BlogSite notes9 October 20267 min read

Three quarters of my GA4 users were a bot in Singapore

In late September azmth had the biggest days in its history. Then I looked closer: three quarters of the visitors were a bot on a Chinese cloud network, posing as Chrome. How I spotted it, the real fans hiding underneath, and the firewall rule that stopped it without blocking Singapore.

Daily users on azmth from August to October 2026: a steady line, then a spike to 22,470 users on 28 September, 17,052 of them in Singapore, falling away after the bot was blocked on 30 September

If GA4 suddenly shows a wave of Singapore users with almost no engagement, one page view each and a 1280x1200 screen, it is very likely the bot traffic reported since September 2025. GA4's built-in bot filter misses it. You can hide it in reports, and if it loads your real pages, block it at your host's firewall.

On 28 September, azmth, my satellite tracker, had the biggest day in its history: 22,470 users. These days an ordinary day brings about two thousand. Then I opened the country report, and 17,052 of them were in Singapore.

So: a bot, or had azmth gone viral somewhere? Both, it turned out. The viral part was hiding underneath the bot.

How do you tell bot traffic from real visitors in GA4?

It took one comparison, Singapore against everyone else:

  • Engagement: one second on average, against a minute and a half site-wide.
  • Screen resolution: 81% of the Singapore visitors reported 1280x1200. Across the rest of the world, 56 people did.
  • Pages: one each, spread across the whole site, then gone. The site as a whole averages almost six.
  • Devices: 83% Windows 10, most of the rest an old version of macOS, and almost no phones.
  • Source: all Direct, with no referrer at all.

The cleanest test came later, and it is the one I would start with now: bots only ever load the page. People click things.

Daily users on azmth in GA4, 1 August to 5 October 2026, rounded to the nearest 10. Hide Singapore and the real waves come back.
All the numbers
DaySingaporeEverywhere elseTotal
Sat 1 Aug80560640
Sun 2 Aug30440470
Mon 3 Aug50570620
Tue 4 Aug501,1401,190
Wed 5 Aug801,2501,330
Thu 6 Aug1401,2501,390
Fri 7 Aug80800880
Sat 8 Aug709901,060
Sun 9 Aug40950990
Mon 10 Aug901,2501,340
Tue 11 Aug301,5701,600
Wed 12 Aug803,3203,400
Thu 13 Aug701,2701,340
Fri 14 Aug50700750
Sat 15 Aug40870910
Sun 16 Aug40700740
Mon 17 Aug80680760
Tue 18 Aug20780800
Wed 19 Aug60810870
Thu 20 Aug30830860
Fri 21 Aug40690730
Sat 22 Aug601,3001,360
Sun 23 Aug602,1102,170
Mon 24 Aug501,4101,460
Tue 25 Aug502,1402,190
Wed 26 Aug601,6001,660
Thu 27 Aug401,7201,760
Fri 28 Aug601,2201,280
Sat 29 Aug501,0601,110
Sun 30 Aug609801,040
Mon 31 Aug101,0601,070
Tue 1 Sep1009401,040
Wed 2 Sep801,3601,440
Thu 3 Sep801,1501,230
Fri 4 Sep401,1301,170
Sat 5 Sep901,0801,170
Sun 6 Sep1001,5801,680
Mon 7 Sep801,3201,400
Tue 8 Sep801,4901,570
Wed 9 Sep1705,2905,460
Thu 10 Sep2302,7903,020
Fri 11 Sep1301,8401,970
Sat 12 Sep801,5801,660
Sun 13 Sep1901,7401,930
Mon 14 Sep1302,7002,830
Tue 15 Sep1702,8403,010
Wed 16 Sep1505,7505,900
Thu 17 Sep3803,0103,390
Fri 18 Sep4302,4202,850
Sat 19 Sep4102,1802,590
Sun 20 Sep5602,5003,060
Mon 21 Sep5702,3102,880
Tue 22 Sep2701,9202,190
Wed 23 Sep4301,9202,350
Thu 24 Sep7602,1602,920
Fri 25 Sep4701,7002,170
Sat 26 Sep9601,8002,760
Sun 27 Sep1,6001,9703,570
Mon 28 Sep17,0505,42022,470
Tue 29 Sep17,2304,62021,850
Wed 30 Sep5,4503,3008,750
Thu 1 Oct702,6702,740
Fri 2 Oct601,9402,000
Sat 3 Oct402,7902,830
Sun 4 Oct602,4802,540
Mon 5 Oct502,3002,350

The real people hiding under the bot

Hide Singapore and the chart shows three waves I had nearly missed. None of them were bots.

  • Argentina, 8 to 10 September. About 4,200 people in three days, starting three days after I launched the Mars globe. They stayed almost three minutes on average, and 72% of them properly engaged.
  • Indonesia, 15 to 18 September. Almost 6,000 people, 84% of them on phones and 87% engaged. My page titles started showing up in GA4 in Indonesian (“Pelacak Satelit”), because people were reading azmth through their browser's translation.
  • Iran, 28 September, the same day as the biggest spike. In the space of half an hour, about 730 people opened the globe and clicked on satellites just over 4,700 times between them. A few were reading it in Persian.

I still don't know where any of them came from. GA4 files most of it under Direct, which is usually what you get when a link travels through WhatsApp, Telegram or a group chat. If that was you, thank you. While I was busy being annoyed at a bot in Singapore, you were the people actually using the thing.

What is the Singapore bot?

I am far from the first person to meet it. The floods of Direct visits from Singapore and from Lanzhou, in China, started in mid-September 2025, and by October GA4 users were comparing notes in a Google Analytics Community thread. It has come back in waves since, including in April and September 2026, and Search Engine Watch has written about its return in GA4's Singapore bot problem is back.

Google itself has said very little. The closest thing to an answer came in November 2025 from a volunteer Product Expert on its forum, relaying that Google's teams see it as non-human traffic that gets past GA4's standard filters, and that a longer-term fix was in development. Nobody has shown who runs it or why. The theory you see most is scraping for AI training, which is a guess, not a finding.

My hosting logs on Vercel told me more than GA4 could. In one day azmth served just over a million requests, and 651,000 of them, 61%, came from a single network: AS132203, Tencent Cloud. Almost every request came from a fresh 43.172.x.x address, claimed a different version of Chrome, and went straight for the satellite catalogue and the 3D models. That address block is registered to Tencent's company in Singapore, which is probably why GA4 put all of it in Singapore, even though some of those servers sit elsewhere. And these were not fake hits sent to Google. The bot loaded the real site, about 38 requests per “visitor”.

Can GA4 filters block the Singapore bot?

No, they can only hide it. GA4 already removes known bots, using Google's own research and the IAB's list of known spiders and bots. You can't switch that filter off or see how much it removes, and this bot gets straight past it. GA4's data filters only drop traffic by IP address, by developer flag or by hostname. This bot changed IP with almost every request, so an IP filter wide enough to catch it would also drop real visitors on the same cloud network, and data filters are permanent. It also loaded the real hostname.

What GA4 can do is hide it. Add a comparison or a report filter that excludes Screen resolution 1280x1200, or Country Singapore if you don't mind losing real Singaporeans too. In Explorations, a segment does the same job. None of this stops the bot. It still loads your pages, and the days it already visited stay polluted.

How I blocked it on Vercel without blocking Singapore

What pinned it down was the TLS handshake. Vercel's firewall shows a JA4 fingerprint for incoming traffic, and all 651,000 of those Tencent requests had the same one:

JA4 fingerprint of the bot and of Chrome, field by field
The botTCP: tTLS 1.3: 13domain: dciphers: 13extensions: 10ALPN: 00cipher hash: _f57a46bbacb6extension hash: _e7c285222651
ChromeTCP: tTLS 1.3: 13domain: dciphers: 15extensions: 17ALPN: h2cipher hash: _8daaf6152771extension hash: _cb7bf5808d99
Two JA4 fingerprints, read field by field. Chrome's is the example FoxIO publishes. The column that matters is ALPN.

The part that matters is the 00. It means the bot offered no ALPN, the part of the handshake where a browser lists the protocols it speaks. No ALPN means no HTTP/2. Chrome puts h2 in that slot.

The rule pairs that fingerprint with the network:

Rule:  Block Tencent Cloud scraper
If:    AS Number   equals  132203
and:   JA4 Digest  equals  t13d131000_f57a46bbacb6_e7c285222651
Then:  Deny

Why not block the whole network? Tencent Cloud rents servers to anyone, and as far as I know, servers like these are also a common place to run a personal VPN or proxy, including for people in China, where azmth has had readers since a Chinese tech site wrote about it. And why not block the fingerprint alone? Other software built on the same TLS library, set up the same way, could share it. Together, in my logs, they matched nothing but the bot.

I set the custom rule to Log first and watched it for a while. Every request it caught was the bot. Then I switched it to Deny. The next day, Singapore was back to a few dozen people a day, roughly what it had always had. And since May 2026, Vercel doesn't bill for requests its firewall denies, so the block costs nothing.

Quick answers

Why is my GA4 traffic from Singapore suddenly so high?

Usually a bot, not new fans. Compare Singapore with all users: about a second of engagement, a 1280x1200 screen resolution and Direct traffic with no referrer match the bot wave that began in September 2025. Real visitors scroll, click and stay.

Why does GA4 say the bot traffic comes from Singapore?

On my site the bot used 43.172.x.x addresses on Tencent Cloud (AS132203), a block registered to Tencent's company in Singapore. That is probably why GA4 places it there, although some of those servers are hosted elsewhere. Other sites report the same pattern labelled Lanzhou, China.

Does GA4 filter out bot traffic automatically?

Only known bots. GA4 always excludes traffic from bots identified by Google's own research and the IAB's International Spiders and Bots List, and you cannot switch that off or see how much it removes. This bot pretends to be Chrome, and it gets through.

Does the Singapore bot actually reach my website?

On azmth it did. Vercel's logs showed it loading real pages, the satellite catalogue and 3D models, about 38 requests per visitor. Some sites report hits sent straight to Google instead, so check your host's logs: if the requests are there, a firewall rule can stop them.

Should I block all traffic from Singapore?

No. A country block also shuts out real people in Singapore and anyone whose VPN exits there. Block the network the bot runs on together with its TLS fingerprint (JA4), so the rule is narrow enough to catch only the bot.

One more thing

Look at the bottom-left corner. When you arrived, this page filed you as a bot, because all you had done was load it. Scrolling doesn't change its mind, since bots scroll too. If it still thinks so, click anything. And if your screen happens to be exactly 1280 by 1200, it has a different message for you.

You, according to GA4Botpage_view only, 0 clicks