When Fake Humans Attack: How BotID Caught a Brand-New Botnet
On October 29 at 9:44am, BotID Deep Analysis flagged a sudden surge in traffic across one customer's project. Volume jumped 500% above normal baseline. The strange part wasn't the size of the spike — it was that the traffic looked completely human.
Vercel's team started investigating and reached out to the customer about what appeared to be bot traffic masquerading as real users. Before that conversation could finish, Deep Analysis — powered by Kasada's machine learning backend — had already identified the threat and adjusted its classification on its own.
A First-Ever Bot Network, Disguised as Real Users
The incident looked like a brand-new browser bot network spinning up for the first time. These weren't typical scrapers. They were sophisticated actors generating telemetry that appeared entirely legitimate. Around 40-45 fresh browser profiles appeared, each with fingerprints and behavioral patterns never seen before.
For a few minutes, BotID's models analyzed the new data, weighing whether these sessions were genuine or malicious. That evaluation window is exactly where advanced bot networks slip past traditional defenses. They look real because they rely on real browser automation tools and carefully crafted profiles.
The Pattern That Gave Them Away
Then the telltale pattern surfaced. These seemingly legitimate browser sessions started appearing across a broad range of IP addresses. Critically, those IPs were identified as proxy nodes, not network origin points. Legitimate users don't rapidly cycle through proxy networks while keeping the same browser profile.
Deep Analysis connected the dots: the same browser fingerprints showing up across multiple proxy nodes indicated coordinated bot activity, not organic behavior. Once the pattern was detected, the system automatically forced these sessions back through the verification process to collect fresh browser telemetry.
From Detection to Blocking in Under 10 Minutes
The second round of telemetry collection, now informed by the proxy node detection and behavioral analysis, exposed the sessions' true nature. What had initially looked human was now confirmed malicious — a coordinated bot network attempting to evade detection.
Here's how the incident unfolded:
- 9:44am: Traffic spike detected, still classified as human
- 9:45–9:48am: Models analyze 40-45 new browser profiles making thousands of requests across proxy nodes
- 9:48am: Pattern correlation identifies coordinated bot activity
- 9:49am: Re-verification confirms threat, bot classification begins
- 9:54am: Attack traffic drops to zero
The entire sequence — detection, accurate classification, and blocking — took only a few minutes. No manual intervention. No emergency patches or rule updates. The customer took no action. BotID learned, adapted, and protected in real time.
Why Adaptive Detection Is the Only Defense
This incident illustrates the core value of machine learning-based bot detection. These bots were engineered specifically to bypass conventional defenses: real browser automation, legitimate-looking telemetry, and carefully constructed profiles that mimic organic behavior.
Standard bot detection handles the vast majority of threats effectively. But sophisticated attacks force a tradeoff: aggressive blocking risks false positives against legitimate users, while permissive rules let advanced bots through.
Deep Analysis exists for those edge cases where attackers invest heavily in evasion. By combining browser telemetry, network patterns, behavioral analysis, and real-time learning, it identifies coordination patterns that individual signals miss. The critical evidence wasn't any single red flag — it was the correlation. Identical browser fingerprints cycling through proxy infrastructure.
As bot networks grow more sophisticated, the only effective defense is a system that can learn and adapt just as fast. That Wednesday morning proved BotID does exactly that.



