So this is interesting, turns out a bunch of AI scraping traffic isn't from infected systems (as I'd thought) but apps and so on that bundle or are bundled with malware for money:
https://jan.wildeboer.net/2025/04/Web-is-Broken-Botnet-Part-2/
Mobile folks: how hard would it be to detect the presence of Infatica in .apks? Publish some sort of "hall of shame"?
Also, might there be any point in reporting to Google / Apple? I'd like to think that one of the benefits of a walled garden would be the ability to reject apps that feature this sort of malware. But honestly both Apple and Google are so far in to the AI bubble that they probably use the results themselves π

Botnet Part 2: The Web is Broken
I guess you have all heard about the growing problem of AI companies trying to aggressively collect whatever data they can get their hands on to train their models. This has caused an explosive surge in web crawlers relentlessly hitting servers big and small. But who runs these crawlers? Turns out β it could be you!
jan.wildeboer.net Β· Jan Wildeboer's Blog
Link author:
Jan Wildeboer π·
@jwildeboer@social.wildeboer.net