Automated scalper bots are overwhelming online DDR5 memory listings as supply shortages and rising prices intensify competition for inventory. DataDome research cited across the reports said one unnamed retailer saw 91% of traffic to DDR5 product pages come from bad bots, with bot activity now outnumbering human shoppers by roughly 10 to 1, up from about 6 to 1 in earlier measurements across multiple e-commerce sites.
The traffic appears designed to monitor stock and pricing at high frequency so operators can reserve or buy scarce memory before legitimate customers. Researchers said the bots repeatedly polled dozens of DDR5 listings every few seconds, including cache-busting requests that hit pages about every 6.5 seconds, while market pressure pushed some 32GB kits from $72 to $392 and broader DDR5 pricing up sharply. The reports link the sustained bot pressure to ongoing DRAM scarcity, retailer anti-scalping efforts, and demand dynamics expected to keep supply constrained into 2027.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
In March, DataDome published research showing bad bots outpaced legitimate traffic on DDR5 product pages by roughly 6 to 1 across several e-commerce sites. The research also documented a single bot operation that generated more than 10 million blocked requests.
Jérôme Segura disclosed that 91% of traffic hitting one unnamed retailer's DDR5 RAM product pages was bad bots, with newer measurements putting the bot-to-human ratio at roughly 10 to 1. DataDome's cited sample showed 91 DDR5 listings being polled about 551 times each in one hour, or roughly once every 6.5 seconds per listing, using cache-busting parameters.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.