VYPR
researchPublished Sep 30, 2026· 1 source

PaperPhone Network Mimics Mobile Traffic with 75,000 IPs and Fabricated Identities

A sophisticated headless browser network, dubbed PaperPhone, is leveraging 75,000 IP addresses across 43 countries to impersonate mobile traffic, evading traditional IP-based defenses.

A vast network of headless browsers, identified as PaperPhone, has been discovered actively mimicking legitimate mobile traffic to bypass security measures. This operation utilizes an extensive pool of 75,000 IP addresses spread across 43 countries, making it difficult for websites to block or ban individual sources. Researchers from CrowdSec observed this network over a two-week period, noting its ability to present fabricated mobile and browser identities while distributing its activity across numerous IP addresses.

The PaperPhone network's global reach and synchronized traffic patterns suggest a high degree of central coordination. Despite requests appearing to originate from distant countries like Japan and the United States, traffic peaks often occurred simultaneously, indicating a managed operation rather than independent user activity. The infrastructure comprises 230 IP blocks, many of which are recognized as data-center resources rather than residential proxies. This sophisticated approach highlights the limitations of relying solely on IP reputation and user-agent strings for defense.

Analysis of the network's infrastructure revealed inconsistencies in address ownership and geolocation data. IP blocks were often registered, managed, and claimed to be located in different regions, creating an artificial geographic distribution. Notably, a significant portion of the observed traffic utilized M247 as its transit provider, even though the IP blocks themselves were not directly registered to M247. This suggests a complex routing or reselling arrangement designed to obscure the network's true origin.

PaperPhone employs fabricated mobile identities, cycling through 13 different claimed device profiles, including various Android and iOS models. However, a consistent viewport size of 375x812 pixels was observed across all bots, matching that of an iPhone 10 or 11. Furthermore, the WebGL renderer field frequently exposed Google SwiftShader, a software renderer typically associated with systems lacking hardware acceleration. This contradicts the claims of using recent, high-performance mobile devices.

The combination of SwiftShader and the claimed device identities points towards Chrome-based automation running without hardware acceleration, rather than genuine sessions from the advertised phones. This discrepancy underscores the need for multi-layered detection strategies that go beyond simple IP or user-agent checks. Organizations are advised to correlate various signals, including request volume, IP rotation, browser viewport dimensions, graphics rendering behavior, and device claims.

When faced with repeated challenge failures, the network demonstrated an ability to rotate its IP addresses, contributing to the growing number of detected sources over time. This dynamic behavior suggests an adaptive infrastructure designed to evade detection and maintain its operations. The earliest sightings likely represent increased visibility rather than the absolute beginning of the PaperPhone network's activity.

CrowdSec's report emphasizes that the observed activity is primarily large-scale scraping, with no confirmed malware infections or data breaches linked to PaperPhone. However, the network's sophisticated evasion techniques and extensive infrastructure pose a significant challenge for defenders. The findings serve as a stark reminder of the evolving tactics used to mask automated traffic and the importance of analyzing address-range behavior and correlating multiple detection signals.

Synthesized by Vypr AI