CrowdSec Details PaperPhone Cluster Using 75,000 IPs
CrowdSec says PaperPhone used about 75,000 data-center IPs across 43 countries to scrape the web while impersonating mobile browsers.
CrowdSec’s September 29 analysis, covered on September 30, describes PaperPhone as a headless-browser network used for large-scale web scraping over about two weeks. The cluster used roughly 75,000 IP addresses in 230 blocks across 43 countries, with request bursts synchronized in UTC even among regions many time zones apart. Clients rotated 13 claimed Android and iOS identities, including Pixel 9 and Galaxy S25 Ultra, yet every client reported a 375 by 812 viewport and Google SwiftShader, which CrowdSec associated with unaccelerated Chrome automation. M247 transited more than 20 percent of the traffic but was not the operator; most ranges were already known data-center space rather than confirmed residential proxies, and registry, WHOIS, and geolocation records conflicted. Addresses rotated after bans. CrowdSec did not name the operator or targets and reported no confirmed compromise, stolen data, or financial losses. The two accounts agree on scale, coordination, and technical fingerprints.
- CrowdSec’s September 29 report describes PaperPhone, a headless-browser scraping cluster observed over about two weeks.
- It used roughly 75,000 IP addresses in 230 blocks across 43 countries.
- Request bursts were synchronized in UTC, including across regions many time zones apart, pointing to one operator rather than local users.
- Clients rotated 13 claimed Android and iOS identities, including Pixel 9 and Galaxy S25 Ultra, but all reported a 375 by 812 viewport and Google SwiftShader, consistent with unaccelerated Chrome automation.
- M247 provided transit for more than 20 percent of the traffic but was not identified as the operator; most ranges were known data-center infrastructure, not confirmed residential proxies.
- Registry, WHOIS, and geolocation records conflicted, and addresses rotated after bans.
- CrowdSec did not name the operator or targets and did not identify compromised servers, specific victims, stolen data, or financial losses.
Coverage timelineoldest first · each row is one article
- · 9h agoPaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
GBHackers· 46
CrowdSec says the PaperPhone scraper used 75,000 IPs in 43 countries to impersonate mobile users.
- · 6h agoPaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
Cyber Security News· 64
CrowdSec says the PaperPhone headless-browser network scraped the web from 75,000 IPs across 43 countries.