An ampersandbot is bot which automatically edits MediaWiki pages and, for reasons unknown, deletes all contents starting with the first ampersand character (&). It may be that these bots are pre-testing MediaWiki sites to see if they are freely editable, in which case other bots will later try to post wikispam on sites tagged as vulnerable, but this is sheer conjecture at this point.

The ampersandbots generally come from different IP addresses each time, indicating that they are operated by a user of at least moderate sophistication who is familiar either with anonymization services or else has access to a collection of zombie PCs.


The latest version of SpamFerret performs basic ampersandbot prevention; development is in progress.