Attackers have been tampering with SSL/TLS signatures at a scale never before seen using a technique called cipher-stunting. The technique helps malicious bot activity masquerade as live human traffic on the web. The idea is to avoid the web client fingerprinting technologies that help security tools and human analysts to differentiate between legitimate clients and impersonators/bots. In fact, Akamai said that activity has ramped up to the tune of 1,355,334,179 billion instances of tampering as of the end of February 2019.
Source: https://threatpost.com/billions-bots-cipher-stunting/144763/

