Security Stop-Press: Malicious AI-Driven Bots Make Up Over a Third of Internet Traffic

Malicious bots now account for 37 per cent of all internet traffic, according to cybersecurity firm Imperva’s 2025 Bad Bot Report, with AI playing a central role in their rapid evolution.

For the first time in a decade, automated traffic (51 per cent) has overtaken human activity online. The rise of accessible AI tools has not only made bots more evasive and effective but also lowered the barrier for low-skilled attackers to launch simple, high-volume attacks.

Imperva warns that bots are increasingly targeting APIs, with 44 per cent of advanced bot traffic now focused on exploiting business logic. These bots scrape data, commit payment fraud, and hijack accounts, often bypassing detection by mimicking human users and leveraging residential proxies, browser spoofing, and CAPTCHA-solving AI.

Tools like ByteSpider (responsible for 54 per cent of AI-powered bot attacks), AppleBot (26 per cent), and ClaudeBot (13 per cent) are being spoofed to launch attacks. Meanwhile, account takeover (ATO) attacks have surged by 54 per cent since 2022, hitting sectors like financial services and telecoms hardest.

Imperva says businesses must urgently adapt by deploying advanced bot detection, securing APIs, applying rate limits, and monitoring for suspicious behaviour. With AI fuelling both the volume and sophistication of attacks, staying ahead requires constant vigilance and smarter defences.

Security Stop-Press: Warning To Delete 16 Malicious Chrome Extensions

GitLab Threat Intelligence has warned over 3.2 million Chrome users to delete 16 malicious browser extensions that compromise security and expose data to attackers.

The extensions, including ad blockers, screen capture tools, and emoji keyboards, were found injecting harmful code into browsers. GitLab says attackers hijacked these extensions through phishing or by acquiring them from developers, using them to bypass security protections and manipulate content.

Once installed, the extensions connect to a remote server, receive hidden commands, and strip security measures from websites. Although Google has removed them from the Chrome Web Store, the warning to users is to manually uninstall them to stay protected.

Compromised extensions include Blipshot, WAToolkit, Super Dark Mode, and Adblock for Chrome. Experts warn that high download counts and positive reviews do not guarantee safety, as attackers often hijack trusted extensions.

Businesses should restrict unverified extensions, review permissions regularly, and use endpoint security to prevent such threats. Monitoring browser activity can also help detect potential risks early.

Company Check – Italian Spyware Firm Accused of Distributing Malicious Apps

According to TechCrunch, it’s alleged that Italian spyware maker SIO has been distributing malicious Android apps designed to masquerade as WhatsApp and other widely used applications while covertly harvesting sensitive data from targeted devices.

The spyware, dubbed ‘Spyrtacus,’ has been operating undetected for years, raising fresh concerns about government-backed surveillance tools and the extent of their reach.

It’s been reported that the discovery was triggered late last year when a security researcher provided TechCrunch with three suspicious Android apps, believed to be government spyware used in Italy. Following independent analyses by Google and mobile security firm Lookout, it was confirmed that these apps contained spyware designed to infiltrate users’ devices. Spyrtacus has been found capable of stealing text messages, social media chats, and contact details, recording calls and ambient audio, and even taking images via a device’s cameras.

SIO, the company behind the spyware, is an Italian firm that sells surveillance tools to the Italian government. Lookout has reported that Spyrtacus samples were found to be embedded within apps mimicking popular services, including those belonging to Italian mobile providers TIM, Vodafone, and WINDTRE. It’s alleged that these fraudulent applications were distributed through malicious websites disguised as official sources. While Google confirmed that no versions of this malware exist on its Play Store, a 2024 report by Kaspersky suggests that earlier versions were available there in 2018 before moving to independent distribution channels.

The spyware appears to have been used in a highly targeted campaign, but the identities of those affected remain unclear. Given that the apps and distribution sites were in Italian, security analysts believe that law enforcement agencies in Italy were the likely operators of the campaign. The scandal comes amid separate allegations that Israeli spyware firm Paragon provided sophisticated surveillance tools used against journalists and NGO founders in Italy.

Kristina Balaam, a researcher at Lookout, revealed that 13 distinct Spyrtacus samples had been identified, with the earliest dating back to 2019 and the most recent traced to October 2024. The continued presence of these samples across multiple years highlights the persistence of state-sponsored spyware and its evolving distribution methods. Also, Kaspersky researchers report finding indications of a Windows version of Spyrtacus and possible variants for iOS and macOS, suggesting a broader cross-platform surveillance effort.

Despite multiple requests for comment, neither SIO nor its senior executives, including CEO Elio Cattaneo, CFO Claudio Pezzano, and CTO Alberto Fabbri, have responded to the allegations. Also, the Italian government and Ministry of Justice have remained silent on the issue, leaving major questions unanswered about the scope and legality of such surveillance operations. The case adds to growing concerns about the global spyware industry and the blurred lines between national security and invasive digital espionage.

What Does This Mean For Your Business?

The allegations against SIO and its Spyrtacus spyware highlight growing concerns over state-backed surveillance and the ethical boundaries of digital espionage. While governments often justify such tools for security purposes, the secrecy surrounding their use raises serious questions. The knowledge of the deployment of spyware disguised as legitimate apps undermines public trust and exposes broader cybersecurity risks.

For UK businesses, this case is a reminder of the dangers posed by sophisticated malware. While not direct targets, organisations handling sensitive data must remain vigilant against similar threats. The methods used, i.e. malicious websites and fake applications, demonstrate vulnerabilities that cybercriminals could exploit.

More widely, this case reflects the unchecked expansion of the spyware industry. With no accountability from SIO or the Italian government, concerns grow over how such tools can be used without oversight. Stronger international regulations are needed to balance security with the protection of civil liberties, or the lines between lawful surveillance and invasive digital monitoring will only continue to blur.

Security Stop Press : List Of Malicious Android Apps To Delete Now

Online protection company McAfee’s Mobile Research Team has identified a list of malicious apps that Android owners should immediately delete. This is because they use Xamalicious malware to build a stealth backdoor, infect, and take over devices.

The apps, which have now been removed from the Google Play store, are reported to have been downloaded hundreds of thousands of times.

Detailed information about how each of the apps infects devices, and a list of the 13 malicious apps that were present in the Google Play Store can be found on McAfee’s website here.

The advice is to avoid using apps that require accessibility services unless there is a genuine need for their use, install security software on your device, always keep the security software up to date.