Scraper Botnet of 3,600+ Devices Unleashed Against US and UK Websites

A newly uncovered scraper botnet, comprising over 3,600 distinct devices, is reportedly targeting web infrastructure in the United States and United Kingdom, according to security analysts at GreyNoise.

First observed on April 19, 2025, this sophisticated botnet leverages subtle yet effective evasion tactics, including a globally unique network fingerprint that sets it apart from previously catalogued automated threats.

Unique Behavioral Signature

Unlike conventional scraper campaigns that rely on easily spoofed indicators such as user-agent strings, this botnet’s true signature lies in its behavioral patterns at the network layer.

Although each bot presents itself with the simple, generic user-agent “Hello-World/1.0,” security teams at GreyNoise have revealed that the actual distinguishing factor is embedded in the interaction patterns of the malicious devices.

Using the JA4+ suite of network fingerprinting tools specifically, the JA4H and JA4T methodologies analysts have crafted a meta-signature capable of identifying this threat based on intrinsic connection behaviors.

The JA4H (HTTP fingerprint) aspect records the unique ordering and formatting of HTTP headers in requests, while JA4T (TCP fingerprint) focuses on how network connections are initiated at the TCP layer.

This combined fingerprinting approach enables defenders to spot botnet traffic by its underlying behavior, a technique far more resilient to spoofing and circumvention than superficial string-matching.

Widespread Campaign With Global Impact

Analysis of the campaign’s infrastructure reveals a global reach, with devices in the botnet making repeated GET requests focused on ports 80 through 85 to targeted web properties.

Of the 3,600+ unique identified IP addresses, approximately 38% have been classified as malicious, 3% as suspicious, and nearly 59% show no known association with existing threat actors or activity.

Notably, only a single benign IP was detected within the data set, underscoring the deliberate nature of the campaign.

Geographical breakdowns highlight an unusual concentration of botnet devices within Taiwanese networks, accounting for over 54% of observed IP addresses totaling 1,934 unique sources. Secondary clusters have been traced to Japan (9%), Bulgaria (7%), and France (3%).

This dominance of Taiwanese IP space has led investigators to hypothesize that either a widely deployed technology or service within Taiwan has been compromised, or that a local vulnerability has been exploited at scale.

The sheer number and geographic spread of the devices further amplify concerns about the scope and coordination of the threat actor behind this operation.

With the campaign’s principal targets located in the US and UK, GreyNoise is urging organizations to take immediate proactive steps.

Security teams are advised to leverage GreyNoise’s Visualizer and API tools to detect and track this botnet’s activity by searching for the relevant JA4+ signatures.

Blocking all known participating IPs is recommended to curtail automated scraping and prevent further reconnaissance.

Additionally, defenders are encouraged to monitor internal network traffic for evidence of communication with these addresses and to pursue ongoing tracking of related behavioral signatures, as similar variants or extensions of the campaign may soon emerge.

As automated threats continue to evolve in sophistication, this case illustrates the growing importance of behavioral network analysis as a cornerstone of robust digital defense, and a move away from obsolete detection practices rooted in static strings and patterns.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories