from countries separated by many time zones were strongly synchronized.
Infrastructure represented as Japanese and U.S. traffic, for example, showed correlated spikes despite their 13-hour difference; the same pattern appeared in Australian and Canadian traffic
Viewed in Coordinated Universal Time rather than local time, the patterns made considerably more sense.
The apparent country diversity was therefore a routing and registration façade, not evidence of a distributed human audience.
The PaperPhone cluster was spread across 230 mostly /24-sized blocks, creating enough fragmentation to complicate reputation-based blocking.

CrowdSec Researchers said that, PaperPhone appeared geographically diverse: requests originated from IP ranges geolocated across 43 countries and nearly 80 networks.
PaperPhone Cluster
CrowdSec found inconsistencies between the regional registry that issued address space, the registry records governing it, the organization associated with the range, and the geographic location attributed to it.
One cited example involved 103.216.1.0/24: address space issued through APNIC but registered through RIPE following an inter-regional transfer, associated with a Lithuanian registrant while WHOIS data claimed a U.S. location.
Other adjacent ranges were geolocated to entirely different cities and countries, including Brussels, Bangkok, Tokyo, and Paris.

The analysis indicates that a smaller set of entities controlled substantial portions of the infrastructure.
M247 was not identified as the owner of the PaperPhone IP blocks, but CrowdSec found it provided transit for more than 20% of the cluster’s traffic.
That transit relationship is an infrastructure observation, not evidence that M247 operated the scraping campaign.
PaperPhone rotated through 13 claimed device identities, including five Android models and seven iOS variants.
The identities included recent devices such as the Google Pixel 9 and Samsung Galaxy S25 Ultra, yet the fingerprinting data repeatedly contradicted those claims.
Every observed client presented the same 375×812 viewport a value associated with certain iPhone form factors regardless of the supposed Android or iOS model.
All clients also reported Google SwiftShader as their unmasked WebGL renderer. SwiftShader is a CPU-based software implementation used as a graphics-driver substitute, not a normal signal for modern flagship mobile hardware with GPU acceleration.
The mismatch was even more conspicuous for claimed iOS 14 and iOS 15 clients. iOS browsers use Apple’s WebKit engine, making a Chrome-style SwiftShader WebGL signal fundamentally inconsistent with the reported mobile identity.
These combined traits suggest automated Chrome-based or headless environments impersonating mobile browsers rather than genuine handsets.
PaperPhone demonstrates why IP-based controls alone cannot reliably identify advanced scraping operations.
Operators can rotate addresses, distribute activity across cloud ranges, manipulate geolocation metadata, and cycle user-agent strings at scale.
CrowdSec said most PaperPhone ranges were already identified as data-center infrastructure, indicating this was not a confirmed residential-proxy operation.
Defenders should correlate network reputation with browser fingerprints, JavaScript challenge outcomes, viewport consistency, WebGL characteristics, timing patterns, and ASN or transit-provider relationships.
CrowdSec’s bot-detection capability uses a client challenge and fingerprinting workflow to distinguish suspicious automation from legitimate users and verified crawlers.
The investigation does not publicly attribute PaperPhone to a named actor or identify its targets.
Its importance lies in the method: a single centralized scraping operation can convincingly imitate a worldwide mobile-user base until defenders compare the signals its automation cannot consistently fake.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.