Skip to content
CYBERSECURITY & DATA PRIVACY

Cheap Android TV Boxes Secretly Spoof Smartphones in Massive AI-Powered Ad Fraud Operation

Security researchers have been sounding the alarm for years regarding the hidden dangers of using generic, off-brand TV streaming boxes that promise unlimited content streaming for a low, one-time fee. While previous warnings focused on how these devices secretly rent out unsuspecting users’ internet connections to anonymous strangers as residential proxies, a groundbreaking new threat analysis reveals an even more insidious secondary operation. According to security firm Bitsight, these popular streaming sticks routinely spoof themselves as mobile phones, silently clicking on ads across automated, AI-generated websites as part of a sprawling, highly coordinated campaign designed to defraud online merchants and major advertising networks.

Pedro Falé, a threat researcher with Bitsight, uncovered the inner workings of this complex ad fraud network entirely by accident after registering an expired domain name. The domain had previously been used for telemetry, periodically collecting comprehensive hardware information and the complete list of installed applications from tens of thousands of popular "H96" brand streaming sticks plugged into television sets across the globe. By analyzing the traffic being funneled to this reclaimed infrastructure, Falé made a startling discovery: nearly all of the TV boxes communicating with the domain were transmitting data claiming to originate from mobile phone models manufactured by prominent brands, including Samsung, Vivo, Huawei, and Xiaomi.

"We noticed something was wildly wrong," Falé said in an interview. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Further investigation into the applications responsible for this behavior revealed a distinct pattern. Every single device reported having the exact same two apps installed, both developed by a mainland Chinese entity founded in 2019 known as Zhejiang Fengwo IoT Technology Ltd, which operates an extensive portfolio of ad-publishing networks under the umbrella of the Fengwo Group. Additional scrutiny by Bitsight uncovered multiple patents registered to the Fengwo Group that directly matched the operational architecture and inner workings of these pre-installed applications.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Bitsight’s threat intelligence platform traced the monetization streams of the operation through a web of shell identities established in Hong Kong, Singapore, and various individual holdings before ultimately linking the entire infrastructure back to Zhejiang Fengwo IoT Technology Co., Ltd. According to Bitsight’s published research report, the malicious applications serve to coordinate a sophisticated ad fraud network that leverages captive H96 streaming devices as an automated traffic source. These devices are commanded to visit and interact with a vast network of AI-generated websites operated by the Fengwo Group, artificially inflating metrics and generating fraudulent advertising revenue.

The investigation revealed that these AI-generated websites feature machine-generated news articles, graphics, and content spanning a wide variety of standard categories, including finance, health, education, gaming, music, and food blogs. However, a telling detail uncovered by researchers was that none of these websites displayed advertisements unless the visiting device successfully matched the spoofed mobile profile associated with the compromised H96 streaming sticks.

AI Digital Humans and Automated Workflows

The primary domain for the Fengwo Group, fwgcloud.com, presents a sophisticated public facade, claiming that the enterprise is "redefining the boundaries of human-AI interaction." The site boasts that the company has created more than 120,000 "AI digital humans" available to rent for a multitude of purposes, ranging from emotional companionship and 24/7 customer service to creative design applications.

However, technical analysis by Bitsight revealed a starkly different reality behind the corporate marketing. The Fengwo Group domain shared SSL certificate data with other domains directly associated with the malicious applications found on the H96 devices, specifically tying them to the mobile phone spoofing mechanism. Furthermore, internal wiki platforms discovered on the domain directly linked the Fengwo Group to a proprietary implementation of Blockly, an open-source visual programming language originally created by Google to help children learn the basics of software development through drag-and-drop code blocks.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

According to Bitsight, the Fengwo Group’s operators utilize Blockly to construct their network of sham websites and ad-fraud routines. This modular approach allows low-skilled operators to drag blocks of code together within the editor to define specific fraud routines based on designated task types, eliminating the need for operators to understand the underlying mechanics of the code. Once a routine is saved, it is automatically exported as JavaScript and deployed to cloud storage buckets.

A statement from one of the Fengwo Group app developers, uncovered during the research, explicitly highlighted the cost-effectiveness and operational efficiency of this setup. The developer noted that only a small team of highly skilled programmers is required to build the foundational template execution-unit images, while lower-skilled operators can create individual execution units from those templates with minimal technical training, drastically reducing the organization’s operating costs.

When an H96 streaming stick is selected for a specific fraud task, it receives the appropriate Blockly module from the command infrastructure. This module can silently launch a web browser in the background, navigate to designated websites, browse pages, manage browser tabs, and execute clicks on targeted advertisements. To ensure these modified TV boxes can reliably interact with ads on the AI-generated sites without triggering bot detection filters, the Fengwo Group integrates advanced vision and reasoning systems into a single interface. This allows the automated scripts to accurately identify advertisements on a webpage and navigate the site with human-like behavior patterns.

TV On: Proxy. TV Off: Ad Fraud

One of the most revealing discoveries made by Bitsight researchers involves the operational scheduling of the compromised H96 devices. The analysis determined that the streaming sticks either function as residential proxies or participate in ad fraud, but they never perform both tasks simultaneously. Specifically, when these TV boxes detect an active HDMI signal from a connected television—indicating that the user has turned on the TV and intends to watch video content—the device shifts its primary function to operating as a residential proxy. Conversely, when the television is turned off, the box immediately switches back to awaiting ad fraud assignments.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Researchers believe this division of labor is intentional. Ad fraud activities are resource-intensive and could easily degrade network performance, consume excessive processing power, or interfere with the device’s primary marketed purpose of streaming video content over the internet, which would likely alert unsuspecting users to compromised hardware.

Despite persistent warnings issued by the Federal Bureau of Investigation and cybersecurity industry leaders regarding the severe privacy and security risks associated with generic streaming devices, major e-commerce platforms continue to distribute hundreds of unverified models. Retailers such as Amazon, Best Buy, and Newegg routinely list devices that bundle unofficial, modified versions of Google’s Android operating system. These products are frequently promoted through online influencers as affordable alternatives that allow users to bypass subscription fees and access a vast array of streaming services and live broadcasts.

In addition to driving ad fraud networks, these inexpensive off-brand streaming boxes almost universally arrive with residential proxy software pre-installed. This software covertly rents out the homeowner’s residential internet IP address to anonymous third-party buyers, whose activities range from aggressive web scraping and ticket scalping to sophisticated cybercrime. Furthermore, because these budget devices are chronically insecure by design and lack basic authentication protocols, connecting one to a home or office network creates a significant vulnerability. Earlier this year, proxy tracking firm Synthient documented how aggressive botnets rapidly enslaved millions of similar TV boxes by exploiting a complex web of security flaws embedded within both the pre-installed residential proxy software and the underlying device firmware.

Scale and Financial Impact

Bitsight tracked approximately 38,000 individual TV boxes globally communicating with the expired Fengwo Group domain. Based on this telemetry sample alone, researchers estimate that this specific ad fraud network generates close to $50,000 a day in revenue, a figure that excludes the substantial earnings generated from the residential proxy side of the business. Falé emphasized that these financial and numerical estimates are highly conservative, as they are derived from telemetry data associated with just a single, older core domain operated by the Fengwo Group.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Regarding the Fengwo Group’s public claims of managing 120,000 "digital humans," Bitsight’s report concludes that the figure may serve as an elaborate marketing cover story designed to obscure the company’s true illicit operations and deflect regulatory suspicion. Historically, operators of large-scale botnets and proxy services frequently employ inconspicuous corporate facades to mask the true scale of their infrastructure.

Efforts by security researchers and journalists to contact the Fengwo Group for comment yielded no response. Inquiries sent to the official contact address listed on the company’s homepage were immediately rejected by mail delivery servers, returning automated failure notifications indicating that the inbox was either completely full or overwhelmed with incoming mail.

Security analysts emphasize that consumers seeking a reliable streaming experience should exclusively purchase name-brand hardware from reputable manufacturers and exercise caution when installing third-party applications, as even legitimate-seeming apps can occasionally bundle residential proxy software. Google advises consumers to verify whether a device runs the official Android TV operating system and features verified Play Protect certification. Additionally, organizations like Synthient maintain public databases cataloging IoT hardware known to ship with pre-installed proxy software and malicious payloads, highlighting that similar risks extend beyond streaming sticks to other connected consumer electronics such as digital photo frames.

Leave a Reply

Your email address will not be published. Required fields are marked *