A newly uncovered scraper botnet, consisting of over 3,600 distinct IP addresses, has been identified by cybersecurity firm GreyNoise. First detected on April 19, 2025, this botnet targets websites in the United States and the United Kingdom using repetitive GET requests across ports 80 to 85. While its user-agent string ("Hello-World/1.0") is simple and easily spoofable, the botnet stands out for its unique behavioral fingerprint. To identify and track this sophisticated threat, GreyNoise analysts used the advanced JA4+ fingerprinting suite, specifically JA4H (HTTP header structure) and JA4T (TCP connection traits).The detection reveals an organized and evasive botnet capable of bypassing traditional signature-based defenses. Geographic analysis shows a striking concentration of the botnet's infrastructure in Taiwan, which accounts for 54% of the IP addresses (1,934 devices), suggesting a potential regional compromise. Other clusters were found in Japan, Bulgaria, and France. GreyNoise categorized 38% of the IPs as malicious and 3% as suspicious, with only a single IP deemed benign. This highlights the predominantly harmful nature of the botnet and raises concerns over systemic vulnerabilities in Taiwan or the presence of a widely exploited service or device. The botnet’s scale and behavioral stealth present a significant risk to data integrity and system performance, especially for high-value online assets. GreyNoise recommends that organizations immediately block all identified IPs to mitigate potential scraping and reconnaissance activity. Additionally, internal monitoring for traffic to or from these IPs is essential, as it may reveal deeper compromises within a network. Tracking similar JA4+ fingerprints can also help identify related threats and expand detection capabilities.
Cybersecurity researchers have uncovered another evolution of the ongoing supply chain attack linked to the Mini Shai Hulud, Miasma, and Hades malware family, targeting both the np...
Amazon has addressed a high-severity security vulnerability, tracked as CVE-2026-12957, affecting Amazon Q Developer IDE plugins. The flaw could allow a malicious Git repository to...
?An active phishing campaign has targeted hotels and hospitality organizations across Europe and Asia since April 2026. Attackers send emails impersonating "Booking Manager (vi...