For years, security researchers and federal agencies have sounded the alarm over the hidden risks associated with generic, bargain-priced TV streaming boxes. These devices are frequently marketed online as a convenient, budget-friendly shortcut to unlimited entertainment, promising access to a wide array of live broadcasts and on-demand streaming services for a single, low upfront fee. However, beneath the promise of free content lies a darker reality. Security experts have repeatedly warned that these unverified hardware units secretly commandeer and monetize the user’s home internet connection, renting out household bandwidth to anonymous strangers. Now, groundbreaking new analysis reveals that the threat posed by these streaming devices goes far beyond simple proxy relaying. A comprehensive investigation shows that these gadgets routinely spoof their hardware profiles to masquerade as mobile phones, silently clicking on advertisements across artificial intelligence-generated websites as part of a sprawling, highly lucrative international ad fraud operation.
Pedro Falé, a threat intelligence researcher with the security firm Bitsight, recently uncovered the true scale of this complex ad fraud infrastructure. Falé detailed how he gained unprecedented visibility into the inner workings of the network by registering an expired domain name that had previously been utilized to coordinate fake ad clicks across a particularly popular brand of streaming sticks known as H96. These inexpensive Android-based boxes are widely distributed through major global e-commerce platforms, including Amazon, Best Buy, and Newegg, often promoted aggressively by online influencers targeting consumers eager to bypass traditional subscription fees.
Upon taking control of the expired domain, which had historically served as a telemetry collection point for tens of thousands of H96 streaming sticks plugged into television sets around the globe, Falé expected to analyze routine diagnostic data. Instead, a deep inspection of the incoming traffic revealed an alarming anomaly. The infrastructure was collecting comprehensive hardware information and app inventories from the connected TV boxes, but the devices themselves were reporting device profiles that flatly contradicted their physical nature. Nearly all of the streaming television boxes transmitting data to the telemetry servers claimed to be mobile phone models manufactured by prominent global brands, including Samsung, Vivo, Huawei, and Xiaomi.
The researcher noted that multiple devices connecting to the factory Android TV box backdoor were explicitly identifying themselves as cellular smartphones rather than stationary media players. Further investigation into the software running on these units revealed that all of the compromised devices shared the exact same two pre-installed applications. These rogue programs were traced back to a corporate entity known as Zhejiang Fengwo IoT Technology Ltd, a mainland China-based enterprise established in 2019 that operates a broad portfolio of ad-publishing and software ventures under the collective banner of Fengwo Group. A deeper probe into the corporate footprint of the Fengwo Group confirmed that the entity had registered multiple technological patents matching the exact operational mechanics observed within the pre-installed streaming box apps.

According to Bitsight’s formal findings, researchers utilized their internal threat intelligence tracking systems to trace the monetization of the operation back through a web of shell identities located in Hong Kong, Singapore, and single-person legal entities. Ultimately, the trail led directly to Zhejiang Fengwo IoT Technology Co., Ltd. The analysis demonstrated that the embedded applications function to coordinate a sophisticated ad fraud network, utilizing the captive traffic source of tens of thousands of H96 streaming devices to simulate authentic user engagement with ads hosted on a vast network of AI-generated websites operated by the Fengwo Group.
Bitsight’s investigation into these destination websites revealed that they consist largely of machine-generated news articles, blog posts, and digital graphics spanning a diverse range of topical categories. These include finance, health, education, gaming, music, and food blogs. Crucially, researchers discovered that none of these sham websites displayed advertisements unless the visiting browser or device profile matched the spoofed mobile phone identity broadcasted by the H96 streaming boxes, confirming a targeted and calculated approach to evading detection by automated security filters deployed by advertising networks.
AI DIGITAL HUMANS AND AUTOMATED FRAUD OPERATIONS
The primary web domain utilized by the Fengwo Group—fwgcloud.com—publicly proclaims that the enterprise is actively redefining the boundaries of human-artificial intelligence interaction. The corporate website claims to have successfully created and deployed more than 120,000 artificial intelligence digital humans available for commercial rental, pitching these virtual entities for applications ranging from emotional companionship to round-the-clock customer service and creative design work. However, security analysts view these grandiose claims with a heavy degree of skepticism, considering them potentially clever marketing facades designed to obscure the true nature of the company’s illicit digital infrastructure.
Falé noted that the core domain for the Fengwo Group shared critical Secure Sockets Layer certificate data with several other domains directly associated with the fraudulent applications discovered on the H96 streaming sticks, providing an undeniable technical link to the mobile phone spoofing mechanism. Furthermore, the researchers uncovered an internal wiki platform hosted on the corporate infrastructure that explicitly connected the Fengwo Group to a proprietary implementation of Blockly, a Google-built visual programming language originally designed as an educational tool to help children learn the fundamentals of software coding.

According to Bitsight’s report, employees and operators within the Fengwo Group utilized the Blockly interface to construct and manage their network of sham websites and automated execution routines. This visual programming environment allowed low-skilled operators to drag pre-built blocks of code together within a centralized editor, eliminating the need for workers to possess a deep understanding of the underlying technical code or execution architecture. Once a routine was finalized within the Blockly workspace, it was automatically exported as JavaScript and deployed to scalable cloud storage buckets.
Internal commentary uncovered by security researchers highlighted the strategic value of this workflow. One of the Fengwo Group application developers explicitly remarked that the system required only a small cadre of highly skilled developers to build the initial template execution-unit images. Meanwhile, lower-skilled operators could easily generate operational tasks using those templates, significantly lowering the technical requirements for day-to-day work and drastically reducing the enterprise’s operational overhead and labor costs.
When an individual user’s H96 streaming stick is selected by the control servers to execute a specific fraud task, the device is quietly pushed the appropriate Blockly module. This injected code can execute a variety of automated behaviors, including silently launching a background web browser, navigating to designated web pages, managing multiple active browser tabs, and generating authentic-looking mouse movements or screen touches to click on targeted advertisements. To ensure that the streaming boxes masquerading as mobile phones can successfully interact with these digital ads without raising algorithmic red flags, the Fengwo Group architecture integrates advanced vision and reasoning systems into a unified interface, empowering the automated bots to accurately identify advertising elements on a webpage and navigate the digital environment with human-like precision.
TV ON? PROXY. TV OFF? AD FRAUD
One of the more revealing technical discoveries made by Bitsight researchers involves the operational scheduling of the compromised H96 streaming devices. The analysis demonstrated that the hardware units seamlessly alternated between two distinct malicious functions, acting either as residential proxy relays or participating in active ad fraud routines, but never performing both operations simultaneously. Specifically, researchers concluded that when these TV streaming boxes detect an active high-definition multimedia interface signal originating from a connected television set—signalling that the human owner intends to watch video content or stream media—the device temporarily halts its background monetization tasks and functions strictly as a residential proxy.

Conversely, once the television is powered down or left idle, the streaming box immediately switches its operational mode back to awaiting ad fraud assignments. Falé explained that this deliberate separation of duties is likely engineered because the ad fraud activities are significantly more resource-intensive and processor-heavy, meaning continuous execution while the user is actively streaming video would noticeably degrade device performance, cause playback buffering, and ultimately alert the owner that something was amiss.
Despite repeated, formal warnings issued by federal law enforcement agencies, including the Federal Bureau of Investigation, regarding the inherent privacy and security hazards of utilizing unverified streaming hardware, major international e-commerce marketplaces continue to list and sell hundreds of distinct brands and models. These devices frequently bundle unofficial, modified versions of Google’s Android operating system and are heavily promoted across social media channels as an economical backdoor to subscription-based entertainment.
Beyond their enrollment in automated ad fraud botnets, these inexpensive generic TV boxes almost universally arrive with residential proxy software pre-installed directly into the system firmware. This software surreptitiously rents out the consumer’s home internet protocol address to anonymous, paying third-party clients. These buyers span a diverse spectrum of malicious or disruptive actors, ranging from aggressive corporate data-scraping operations and automated ticket scalpers to malicious cybercrime syndicates seeking a clean residential IP address to obfuscate their illicit digital footprints.
Because these mass-produced streaming sticks are routinely manufactured with minimal security controls, lack basic device authentication protocols, and are rarely updated with security patches, integrating one into a residential or office network exposes the entire local environment to severe risks. Earlier in the year, proxy tracking and threat intelligence service Synthient documented how multiple sophisticated botnets rapidly enslaved millions of insecure TV boxes by exploiting complex chains of vulnerabilities embedded within both the pre-installed proxy applications and the core operating system firmware of the streaming devices.

FINANCIAL SCALE AND CONSUMER PROTECTION
Bitsight estimated the global scope of this specific operation by tracking approximately 38,000 distinct TV streaming boxes phoning home to the expired Fengwo Group domain. Based solely on that conservative telemetry sample, researchers calculated that the ad fraud network generates estimated revenues approaching $50,000 every single day, a figure that excludes the substantial secondary income generated through the simultaneous leasing of residential proxy bandwidth. Falé emphasized that these financial projections are highly conservative, as they rely entirely on data collected from just one core and relatively aging domain belonging to the Fengwo Group infrastructure.
Efforts by security researchers and journalists to obtain formal comments from the operating entities have proven difficult. When inquiries were sent to the primary corporate contact address listed on the Fengwo Group’s public homepage, the electronic mail messages were immediately rejected by automated mail servers with delivery failure notices indicating that the designated inbox was completely full or receiving an overwhelming volume of incoming traffic.
Security authorities and industry analysts reiterate that consumers looking to purchase streaming hardware should exclusively invest in recognized name-brand devices manufactured by reputable, established technology companies. Furthermore, users are advised to exercise extreme caution regarding the installation of unverified third-party applications, as many auxiliary apps available for smart televisions and streaming boxes have likewise been found to bundle hidden residential proxy utilities. Google maintains that consumers can easily verify whether a specific device operates on the official, secure Android TV operating system equipped with Google Play Protect certification by consulting official verification guidelines.
Additionally, specialized threat intelligence organizations like Synthient maintain public, continuously updated repositories documenting specific internet-of-things hardware products known to ship with pre-installed proxy software and malicious payloads. As federal security warnings have repeatedly emphasized, this embedded proxy threat extends beyond television streaming sticks to impact a wide variety of popular consumer electronic devices found in modern households, most notably connected digital photo frames and smart home accessories.
Leave a Reply