Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Citrix ADC, Gateway Zero-Days Under Active Attack
September 30, 2026
Google Chrome Update Patches 32 Security Flaws Across Platforms
September 30, 2026
Cloudflare Launches Post-Quantum CA with Merkle Tree Certificates for Faster TLS
September 30, 2026
Home/Threats/PaperPhone Headless Browser Network Impersonates 75,000 Mobile Devices Across 43 Countries
Threats

PaperPhone Headless Browser Network Impersonates 75,000 Mobile Devices Across 43 Countries

Key Takeaways A sophisticated headless browser network, dubbed “PaperPhone,” has been discovered impersonating over 75,000 mobile devices across 43 countries. The network leverages...

David kimber
David kimber
September 30, 2026 5 Min Read
2 0

Key Takeaways

  • A sophisticated headless browser network, dubbed “PaperPhone,” has been discovered impersonating over 75,000 mobile devices across 43 countries.
  • The network leverages thousands of IP addresses and fabricated mobile browser identities to conduct automated web requests, making it difficult to detect with traditional IP-based defenses.
  • Analysis by CrowdSec revealed inconsistencies in geographical claims, synchronized request patterns across time zones, and uniform browser characteristics despite diverse device claims.
  • This operation highlights the need for advanced bot detection strategies that go beyond simple IP blocking and user-agent analysis, focusing on behavioral and fingerprinting discrepancies.

A new, highly elusive headless browser network, dubbed “PaperPhone,” has been identified actively impersonating approximately 75,000 mobile devices across 43 countries. This sophisticated operation is designed to make automated web requests appear as legitimate mobile traffic, effectively bypassing conventional IP-based security measures.

Table Of Content

  • Key Takeaways
  • PaperPhone Headless Browser Network
  • Fabricated Mobile Identities
  • What You Should Do

Unlike botnets that rely on a single, easily identifiable source, PaperPhone distributes its malicious activity across thousands of IP addresses. It continuously rotates fabricated phone and browser identities, presenting a significant challenge to organizations attempting to identify and block automated traffic. The network’s ability to appear to originate from dozens of countries renders straightforward geographical blocking or single-address bans largely ineffective. While observed over a two-week period, researchers suggest the underlying infrastructure may have been operational for an extended duration before detection.

Security researchers at CrowdSec uncovered the PaperPhone network following an August 31 update to their bot detection systems. Their comprehensive report, released on September 29, detailed the findings. CrowdSec said in a report shared with Cyber Security News (CSN) that the activity encompassed 75,000 IP addresses, distributed across 230 IP blocks, originating from 43 different countries. The report primarily focuses on large-scale web scraping activities and does not indicate a confirmed malware infection or data breach.

The findings underscore the limitations of relying solely on browser fingerprinting guidance, which distinguishes between automated and real device environments based on browser characteristics. CrowdSec’s investigation did not pinpoint specific victims, identify stolen datasets, or confirm any financial losses directly attributable to PaperPhone.

PaperPhone Headless Browser Network

Despite its seemingly global footprint, the PaperPhone network does not represent a genuine worldwide distribution of users or devices. Researchers observed synchronized request peaks from geographically disparate countries, occurring simultaneously despite significant time-zone differences. For instance, traffic attributed to Japan and the United States, as well as Australia and Canada, exhibited closely related timing in their activity spikes. This synchronized behavior strongly suggests centralized coordination rather than independent browsing patterns.

The 230 IP blocks identified were predominantly /24 ranges, spanning across 80 distinct networks. Many of these ranges were already known to belong to data center infrastructure providers, rather than residential proxy services. Unlike operations such as the SystemBC proxy botnet, this investigation did not establish that servers were compromised to facilitate PaperPhone’s activities.

Further inconsistencies were found in address ownership and geolocation records. A single IP range might display conflicting registration, management, and claimed location details, pointing to different regions. Adjacent IP ranges were observed being presented as originating from diverse cities like Brussels, Bangkok, Tokyo, and Paris, creating an artificially inflated and geographically misleading picture. Over 20% of the observed cluster utilized M247 as its transit provider, despite none of the listed IP blocks being directly owned by M247. Many of these blocks were utilized at full capacity during the scraping operations.

Defenders should prioritize assessing the collective behavior of address ranges rather than treating each IP as an isolated entity. This transit relationship, while notable, does not definitively attribute the operation to a specific actor. Researchers also documented instances where IP addresses were rotated after repeated challenge failures resulted in bans. This adaptive behavior explains the increasing number of detected addresses over time, a phenomenon influenced by both expanding telemetry and the network’s address cycling. Consequently, the earliest sightings indicate enhanced visibility rather than the definitive commencement of the operation.

Fabricated Mobile Identities

PaperPhone employs a strategy of cycling through 13 different claimed device identities, including five Android models and seven iOS variants. However, a critical inconsistency emerged: every observed bot consistently reported the same 375×812 viewport resolution. This specific display size corresponds to an iPhone 10 or 11, a stark contradiction to the diverse range of handsets the network purported to represent. Furthermore, the browsers exposed Google SwiftShader within the WebGL renderer field. SwiftShader is a software graphics renderer typically found in systems lacking dedicated hardware acceleration.

This finding is difficult to reconcile with the recent Android devices claimed in the traffic, such as Pixel 9 and Samsung Galaxy S25 Ultra models, or with the purported iOS 14 and iOS 15 sessions. These inherent contradictions highlight the inadequacy of relying solely on factors like country of origin, user-agent strings, or IP reputation to establish the legitimacy of web traffic.

The presence of SwiftShader indicates that the graphics processing is handled by the CPU rather than a dedicated GPU. CrowdSec interpreted this combination as definitive evidence of Chrome-based automation operating without hardware acceleration, rather than genuine sessions originating from the mobile devices advertised in the browser identities. The findings emphasize the limitations of basic geographic blocking and individual IP address bans. A more comprehensive approach involves correlating request volume, address rotation patterns, browser viewport dimensions, graphics rendering behavior, device claims, and challenge failures. These signals are crucial for detecting sophisticated evasion techniques, similar to those seen in macOS browser fingerprinting evasions where attackers inspect visitors to conceal malicious content.

In summary, the synchronized activity across different time zones, the uniform display dimensions, the reliance on software rendering, and the concentrated ownership of IP addresses collectively exposed the automation underlying PaperPhone’s seemingly diverse mobile visitors. This underscores the necessity for multi-faceted detection strategies to counter advanced bot networks.

What You Should Do

  • Implement advanced bot detection solutions that analyze behavioral patterns, browser fingerprinting, and device characteristics beyond basic IP and user-agent checks.
  • Monitor for synchronized traffic patterns across geographically diverse IP ranges, as this can indicate centralized botnet activity.
  • Scrutinize inconsistencies between claimed device identities (user-agent strings) and actual browser characteristics, such as viewport size and graphics renderer information (e.g., presence of SwiftShader).
  • Move beyond simple IP reputation and geographic blocking; instead, focus on the collective behavior and anomalies within entire IP ranges and network blocks.
  • Regularly update and refine your telemetry and detection rules to adapt to evolving bot evasion techniques, as early sightings of new bot activity may only reflect increased visibility rather than the absolute start of an operation.

Indicators of compromise (IoCs):-

Type Indicator Description
IP range 103.216.1[.]0/24 PaperPhone-associated range illustrating registration inconsistencies: APNIC origin, RIPE registration, Lithuanian registrant, and a claimed United States location.
IP range 62.105.200[.]0/22 Range listed in the investigation with a claimed location of Brussels, Belgium. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/56290e46-978f-4df5-b67f-c8558e712d83/PaperPhone-Headless-Browser-Network-Uses-75000-IPs-and-Fabricated-Mobile-Identities-Across-43-Countries.pdf?AWSAccessKeyId=ASIA2F3EMEYETZUEGZTY&Signature=H4IYzbT7MyyeJ9uqLrVGU8Gm%2B5c%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEKD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCP%2Bvb30WUpHSjou1ZEsnmoBrtfu2GTP3ej0A9B1xnCqgIhAI3qUfqHoMKY1DbyFm0d0qrUcUdS2K1Gu9lT8pPYIU4eKvMECGgQARoMNjk5NzUzMzA5NzA1IgxahnseWAfq0XnZaFgq0AQBUcfM%2Fy4ExE4H1mQ04sol1p%2FPI3%2FgfmZIU7f1MWhxiDrUvppV3on1z0QS6AwXktPpsmP9BF3n1ZnOioC%2BNoa9Cqg3x5%2BtXCwai00ESQ5qfdtieOMdbeiS6daLAX4UttLBxwXu32E%2BUPWzGKfbPI2r7NWOwtUbnpx%2BIVYKXX1MUmk4%2BRXK0I

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

APT28 Targets Organizations With RedFlick Phishing Attacks

Next Post

Accelerate Phishing Investigations: 3 Steps for SOC Teams

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
APT28 Targets Organizations With RedFlick Phishing Attacks
September 30, 2026
AI Coding Agents Leak 13,000+ Internal Screenshots from 300+ Companies on GitHub
September 30, 2026
Critical Microsoft 365 Flaw Let Attackers Access Accounts
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us