PaperPhone Scraping Cluster Used 75,000 IP Addresses
Security analysts identified a sophisticated global botnet that simulated mobile traffic across 43 countries.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you trust that online services are effectively blocking sophisticated bot traffic from your experience?
Security analysts have identified a massive botnet, dubbed PaperPhone, which leveraged 75,000 IP addresses to mimic authentic mobile user behavior. The infrastructure operated across 43 countries, using 230 distinct IP address blocks to bypass detection.
Why it matters
This operation highlights the growing sophistication of large-scale scraping infrastructure designed to simulate distributed mobile user traffic. By maintaining a presence in dozens of countries, the cluster effectively evades standard geolocation and rate-limiting security controls.
The cluster utilized 75,000 IP addresses drawn from 230 different address blocks. This architecture spanned 43 countries to maintain a global footprint that mimics genuine distributed mobile traffic.
The players
PaperPhone
A centrally coordinated scraping cluster that simulates mobile user traffic through a massive global network of proxy IP addresses.
The details
The PaperPhone cluster used browser-fingerprinting—a technique that collects device-specific data to create a unique identifier for a browser—to mask bot traffic as legitimate user activity. Analysts also observed the use of network-analysis signals to blend automated traffic patterns with real-world connection protocols. By distributing the infrastructure across 43 countries, the operation successfully mimics the fragmented nature of a global mobile user base.
Timeline
September 30, 2026: Report publication regarding PaperPhone cluster discovery.
The Tech Race
The PaperPhone operation represents a significant expansion in the scale of automated scraping networks documented in recent security reports. It follows the established trend of using residential proxy networks to outpace traditional, single-source anti-bot detection systems.
Website administrators and security engineers should audit their rate-limiting and geolocation filters to account for traffic originating from high-volume, global proxy pools. While individual users are not directly affected, the increased prevalence of such bots may trigger more aggressive CAPTCHA challenges or blocking policies on major platforms.
The takeaway
The PaperPhone cluster serves as a warning that standard IP-based rate limiting is insufficient against globally distributed, high-volume automation. Security teams should monitor for large-scale, coordinated shifts in traffic patterns that utilize diverse address blocks across multiple international regions.
Further reading
For more on the current state of bot detection, visit our Cybersecurity section.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you trust that online services are effectively blocking sophisticated bot traffic from your experience?







