PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
CrowdSec says the PaperPhone headless-browser network scraped the web from 75,000 IPs across 43 countries.
CrowdSec’s September 29 report describes PaperPhone, a headless-browser network seen over two weeks using about 75,000 IP addresses in 230 blocks across 43 countries for large-scale web scraping. Traffic peaks from distant countries rose together, and many ranges were known data-center space rather than residential proxies; more than 20% transited via M247. Bots cycled 13 claimed Android and iOS identities but all reported a 375×812 viewport and exposed Google SwiftShader, consistent with unaccelerated Chrome automation. CrowdSec did not identify compromised servers, specific victims, stolen data, or financial losses.
- CrowdSec tracked 75,000 IPs in 230 blocks across 43 countries.
- Synchronized peaks and data-center ranges point to central coordination, not real users.
- All bots used a 375×812 viewport and Google’s SwiftShader despite 13 claimed phones.
- Over 20% of the cluster transited via M247, and addresses rotated after bans.
- Researchers describe large-scale scraping, not confirmed compromise or data theft.
Full article842 words · extracted from cybersecuritynews.com · click to collapse
PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single obvious source.
Instead, it spreads activity across thousands of addresses while repeatedly presenting fabricated phone and browser identities. The operation exposes weaknesses in simple IP-based defenses.
Websites facing this traffic may see requests apparently arriving from dozens of countries, making location blocks and one-off address bans far less useful. The network was observed during a two-week period, although its infrastructure may have existed earlier.
CrowdSec analysts identified PaperPhone after collecting bot signals following an August 31 detection update. Their September 29 report detailed the findings.
CrowdSec said in a report shared with Cyber Security News (CSN) that the activity involved 75,000 IP addresses across 230 IP blocks and 43 countries. The report describes large-scale scraping, not a confirmed malware infection or data breach.
Its findings build on the distinction explained in browser fingerprinting testing guidance, where browser characteristics reveal differences between automated environments and real devices. CrowdSec did not identify specific victims, stolen datasets, or financial losses.
PaperPhone Headless Browser Network
The apparent global footprint does not reflect worldwide users or devices. Researchers found that request peaks from distant countries moved together despite major time-zone gaps.
Traffic attributed to Japan and the United States rose at closely related times, as did traffic presented as coming from Australia and Canada.
That timing suggests central coordination, not independent browsing. The 230 blocks were mostly /24 ranges across 80 networks. Many were already recognized as data-center infrastructure, rather than residential proxies.
Unlike the SystemBC proxy botnet operation, this investigation does not establish that servers were compromised. Address ownership and geolocation records also raised questions.
A range could have registration, management, and claimed location details that point to different regions. Adjacent ranges were presented as being in cities from Brussels to Bangkok, Tokyo, and Paris, creating an artificial geographic picture.
More than 20% of the observed cluster used M247 as its transit provider, despite none of the listed blocks belonging to that provider. Many blocks were used to their full capacity during scraping.
Defenders should assess address-range behavior rather than treat every IP as unrelated. This transit relationship does not establish operator attribution. Researchers also observed addresses rotating after repeated challenge failures led to bans.
This behavior helps explain why the number of detected addresses grew over time: both expanding telemetry and address cycling affected the picture. The earliest sightings therefore mark increased visibility, not necessarily the beginning of the operation.
Fabricated Mobile Identities
PaperPhone cycled through 13 claimed device identities, including five Android devices and seven iOS variants. Yet every observed bot reported the same 375×812 viewport.
That size matches an iPhone 10 or 11 display area, not the varied handsets the network claimed to represent. The browsers also exposed Google SwiftShader through the WebGL renderer field, a software graphics renderer generally associated with systems lacking hardware acceleration.
That is difficult to reconcile with the recent Android devices named in the traffic, including Pixel 9 and Samsung Galaxy S25 Ultra models, or with claimed iOS 14 and iOS 15 sessions.
These contradictions show why country, user-agent, or IP reputation alone cannot establish legitimacy. Organizations should correlate request volume, address rotation, browser viewport, graphics behavior, device claims, and challenge failures.
The importance of these signals also appears in macOS browser fingerprinting evasions, where attackers inspect visitors to hide malicious content.
SwiftShader uses the processor to draw graphics rather than a dedicated graphics chip. CrowdSec interpreted the combination as evidence of Chrome-based automation without hardware acceleration, rather than genuine sessions from the phones advertised in the browser identities.
The findings underline the limits of geographic blocking and individual address bans. Looking at request timing alongside browser characteristics provides a fuller picture than location labels alone.
For this cluster, synchronized activity, identical display dimensions, software rendering, and concentrated address ownership exposed the automation beneath its supposedly diverse mobile visitors.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.