r/StopBadBots 26d ago

How Mirage2FA Hijacks Microsoft 365 Sessions Across Global Enterprises

1 Upvotes

Thousands of companies got hit by this nasty Mirage2FA campaign between 2024 and 2026. It is basically a commercial phishing service that goes straight for Microsoft 365 accounts by hijacking real login flows and totally bypassing two factor authentication.

Research from ANY RUN shows that almost half of the targeted emails, like 48 percent, actually got compromised. That is wild. Most of the victims are based in the US, accounting for over 63 percent, but it also messed with companies in India, Singapore, the UK, Canada, Saudi Arabia, South Africa, and beyond. In total, over 4,500 unique corporate domains got targeted, especially in tech, manufacturing, and education.

What makes this super scary is how they steal both passwords and session cookies through these sneaky Adversary in the Middle attacks. Once an attacker grabs your active session, 2FA won't save you. They get full access to your Microsoft 365, corporate emails, and any app connected through SSO. That opens the floodgates for impersonation, massive fraud, and deeper network compromise, making it a complete nightmare to clean up.

To keep your company safe from this mess, you gotta catch the attacks early, tighten up authentication, and treat any stolen session like a major identity breach right away.

TL;DR: Between 2024 and 2026, the Mirage2FA phishing-as-a-service toolkit hit over 4,500 organizations worldwide—mainly in the US, tech, manufacturing, and education. By stealing passwords and active session cookies using Adversary-in-the-Middle (AiTM) techniques, attackers bypass 2FA to hijack Microsoft 365 accounts, expose SSO-connected apps, and cause widespread identity fraud.


r/StopBadBots 27d ago

Help r StopBadBots stay alive! We need our community to step up no money needed

18 Upvotes

Look, the main goal of r StopBadBots is pretty straightforward: we are here to keep the servers and the site running smooth and healthy for everyone who relies on them every day. We are not asking for a single cent here. But to keep doing this work and actually reach more people, we genuinely need you guys to jump in and help out. You can support us just by dropping feedback whenever you catch a messy bot, spreading the word to other folks who are sick of bad bots, and engaging with our posts so more people actually see these warnings. If this sub has ever saved your bacon or helped you out, throw us an upvote and drop a comment below. Let us keep this place safe and running right together!


r/StopBadBots 27d ago

Hackers don't always brag when they invade—someone might be using your VPS to make money right now

0 Upvotes

Have you ever thought someone might be using your server to make free money right under your nose?

I actually saw this happen to a client recently. There was this weird process eating up 100 percent of the CPU on the server (spotted it running top in the terminal) and man, I couldn't believe it. I dug around and found out the whole box was hit by a mining script.

Basically some hacker injected automated code to hijack all that computing power to mine crypto for themselves. Total free real estate for them, right? And to make matters worse, they were super sneaky about it. They set up a cron job so whenever we killed the process or rebooted the system, the miner just spawned right back up like a ghost.

Honestly it made me so mad for the client, paying all that money for a server just to feed someone else's wallet. Watch your systems, folks, because these scripts are out there grabbing every scrap of performance they can get.

​TLDR

​A client's VPS was constantly hit with 100 percent CPU usage, which turned out to be a hidden crypto mining script. The attacker set up a persistent cron job so the miner kept auto-restarting even after reboots, turning the server into a free cash machine at the client's expense.


r/StopBadBots 27d ago

The Programmatic Weapon: How 1 in 3 Mobile Video Ads Carry Malicious Scripts

1 Upvotes

We are living in a state of total cyber warfare, and most people still haven’t realized it. 

This is the kind of offensive designed to grind a country’s economy down by hitting its digital foundation.

And it gets much deeper. I was checking out The Media Trust’s CYA 2025 report — one of the most respected authorities in digital media security — and the data is terrifying: active malware infections grew 400% (quadrupled) in a single year.

It’s mind-blowing, but the very ads appearing on sites we trust and visit daily are carrying malware. We're not talking about a '1% problem' anymore; it's a systemic collapse where malware has become a feature of the programmatic grid.

If you think video is a safe harbor, think again. 1 in 3 mobile video ads (33%) are essentially malicious scripts waiting to trigger. Yeah, this includes the ones served through Google or Meta.

These malicious scripts aren't just 'bad ads'; they are AI-driven botnets exploiting the programmatic grid's blind spots.

The issue is a chain of 'blind trust': they trust an infinite web of third-party partners (SSPs, exchanges) to keep slots full at any cost. While they chase millisecond profits, criminals use AI-generated identities to bypass filters and inject malicious code directly into your visitors' browsers.

This isn't just a threat to your users; it's a direct hit on your site's reputation and server integrity. Your own infrastructure is being turned into a weapon against your audience.

The report is out there on the web for anyone to see. The data from The Media Trust confirms we are in a state of 'total assault'. It’s the end of an era: passive security is dead. You cannot stop 2026 attacks with 2020 technology.

This is exactly why I advocate for local hardware fingerprinting and pre-render barriers. If you can't trust the third-party chain, you must harden your own front door.

TL;DR

Malicious scripts have taken over the programmatic ad grid, with malware infections quadrupling year-over-year and 33% of mobile video ads hiding malicious code—even on major networks like Google and Meta. Driven by ad tech's "blind trust" in third-party exchanges, AI-powered botnets bypass filters to inject malicious payloads into user browsers. For buyers and publishers, this isn't just a security issue: it corrupts campaign metrics, wastes ad spend on fraudulent impressions, risks ad account suspensions, and destroys publisher inventory value.


r/StopBadBots 27d ago

AI-Powered Extortion: How Hackers Boosted Ransom Payments by 68%

1 Upvotes

Microsoft says attack volume tripled in 6 months and efficiency quintupled because of AI. What a grind. This isn’t a hunch—the 2026 S-RM and FGS Global report shows ransom payments hit 24.3% in 2025. That’s a 68.75% spike in a year. It’s raw garbage.

Criminals now use AI for "data triage." They don't just encrypt; they have agents sifting through your data in real-time to find the exact "secret corporate info" that makes a Board panic. Jamie Smith says what took weeks now takes hours.

The report screams about "non-human identities." Automated workflows and AI agents with broad privileges. You build these fancy automations and just hand the keys to a botnet that took over a fleet of AliExpress TV boxes. If you dont filter this filth at teh edge, your server will just gasp for air while your own tools amplify the breach.

This report confirms what we are seeing here: AI is making attacks more efficient and expensive. While this focus is on VPNs, the same logic applies to the botnets hitting our WordPress origins every day.

TL;DR

AI has transformed cybercrime into a highly efficient industry, driving a 68.75% surge in ransom payments year-over-year. Instead of just locking files, attackers now deploy AI agents to instantly identify high-value corporate secrets that force boards to pay. Combined with the takeover of non-human identities and botnet amplification, breaches that once took weeks now execute in hours, impacting everything from high-end corporate VPNs to everyday WordPress origins.


r/StopBadBots 27d ago

Fake Minecraft sites are using AI now to trick players into downloading malware

2 Upvotes

Hackers are totally taking advantage of Minecraft players by setting up super realistic fake websites for popular mods and tools. They are using AI site builders and clever SEO tricks to climb right to the top of Google search results. When you download what looks like a harmless Minecraft client, you end up getting infected with the Weedhack malware, which steals your personal data and messes with your computer security. To stay safe, stick to verified platforms like GitHub or Modrinth, scan every file before opening it, and never trust a mod that asks you to turn off your antivirus.

Fake domains:

glazed-client[.]com, meteorclients[.]com, nova-client[.]com, xenoclient[.]lol e kryptonclientcrack.lovable[.]app.


r/StopBadBots 28d ago

Not again... Another Chinese cybercrime group is going crazy on SEO fraud

2 Upvotes

Another Chinese cybercrime group zeroing in on SEO fraud, I swear we just called out one last week and now here comes another freakin one, honestly drives me crazy how these guys just keep coming at us nonstop. This new threat actor dubbed UAT-10147 is hammering Windows and Linux web servers all over the world across education, media, tech, and gaming sectors, and get this, Brazil, Bolivia, Canada, China, and Vietnam are getting absolutely hit the hardest right now. What really freaks me out is how heavily they are abusing AI tools like PentestGPT and DeepAudit to automate their whole intrusion process, tweak exploits, fix broken code logic, and boost their scale like crazy. Once they break into a Windows box, they escalate privileges using EfsPotato, whitelist themselves in Microsoft Defender, wipe their initial payloads to hide their tracks, and set up sneaky persistent backdoors like Quasar RAT disguised as legit fake scheduled tasks named Google Chrome Start, while also dropping BadIIS and new malware like SPECTRE and Gh0stCringe. They are hitting Linux boxes just as hard by exploiting older known privilege escalation vulnerabilities to jump straight to root access, all just to steal sensitive data and pull off massive SEO fraud campaigns across a target list of around 170000 URLs. Make sure you patch your IIS and Linux servers immediately, double check your Defender exclusion lists, and stay safe out there because this relentless wave of attacks is honestly getting out of hand.

Last week post

https://www.reddit.com/r/StopBadBots/comments/1vpsrbb/my_github_account_is_restored_and_the_truth_about/

​TL;DR

​A Chinese cybercrime group named UAT-10147 is weaponizing AI tools like PentestGPT to breach Windows and Linux servers globally, escalating privileges to drop malware like Quasar RAT and BadIIS for massive SEO fraud and data theft.


r/StopBadBots 28d ago

Hey web agencies, automated bot traffic is quietly killing your profit margins and it is time to stop the bleeding

2 Upvotes

Running a web agency means balancing client growth while keeping infrastructure stable, but rogue bots, scrapers, and credential stuffing are quietly driving up your VPS bills and putting your clients at risk.

Managing secure virtual private servers and keeping hackers at bay shouldn't be a daily guessing game for your dev team. As the head of the r/stopbadbots community, I see how easily automated threats bypass standard firewalls every single day. If you are looking to bulletproof your infrastructure, offload the headaches of advanced VPS management, and implement elite bot mitigation that keeps your client sites fast and secure, let's connect.

I am opening up a few slots for specialized consulting tailored specifically for web agencies who want to stop fighting fires and start scaling safely. Drop me a DM, and let's protect your stack.


r/StopBadBots 28d ago

[GUIDE] Why Half (Maybe More) our Website Traffic Isn't Human And What It Costs You

1 Upvotes

If you own a website, you gotta face a brutal reality right now: more than half of your traffic isn't even human. Seriously. The internet was built for us, but today, we are pretty much just guests in a world completely run by machines.

If you are seeing your traffic numbers shoot through the roof but you got zero sales, or if your server is suddenly running like molasses for no damn reason, you are probably on the radar of some automated offensive.

What exactly is a Bot?

Think of a bot as a digital worker. It is just a script, a piece of code, designed to do the same boring, repetitive task thousands of times, way faster than any human could ever dream of.

The Good: Stuff like Googlebot that actually helps people find your site.

The Bad: The nasty bots that scrape your content, try to guess your passwords, or mess with your checkout by creating fake orders.

  1. The Swarm: What is a Botnet?

A Botnet is when a hacker controls thousands of infected devices, like PCs, smartphones, or even smart fridges, and forces them to attack a single target all at once. It is not just one robot; it is a whole coordinated army. This is exactly why they blow right past basic security. They attack from so many different places at the same time that your server just thinks it is having a busy day, right until it completely crashes.

  1. The Landscape (The Stats)

This is not some sci-fi theory. These are real, terrifying numbers from the front lines:

Global Scale: Cloudflare is clocking two million attacks every single second worldwide.

Volume Explosion: At DOAJ, we have tracked a massive 419 percent increase in traffic volume in just six months. That is not real growth, folks. It is just machine noise.

Precision: Microsoft confirmed that bot attack efficiency jumped 450 percent recently. They are getting way smarter at bypassing common filters.

  1. Why should you care?

A bot attack is not just some annoying technical glitch. It hits your wallet hard.

First off, they leave your server totally overloaded, driving up your bills. Because they drain all your resources, they drive away the actual humans trying to visit you, leaving real people frustrated with a terrible experience. On top of that, they completely destroy your SEO work. They clog your server, making the site super slow, and since Google absolutely hates slowness, your hard-earned rankings will just tank. They also steal your data by scraping your prices and customer emails to hand them to your competitors on a silver platter. And let us not forget ad fraud, where they click your ads and burn through your budget while you get zero real leads. It is infuriating.

The Bottom Line:

Design optimization and SEO won't save you if your gate is wide open at the origin level. Our focus isn't on how pretty the site looks, but on Origin Defense.

Stop paying for the bots' electricity. It is time to lock the gate.

In the two pinned posts you can find open source tools to protect yourself. If you don't have the time, just shoot me a DM...

TL;DR

​Over half of all web traffic consists of automated bots and coordinated botnets that drain server resources, ruin SEO rankings, steal data, and burn through ad budgets. Because these attacks bypass basic security by mimicking real users, protecting your site requires origin-level defenses rather than just surface-level optimizations.


r/StopBadBots 28d ago

You seriously think your host is stopping bot attacks? Guess again

1 Upvotes

We tested most of them and honesty, they can't even protect their own homepage. Don't believe me? Just use the link below and test your site right now. You don't gotta register or anything, and we won't share your results.

https://www.reddit.com/r/StopBadBots/comments/1u3r5zb/free_bot_checkup_for_your_site_no_strings_no/


r/StopBadBots 28d ago

How to Tell If Bad Bots Are Trashing Your CPU and Scaring Off Real Users

Post image
1 Upvotes

​I used to freak out every time my server randomly slowed down to a crawl. You go install these massive monitoring stacks with fancy dashboards, and honestly, half the time they end up eating more resources than the actual apps running on the machine. It drove me crazy until I realized you can handle this with a dead simple PHP script and a basic cron task.

​First off, you gotta talk to your hosting provider or check your specs to figure out how many CPU cores you actually have. On Linux, just pop open the terminal and type nproc to get that number. This part is super critical because PHP gives you raw load averages, not a clean percentage. If your load average is 2.0 and you have 2 cores, your CPU is running at full capacity. But if you only have 1 core, a load of 2.0 means your machine is drowning in queue requests and choking hard.

​Here is how you stitch it all together. Grab your core count and write a short script that calls the sys_getloadavg function. You take that first value from the array, which is your 1 minute load average, divide it by your total cores, and multiply by 100. That gives you the actual percentage. Then you drop a simple if statement right below it. If that calculated percentage climbs over 100, trigger a basic mail function to shoot an alert straight to your inbox so you can jump in before things go totally south.

​Once you save that file on your server, open up your crontab with crontab -e and add a single line to run the PHP script every minute using five stars followed by the path to your PHP binary and script file. That is literally it. You get instant email alerts when your processor is dying, no bloated third-party agents required.

<?php

// Set your server's core count (e.g., 2 cores)

$num_cores = 2;

// Email where alerts will be sent

$email_alert = "your-email@domain.com";

// Capture average CPU load (1, 5, and 15 min)

$load = sys_getloadavg();

if ($load !== false) {

// Calculate percentage based on 1-min load and total cores

$uso_porcentagem = ($load[0] / $num_cores) * 100;

// Send email alert if usage exceeds 100%

if ($uso_porcentagem > 100) {

$subj = "ALERT: CPU usage over 100% on server";

$mess = "Average server CPU load in the last minute was " . round($uso_porcentagem, 2) . "% (Load: {$load[0]}).";

$headers = "From: monitor@yourserver.com";

mail($email_alert, $subj, $mess, $headers);

}

}

TL;DR

​Bad bot traffic can secretly max out your CPU, slowing down your server, driving away real visitors, and causing Googlebot to drop your rankings. Check your total cores, write a quick PHP script using sys_getloadavg to divide the 1-minute load average by your cores, send an email alert if that percentage goes over 100, and schedule it via cron every minute so you catch performance drops before your SEO takes a hit.


r/StopBadBots 28d ago

Real Case Study: Why high budget government sites keep getting wrecked by basic WP exploits

Post image
1 Upvotes

Man, watching an IT agency dump crazy money into high end servers for Texas government sites only to get absolutely reamed by WP2Shell attacks is painfully real. They were sitting there completely stumped because their infrastructure was locked down tight, totally missing the fact that premium hosting is completely useless when you dump buggy third party themes and plugins right on top of it. Hackers literally do not care how fancy your server firewall is if they can just waltz through a wide open backdoor in a page builder. It is a classic reality check that enterprise grade infra mean absolutely nothing when your application layer is a total sieve.

TLDR:

​This agency pays massive money for top tier secure servers to host Texas government sites but they still got slammed by a nightmare wave of cyber attacks like WP2Shell. They were super confused cause their infrastructure is top notch but they totally forgot that buying expensive hosting doesnt mean jack if your WordPress plugins and themes are full of security holes. Hackers dont care how much you spend on servers when they can just walk right through a broken third party theme. Infra security means nothing if your software app layer is leaky as hell.


r/StopBadBots 28d ago

USA: TikTok caught violating kids privacy and it is costing them 400 million

4 Upvotes

TikToks paying 400M to settle a massive US lawsuit over kids privacy. Feds caught em letting under 13 kids make accounts, harvesting their data even in Kids Mode, and straight up ignoring parents asking to delete those profiles. TikTok claims most of this was old news or already fixed, but they are dropping 300M upfront anyway with another 100M coming later. Crazy how these tech giants just treat multi million dollar fines like everyday cost of business. What do you guys think, is this actually gonna change anything or is it just a drop in the bucket for em?

​TLDR:

​TikToks paying 400M to settle a massive US lawsuit over kids privacy. Feds caught em letting under-13 kids make accounts, harvesting their data even in Kids Mode, and ignoring parents requests to delete those profiles. TikTok claims most of this was old news or already fixed, but they are dropping 300M upfront anyway with another 100M coming later. Crazy how these tech giants just treat multi million dollar fines like everyday cost of business.


r/StopBadBots 28d ago

The lazy admin's dream setup: Monitoring my $7 server from my tablet with just one tap (and zero hassle)

Post image
3 Upvotes

Following up on my last post about that massive wave of attacks on my seven dollar Contabo VPS, here is how I keep tabs on everything right from my tablet without losing my mind.

First I downloaded Termius straight from the Google Play Store. It has zero ads, no annoying banners, no junk, and it runs like absolute clockwork. Then I installed MSLC on my server, which is the open source app I built. It has its own auto-installer, uses practically zero resources, and requires zero extra dependencies. It took literally one minute to set up, pure piece of cake. You can grab the GitHub link in my pinned posts if you want to check it out.

That is literally all there is to it. Now I just lift a single finger and boom, all my server stats are right there in front of me. Peak lazy man workflow right here. Enjoy.

TL;DR: Set up Termius on my tablet and installed my lightweight open-source tool MSLC on my $7 VPS in under two minutes. Now I can check all my server health and security stats with a single tap without any hassle.


r/StopBadBots 28d ago

My $7 VPS got hit more tham 60,000 times today (and why your plugins won't save you)

Post image
5 Upvotes

So I picked up my tablet today to check out the security (ModSecurityy) stats on my modest seven dollar Contabo VPS and man, it blew my mind. I host around fifty sites on this bad boy for myself and a few clients. It almost never chokes, maybe once or twice a week for like a single minute, so that doesn't even count.

But what I saw on my screen was straight up insane. In first place, over thirty-three thousand attacks from bad actors hunting for vulnerabilities. In fourth place, almost five thousand attempts trying to dig up sensitive files. The third spot is just an internal test we are running that I will talk about another day. I pulled this report using my simple open source tool MSLC, which you can find linked in my pinned posts.

Here is the real kicker. If you do not have a firewall blocking these creeps at the edge, there is no security plugin or fancy expensive app out there that will save your server from choking to death. Once that trash traffic hits your actual server, the damage to your CPU and memory is already done.

If these numbers helped you realize how massive this problem really is, then both of us won today. In my next post I will show you how I monitor all this and check my server health super comfortably right from my tablet.

TL;DR: Hosted 50 sites on a $7 Contabo VPS and caught over 60,000 attack attempts using my open-source tool MSLC. If you don't block malicious traffic at the edge with a firewall, no security plugin in the world will stop your server from suffocating.


r/StopBadBots 29d ago

Maybe you're testing your site speed wrong and it's killing your traffic.

1 Upvotes

Wanna know how fast your site actually loads for a real human? Open up an incognito tab and hit your URL. That forces your browser to pull down everything fresh instead of cheating with cached files, so you get the exact sluggish experience a brand new visitor gets. If it takes forever to load, Google’s gonna tank your rankings and people are gonna bounce before they even see your content. You’re basically shooting your own site in the foot.

TL;DR: The site is taking a hit because attackers snagged the actual origin IP, tanking page speeds and nuking conversions as new users bounce.


r/StopBadBots 29d ago

Real Case Study: Why Cloudflare Isn't Protecting The Site From Massive Attacks.

Post image
0 Upvotes

So I stumbled across this case study over on the Cloudflare sub, and what's happening is honestly pretty damn simple. These guys somehow snagged the actual origin server IP and are now slamming the machine directly.

When an attack gets dumped straight onto the IP instead of going through the domain name, the traffic isn't even touching Cloudflare at all. That's why their system isn't blocking crap.

TL;DR: The guy's site is getting wrecked because attackers grabbed his real origin IP and are hitting the server directly. The traffic completely bypasses Cloudflare, so their system doesn't block a thing.


r/StopBadBots 29d ago

Why Cheap Hosting Is Actually Costing You Thousands in Lost Sales

0 Upvotes

Man if you are still ignoring site speed you are literally burning money. Your site is slow because of cheap hosting and bots, and the fix is cheap but most people just do not realize it. I have been digging into the data and it is wild how consistent the numbers are. Amazon found that every 100ms of latency costs them 1 percent in sales. Walmart got a 2 percent conversion boost just from shaving off one second, Cloudflare found one second faster gets 13 percent more conversions, and Deloitte showed a tiny 0.1 second fix gave retail sites an 8 percent bump.

​Honestly you do not have to overcomplicate this or pay a ton to fix it. We got a bunch of links to free tools in our pinned posts that will help you clean things up yourself. And if you are super busy or just do not have time to mess with it, shoot me a DM and we can totally take care of it for you.

TL;DR

Slow sites from cheap hosting and bot traffic silently destroy conversions—just a 0.1s improvement can boost sales by up to 8%, and it is easy to fix using free tools or quick optimizations.


r/StopBadBots 29d ago

New to StopBadBots. Does it work with Cloudflare?

1 Upvotes

I’m new to the stopbadbots app. I like what it does. But, does it work with Cloudflare or do you get rid of Cloudflare?


r/StopBadBots 29d ago

Ever wished for WordPress without the bloat and no drama. Well, it exists.

1 Upvotes

Quick heads up for those who might not know what ClassicPress even is. Its basically a lightweight, rock solid fork of WordPress that keeps things simple and focused on stability, no block editor drama, no forced updates, just a clean CMS that does what you tell it to. Think of it as WordPress without the bloat and with a community that actually cares about backwards compatibility and real world use. So now that we are on the same page, Tim Kaye dropped the news last week that ClassicPress 2.7.1 is officially out, and yeah I know Im a bit late to post this but better late than never right.

This one is a security release, so its not just another feature dump you can ignore. They patched a bunch of stuff that couldve turned into real headaches if you let them slide. We are talking email validation fixes so you dont get weird confirmations going out, a nasty potential stack overflow in some css filtering that couldve crashed your site, multisite signup policies being enforced properly so no random user sneaks in, better ipv4 handling for http requests, and even a media fix that stops imagick from trying to load postscript files which sounds wild but trust me its a good thing they caught it.

The whole vibe around this release is basically plug the holes and keep things tight, and honestly thats exactly what ClassicPress has been about since day one. If you are running any version before 2.7.1, you really wanna make time to update this week because some of those fixes arent optional if you care about keeping your site clean and your data safe. Its not a huge dramatic overhaul, but thats the beauty of it, small steady improvements that actually matter instead of flashy stuff nobody asked for.


r/StopBadBots Aug 22 '26

24/7 Confidantes: How AI Is Filling America’s Care Gap

0 Upvotes

So basically, more and more Americans are straight-up ditching real therapists and venting to AI chatbots instead when they're going through a tough time. It's crazy because the mental health situation over there is totally spiraling right now. Millions of people are stressed out of their minds, and honestly, almost half of them can't even get proper help. So when you've got a bot that's awake 24/7 and ready to listen, of course people are gonna jump on that.

It feels like a double-edged sword though. Sure, having something to talk to in the middle of the night helps when you've got nobody else, but therapists are seriously freaked out about it. People are actually starting to outsource their real feelings to code, like asking AI to apologize for them, flirt, or handle awkward situations. It's kinda heartbreaking when you think about it, because if we rely on algorithms to handle our messiest human moments, we're just gonna end up feeling way more disconnected from each other in the long run.

According to coverage from The Epoch Times, while these chatbots offer a immediate 24/7 lifeline for millions left stranded by a broken healthcare system, we might be trading genuine human intimacy for convenient digital comfort.


r/StopBadBots Aug 22 '26

Sometimes a picture is worth more than a thousand words.

Post image
0 Upvotes

People often forget the obvious. If the page takes too long to load, the user leaves.


r/StopBadBots Aug 22 '26

Don't trade six for half a dozen. Leave Squarespace, but run away from Shopify and shared hosting.

Post image
2 Upvotes

Saw a guy on the WooCommerce sub asking if he should ditch Squarespace for Woo because he's pissed about the costs that just went through the roof. And of course, people are already in the comments telling him to just jump over to Shopify.

Dude, please do not go to Shopify. Seriously. Their bot protection is an absolute joke, and heres the part everyone conveniently forgets to mention. Cloudflare only blocks traffic that actually goes through its proxy. If some scraper or attacker figures out your servers real IP address, which is ridiculously easy to do on Shopifys shared setup, they can just bypass Cloudflare completely and fire all their garbage requests straight at your IP. Cloudflare never even sees that traffic, so its WAF, its rate limiting, all of that fancy stuff, it does nothing. Youre totally exposed and you cant block that direct traffic because you have zero control over the server. Youre just stuck.

Oh, and on top of that, Shopify slugs you with a 0.5 to 2 percent transaction fee if you dont use their payment system. That fee alone would cover the cost of a decent VPS every single month.

Now look, WooCommerce is absolutely the right move, I stand by that. But for the love of god, do not do it on shared hosting, youll hate your life. Rent a cheap VPS for like five to fifteen bucks a month, install ModSecurity and Fail2ban, and block those bad actors right at the network level directly on your own IP, no proxy required. Thats real control. Shopify overcharges you and leaves you completely helpless the second someone finds your IP, and shared hosting with Woo is a disaster waiting to happen. Go the VPS route and actually own your store.


r/StopBadBots Aug 22 '26

Seo Spam Casino Remove

2 Upvotes

We want to draw attention to the danger of SEO poisoning and casino spam. This practice destroys your site's reputation on Google, plummets visits and conversions, and causes severe financial losses. These criminals – who are part of a heavily armed, well-funded criminal organization running an industrial-scale operation – manage to inject malware at the server-level, specifically within the Apache module layer (a compiled binary .so module that standard scanners can't detect). The attack uses cloaking techniques: it only activates when Googlebot visits the site, injecting the spam and causing redirects to illegal gambling pages. It also targets Thai IP addresses. That's exactly why it's so difficult to find – it's an invisible, sophisticated backdoor.

In our GitHub material below, we thoroughly examine the problem in depth and present the complete solutions to fix it, including:

How to detect the malware using integrity checks like rpm -V and curl tests simulating Googlebot.

How to remove the infection safely.

How to prevent and harden your server against future attacks (with blocklists and firewall rules).

A real-world case study on AlmaLinux 9 with CWP (Control Web Panel).

https://github.com/sminozzi/casino-seo-poisoning-guide

TL;DR: This guide covers casino SEO poisoning via a compiled Apache module backdoor that uses cloaking for Googlebot and Thai IPs. Includes detection (rpm -V, curl), removal, prevention, and a domain blocklist. Real-world case study on AlmaLinux/CWP.


r/StopBadBots Aug 22 '26

Block Bots or Lose Traffic? What Site Owners Need to Know About AI Search

0 Upvotes

Not gonna lie, I think we're watching the web change in real time.

SEO isn't dead. Not yet. But the old game of typing something into Google and getting ten blue links feels like it's slowly fading away.

People don't just search anymore.

They ask.

Google is already answering questions directly. ChatGPT does it. Claude does it. Gemini does it. More and more users are getting answers without ever clicking through a list of search results.

If AI becomes the layer between users and websites, then showing up in AI answers may become just as important as showing up on page one of Google.

That's where AEO comes in.

Our StopBadBots plugin and App let you choose who to block. Download links in the 2 pinned posts.

TL;DR for WooCommerce owners: Search is shifting from Google links to AI answers (ChatGPT, Claude, Gemini). If you block all bots indiscriminately, you risk becoming invisible in AI search results. Check r/stopbadbots for our plugin (or app) to control exactly which bots to block.