Three quarters of my GA4 users were a bot in Singapore
In late September azmth had the biggest days in its history. Then I looked closer: three quarters of the visitors were a bot on a Chinese cloud network, posing as Chrome. How I spotted it, the real fans hiding underneath, and the firewall rule that stopped it without blocking Singapore.

If GA4 suddenly shows a wave of Singapore users with almost no engagement, one page view each and a 1280x1200 screen, it is very likely the bot traffic reported since September 2025. GA4's built-in bot filter misses it. You can hide it in reports, and if it loads your real pages, block it at your host's firewall.
On 28 September, azmth, my satellite tracker, had the biggest day in its history: 22,470 users. These days an ordinary day brings about two thousand. Then I opened the country report, and 17,052 of them were in Singapore.
So: a bot, or had azmth gone viral somewhere? Both, it turned out. The viral part was hiding underneath the bot.
How do you tell bot traffic from real visitors in GA4?
It took one comparison, Singapore against everyone else:
- Engagement: one second on average, against a minute and a half site-wide.
- Screen resolution: 81% of the Singapore visitors reported 1280x1200. Across the rest of the world, 56 people did.
- Pages: one each, spread across the whole site, then gone. The site as a whole averages almost six.
- Devices: 83% Windows 10, most of the rest an old version of macOS, and almost no phones.
- Source: all Direct, with no referrer at all.
The cleanest test came later, and it is the one I would start with now: bots only ever load the page. People click things.
All the numbers
| Day | Singapore | Everywhere else | Total |
|---|---|---|---|
| Sat 1 Aug | 80 | 560 | 640 |
| Sun 2 Aug | 30 | 440 | 470 |
| Mon 3 Aug | 50 | 570 | 620 |
| Tue 4 Aug | 50 | 1,140 | 1,190 |
| Wed 5 Aug | 80 | 1,250 | 1,330 |
| Thu 6 Aug | 140 | 1,250 | 1,390 |
| Fri 7 Aug | 80 | 800 | 880 |
| Sat 8 Aug | 70 | 990 | 1,060 |
| Sun 9 Aug | 40 | 950 | 990 |
| Mon 10 Aug | 90 | 1,250 | 1,340 |
| Tue 11 Aug | 30 | 1,570 | 1,600 |
| Wed 12 Aug | 80 | 3,320 | 3,400 |
| Thu 13 Aug | 70 | 1,270 | 1,340 |
| Fri 14 Aug | 50 | 700 | 750 |
| Sat 15 Aug | 40 | 870 | 910 |
| Sun 16 Aug | 40 | 700 | 740 |
| Mon 17 Aug | 80 | 680 | 760 |
| Tue 18 Aug | 20 | 780 | 800 |
| Wed 19 Aug | 60 | 810 | 870 |
| Thu 20 Aug | 30 | 830 | 860 |
| Fri 21 Aug | 40 | 690 | 730 |
| Sat 22 Aug | 60 | 1,300 | 1,360 |
| Sun 23 Aug | 60 | 2,110 | 2,170 |
| Mon 24 Aug | 50 | 1,410 | 1,460 |
| Tue 25 Aug | 50 | 2,140 | 2,190 |
| Wed 26 Aug | 60 | 1,600 | 1,660 |
| Thu 27 Aug | 40 | 1,720 | 1,760 |
| Fri 28 Aug | 60 | 1,220 | 1,280 |
| Sat 29 Aug | 50 | 1,060 | 1,110 |
| Sun 30 Aug | 60 | 980 | 1,040 |
| Mon 31 Aug | 10 | 1,060 | 1,070 |
| Tue 1 Sep | 100 | 940 | 1,040 |
| Wed 2 Sep | 80 | 1,360 | 1,440 |
| Thu 3 Sep | 80 | 1,150 | 1,230 |
| Fri 4 Sep | 40 | 1,130 | 1,170 |
| Sat 5 Sep | 90 | 1,080 | 1,170 |
| Sun 6 Sep | 100 | 1,580 | 1,680 |
| Mon 7 Sep | 80 | 1,320 | 1,400 |
| Tue 8 Sep | 80 | 1,490 | 1,570 |
| Wed 9 Sep | 170 | 5,290 | 5,460 |
| Thu 10 Sep | 230 | 2,790 | 3,020 |
| Fri 11 Sep | 130 | 1,840 | 1,970 |
| Sat 12 Sep | 80 | 1,580 | 1,660 |
| Sun 13 Sep | 190 | 1,740 | 1,930 |
| Mon 14 Sep | 130 | 2,700 | 2,830 |
| Tue 15 Sep | 170 | 2,840 | 3,010 |
| Wed 16 Sep | 150 | 5,750 | 5,900 |
| Thu 17 Sep | 380 | 3,010 | 3,390 |
| Fri 18 Sep | 430 | 2,420 | 2,850 |
| Sat 19 Sep | 410 | 2,180 | 2,590 |
| Sun 20 Sep | 560 | 2,500 | 3,060 |
| Mon 21 Sep | 570 | 2,310 | 2,880 |
| Tue 22 Sep | 270 | 1,920 | 2,190 |
| Wed 23 Sep | 430 | 1,920 | 2,350 |
| Thu 24 Sep | 760 | 2,160 | 2,920 |
| Fri 25 Sep | 470 | 1,700 | 2,170 |
| Sat 26 Sep | 960 | 1,800 | 2,760 |
| Sun 27 Sep | 1,600 | 1,970 | 3,570 |
| Mon 28 Sep | 17,050 | 5,420 | 22,470 |
| Tue 29 Sep | 17,230 | 4,620 | 21,850 |
| Wed 30 Sep | 5,450 | 3,300 | 8,750 |
| Thu 1 Oct | 70 | 2,670 | 2,740 |
| Fri 2 Oct | 60 | 1,940 | 2,000 |
| Sat 3 Oct | 40 | 2,790 | 2,830 |
| Sun 4 Oct | 60 | 2,480 | 2,540 |
| Mon 5 Oct | 50 | 2,300 | 2,350 |
The real people hiding under the bot
Hide Singapore and the chart shows three waves I had nearly missed. None of them were bots.
- Argentina, 8 to 10 September. About 4,200 people in three days, starting three days after I launched the Mars globe. They stayed almost three minutes on average, and 72% of them properly engaged.
- Indonesia, 15 to 18 September. Almost 6,000 people, 84% of them on phones and 87% engaged. My page titles started showing up in GA4 in Indonesian (“Pelacak Satelit”), because people were reading azmth through their browser's translation.
- Iran, 28 September, the same day as the biggest spike. In the space of half an hour, about 730 people opened the globe and clicked on satellites just over 4,700 times between them. A few were reading it in Persian.
I still don't know where any of them came from. GA4 files most of it under Direct, which is usually what you get when a link travels through WhatsApp, Telegram or a group chat. If that was you, thank you. While I was busy being annoyed at a bot in Singapore, you were the people actually using the thing.
What is the Singapore bot?
I am far from the first person to meet it. The floods of Direct visits from Singapore and from Lanzhou, in China, started in mid-September 2025, and by October GA4 users were comparing notes in a Google Analytics Community thread. It has come back in waves since, including in April and September 2026, and Search Engine Watch has written about its return in GA4's Singapore bot problem is back.
Google itself has said very little. The closest thing to an answer came in November 2025 from a volunteer Product Expert on its forum, relaying that Google's teams see it as non-human traffic that gets past GA4's standard filters, and that a longer-term fix was in development. Nobody has shown who runs it or why. The theory you see most is scraping for AI training, which is a guess, not a finding.
My hosting logs on Vercel told me more than GA4 could. In one day azmth served just over a million requests, and 651,000 of them, 61%, came from a single network: AS132203, Tencent Cloud. Almost every request came from a fresh 43.172.x.x address, claimed a different version of Chrome, and went straight for the satellite catalogue and the 3D models. That address block is registered to Tencent's company in Singapore, which is probably why GA4 put all of it in Singapore, even though some of those servers sit elsewhere. And these were not fake hits sent to Google. The bot loaded the real site, about 38 requests per “visitor”.
Can GA4 filters block the Singapore bot?
No, they can only hide it. GA4 already removes known bots, using Google's own research and the IAB's list of known spiders and bots. You can't switch that filter off or see how much it removes, and this bot gets straight past it. GA4's data filters only drop traffic by IP address, by developer flag or by hostname. This bot changed IP with almost every request, so an IP filter wide enough to catch it would also drop real visitors on the same cloud network, and data filters are permanent. It also loaded the real hostname.
What GA4 can do is hide it. Add a comparison or a report filter that excludes Screen resolution 1280x1200, or Country Singapore if you don't mind losing real Singaporeans too. In Explorations, a segment does the same job. None of this stops the bot. It still loads your pages, and the days it already visited stay polluted.
How I blocked it on Vercel without blocking Singapore
What pinned it down was the TLS handshake. Vercel's firewall shows a JA4 fingerprint for incoming traffic, and all 651,000 of those Tencent requests had the same one:
| The bot | TCP: t | TLS 1.3: 13 | domain: d | ciphers: 13 | extensions: 10 | ALPN: 00 | cipher hash: _f57a46bbacb6 | extension hash: _e7c285222651 |
|---|---|---|---|---|---|---|---|---|
| Chrome | TCP: t | TLS 1.3: 13 | domain: d | ciphers: 15 | extensions: 17 | ALPN: h2 | cipher hash: _8daaf6152771 | extension hash: _cb7bf5808d99 |
The part that matters is the 00. It means the bot offered no ALPN, the part of the handshake where a browser lists the protocols it speaks. No ALPN means no HTTP/2. Chrome puts h2 in that slot.
The rule pairs that fingerprint with the network:
Rule: Block Tencent Cloud scraper
If: AS Number equals 132203
and: JA4 Digest equals t13d131000_f57a46bbacb6_e7c285222651
Then: DenyWhy not block the whole network? Tencent Cloud rents servers to anyone, and as far as I know, servers like these are also a common place to run a personal VPN or proxy, including for people in China, where azmth has had readers since a Chinese tech site wrote about it. And why not block the fingerprint alone? Other software built on the same TLS library, set up the same way, could share it. Together, in my logs, they matched nothing but the bot.
I set the custom rule to Log first and watched it for a while. Every request it caught was the bot. Then I switched it to Deny. The next day, Singapore was back to a few dozen people a day, roughly what it had always had. And since May 2026, Vercel doesn't bill for requests its firewall denies, so the block costs nothing.
Quick answers
Why is my GA4 traffic from Singapore suddenly so high?
Usually a bot, not new fans. Compare Singapore with all users: about a second of engagement, a 1280x1200 screen resolution and Direct traffic with no referrer match the bot wave that began in September 2025. Real visitors scroll, click and stay.
Why does GA4 say the bot traffic comes from Singapore?
On my site the bot used 43.172.x.x addresses on Tencent Cloud (AS132203), a block registered to Tencent's company in Singapore. That is probably why GA4 places it there, although some of those servers are hosted elsewhere. Other sites report the same pattern labelled Lanzhou, China.
Does GA4 filter out bot traffic automatically?
Only known bots. GA4 always excludes traffic from bots identified by Google's own research and the IAB's International Spiders and Bots List, and you cannot switch that off or see how much it removes. This bot pretends to be Chrome, and it gets through.
Does the Singapore bot actually reach my website?
On azmth it did. Vercel's logs showed it loading real pages, the satellite catalogue and 3D models, about 38 requests per visitor. Some sites report hits sent straight to Google instead, so check your host's logs: if the requests are there, a firewall rule can stop them.
Should I block all traffic from Singapore?
No. A country block also shuts out real people in Singapore and anyone whose VPN exits there. Block the network the bot runs on together with its TLS fingerprint (JA4), so the rule is narrow enough to catch only the bot.
One more thing
Look at the bottom-left corner. When you arrived, this page filed you as a bot, because all you had done was load it. Scrolling doesn't change its mind, since bots scroll too. If it still thinks so, click anything. And if your screen happens to be exactly 1280 by 1200, it has a different message for you.