HabrJuly 31, 2026🇷🇺Translated from Russian

Bots Now Form Over Half of Global Internet Traffic in 2025, Driving API Attacks and Business Metric Distortion

Bots already account for the majority of internet traffic, creating challenges that extend far beyond traditional information security. In 2025, automated clients generated more than 50% of observed traffic, with malicious bots responsible for 40% of the total. The number of attacks leveraging AI-enabled automation grew 12.5 times compared with the previous year.

During the 81st anniversary of Victory Day, Garda WAF blocked over 3.5 million attacks and stopped more than 307,000 bot requests targeting the Immortal Regiment historical movement site. Industry reports vary because vendors analyze different networks and apply different counting methods, yet the consistent message is that human-generated requests can no longer be assumed by default.

Shift of automated traffic from web pages to APIs

Modern bots increasingly target APIs directly instead of emulating browsers. Akamai data shows a 113% rise in daily API attacks, with 87% of organizations reporting at least one API-related security incident. The share of attacks involving unauthorized business workflows grew from 30% to 61%.

At the same time, simple automated scripts remain dominant. Qrator Labs statistics for Q2 2025 indicate that basic bots generated 59% of protected bot traffic while API bots accounted for 38%. A single large botnet observed by the company contained more than 4.5 million devices, twenty times larger than the biggest network detected the previous year.

New categories of crawlers and agents

Cloudflare Radar data reveals that 40% of verified bot traffic came from search crawlers, 20% from AI crawlers, and 13% from SEO bots. The boundary between beneficial and harmful automation has blurred because AI agents can generate high load, consume content without returning visitors, or perform reconnaissance under the guise of legitimate use.

OWASP classifies automated abuse of legitimate application functions as automated threats. Common scenarios include credential stuffing, scraping of pricing and inventory data, gift-card enumeration, ticket hoarding, and market manipulation through fake reviews or demand signals.

Impact on business metrics and infrastructure

Bot traffic distorts web analytics by inflating session counts and lowering observed conversion rates. An example shows that 5,000 additional bot sessions can reduce measured conversion from 3% to 2% without any change in real customer behavior. Infrastructure resources are consumed for CDN traffic, database queries, and third-party service limits, while aggressive protection mechanisms such as repeated CAPTCHAs can degrade genuine user experience.

Detection now relies on combinations of signals rather than single indicators. JA3/JA4 TLS fingerprints, header ordering, JavaScript execution integrity, and behavioral patterns within sessions help distinguish automated clients even when they use real browser engines such as Chromium, Playwright, or Puppeteer.

Related articles

AntiMalwareMalware & Botnets

Microsoft Removes WMIC from Windows 11 After Years of Abuse as LOLBIN by Ransomware and Attackers

Microsoft has begun permanently removing the legacy WMIC command-line utility from Windows 11, starting with versions 24H2 and 25H2. The tool is no longer available in fresh installations, has been dropped as an optional component, and is absent from the latest beta builds. WMIC provided text-based access to Windows Management Instrumentation for querying hardware, processes, services, and security software, as well as performing administrative tasks. Although the underlying WMI technology remains untouched, Microsoft has deprecated the command shell due to its long-standing use as a LOLBIN in cyberattacks. Ransomware operators have leveraged WMIC to delete shadow copies and hinder recovery, while other attackers used it to enumerate and disable security tools or add exclusions in Microsoft Defender. Administrators are directed to migrate to PowerShell, COM API, .NET libraries, and modern scripting languages, which will require rewriting legacy automation scripts.

AntiMalwareMalware & Botnets

Octagon Malware-as-a-Service Platform Targets Android Banking Apps and Crypto Wallets for $1400 Monthly Subscription

Researchers at iVerify have uncovered the previously unknown Octagon platform, a malware-as-a-service offering sold by a Russian-speaking actor under the handle AndroidKitKat. The service first appeared on underground forums on June 1, 2026, with version 1.2 released by June 29, providing a ready-made control panel for account takeovers across banks, crypto exchanges, messengers, and wallets. Infection starts with a disguised APK that requests Accessibility Services permissions, after which the trojan can read UI elements, simulate taps, launch apps, and overlay phishing screens on services such as Trust Wallet, Binance, and MEXC. The malware also intercepts SMS one-time codes, spoofs the system lock screen to steal PINs or patterns, and supports VNC-style remote control while operating on the victim’s own device to evade anti-fraud systems. Three related builds—Octagon, Lifted Dreams, and BahrDate—were identified, with one variant displaying a visual novel to distract users while the spyware runs in the background. The campaign underscores the growing threat of sophisticated Android remote-access trojans sold on a subscription basis.

AntiMalwareMalware & Botnets

BTMOB Platform Turns Android Banking Trojan into Customizable Fraud Campaign Constructor

Researchers at QuimeraX have uncovered BTMOB, a platform that evolved from a banking trojan into a full-featured builder for fraudulent Android campaigns. The service allows clients without development skills to select an app name, icon, command-and-control server, permissions, and social-engineering lure, after which the system automatically compiles a ready-to-use APK. The package includes an Android payload, dropper, VB.NET control panel, PHP and MySQL backend, and build tools that enable rapid production of localized copies of streaming services, banking protection modules, parcel trackers, and social networks. One BTMOB 2.5 variant was distributed via a phishing site mimicking the Turkish iNat TV service, while Brazilian operators created fake Google Play pages impersonating Nubank, TikTok, and the government portal Gov.BR. After installation, the trojan requests accessibility permissions and, once granted, grants operators near-complete device control including screen viewing, keystroke capture, audio recording, and real-time WebSocket interaction that lets attackers perform actions directly on the victim’s device. Analysts link BTMOB to the SpySolr family and earlier commercial RATs CypherRAT and CraxsRAT, which had already attracted more than 100 licensees.

BoletimSecMalware & Botnets

Dysphoria Botnet Compromises Nearly 300,000 Devices for DDoS Attacks and Residential Proxy Services

The Dysphoria botnet has infected approximately 296,000 devices, including routers, IP cameras, gateways, and embedded Linux systems. Researchers first observed the threat in the first quarter of 2026, noting rapid evolution from the jackskid and fbot families. The infrastructure is primarily used for DDoS attacks but has expanded to offer residential proxy capabilities. Infection occurs through brute-force attacks on Telnet and SSH services with weak credentials, as well as known remote code execution vulnerabilities in IoT equipment. A key technical advancement involves the use of Ethereum and Solana blockchain domains for command-and-control infrastructure, making takedowns significantly harder. Compromised devices can also function as relays by leveraging UPnP to expose ports and hide criminal traffic origins. Operators advertise attack capacity of up to 4 Tbps and sell DDoS services in structured commercial packages targeting internet services and gaming platforms worldwide.