Skip to content
CYBERSECURITY & DATA PRIVACY

Cheap Android TV Boxes Are Secretly Spoofing Mobile Phones in a Massive Global Ad Fraud Scheme

Security researchers have been sounding the alarm for years about the hidden dangers of using generic, off-brand TV streaming boxes. These inexpensive devices often lure consumers in with the promise of unlimited content streaming and live television for a single, low, one-time fee. Beneath the surface, however, security experts have repeatedly warned that these gadgets secretly commandeer and rent out the user’s home internet connection to anonymous strangers as residential proxies. Now, a groundbreaking and comprehensive new analysis reveals that these pervasive devices are involved in an even more sophisticated and sprawling criminal enterprise. According to threat intelligence experts, these streaming sticks routinely spoof themselves as high-end mobile phones, automatically clicking on ads hosted on AI-generated websites as part of a massive international operation designed to defraud online merchants and digital advertising networks.

Pedro Falé, a threat researcher with the cybersecurity firm Bitsight, recently uncovered the inner workings of this vast and complex ad fraud network. His discovery began when he registered an expired domain name that had previously been utilized to coordinate fake ad clicks across a particularly popular brand of streaming hardware known on the market as H96. Falé explained to security journalist Brian Krebs that securing this domain provided a rare window into the telemetry data flowing from tens of thousands of these devices plugged into television sets located in homes and offices all over the world.

Upon inspecting the inbound traffic being funneled toward the domain, Falé made a startling realization. The domain had originally been configured for telemetry, periodically collecting complete hardware profiles and exhaustive lists of installed applications from the streaming sticks. However, nearly all of the TV boxes transmitting data to the server were claiming to be mobile phone models from major manufacturers such as Samsung, Vivo, Huawei, and Xiaomi.

"We noticed something was wildly wrong," Falé said, highlighting the glaring discrepancy between the physical hardware reporting the data and the device signatures it was broadcasting. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Upon diving deeper into the telemetry data, the researcher discovered a common thread uniting all of the compromised devices. Every single one of the reporting units contained the exact same two applications pre-installed on the system. Further analysis revealed that these specific applications were developed and maintained by an entity known as Zhejiang Fengwo IoT Technology Ltd., a company founded in 2019 in mainland China that operates a portfolio of ad-publishing networks under the banner of the Fengwo Group. Subsequent investigations into the corporate structure of the Fengwo Group showed that the entity has registered multiple software patents whose inner mechanics match the exact operational behavior observed within the applications found on the streaming sticks.

Bitsight’s threat intelligence division, known as TRACE, was able to trace the monetization pipeline back through a complex web of shell identities operating out of Hong Kong, Singapore, and various individual legal entities. Ultimately, the trail led squarely back to the mainland Chinese enterprise, Zhejiang Fengwo IoT Technology Co., Ltd. According to the published research findings, these embedded applications help coordinate a sprawling ad fraud network that leverages the global fleet of H96 devices as a captive, automated traffic source designed to visit and interact with advertisements hosted on a network of artificial intelligence-generated websites operated directly by the Fengwo Group.

Bitsight’s investigation into these destination websites revealed that they are entirely machine-generated, featuring automated news articles, blog posts, and digital graphics spanning a wide variety of topics, including finance, health, education, gaming, music, and food blogs. Crucially, the researchers observed that none of these websites displayed advertisements unless the visiting device successfully matched the spoofed mobile profile associated with the compromised H96 streaming boxes, revealing a tightly controlled and highly targeted ad fraud mechanism.

AI Digital Humans and Low-Skilled Operations

The primary domain utilized by the Fengwo Group, operating under the web address fwgcloud[.]com, publicly claims that the enterprise is "redefining the boundaries of human-AI interaction." The company’s promotional materials assert that it has successfully created more than 120,000 "AI digital humans" that are purportedly available to rent for a wide array of applications, ranging from emotional companionship and 24-hour customer service to creative design tasks.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

However, Falé and his colleagues at Bitsight discovered that the Fengwo Group’s infrastructure shared critical SSL certificate data with other domains directly associated with the fraudulent applications discovered on the H96 devices, specifically linking them to the mobile phone spoofing mechanism. Furthermore, internal wiki platforms hosted on the corporate domains directly tied the Fengwo Group to a proprietary implementation of Blockly, a Google-built visual programming language that was originally designed to help children learn the foundational concepts of software development.

According to Bitsight, employees and operators within the Fengwo Group utilize Blockly to construct their network of sham websites and ad-clicking routines. This intuitive visual interface allows low-skilled operators to simply drag and drop blocks of code together within a web-based editor, entirely eliminating the need for them to understand the underlying technical mechanics of how the code actually functions. Once a routine is assembled and saved within the visual editor, the system automatically exports the workflow as JavaScript code and uploads it to cloud storage buckets for rapid deployment.

"An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type," the Bitsight report details. "Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use."

The operational advantages of this approach were even discussed openly by Fengwo Group app developers in internal communications discovered by researchers. One developer explicitly remarked that only a small number of highly skilled programmers are required to build the foundational template execution-unit images, while everyday operators who create specific execution units from those templates face significantly lower technical requirements. This streamlined approach allows the enterprise to drastically minimize its operating costs while scaling its illicit activities.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

When a user’s H96 streaming stick is selected by the command-and-control infrastructure to perform a specific fraud task, it is quietly pushed the appropriate Blockly module. This module can execute a variety of automated actions, including silently launching a background web browser, visiting targeted web pages, browsing through content, managing open tabs, and interacting with displayed advertisements. To ensure that the TV boxes masquerading as mobile phones can reliably and realistically click on ads without tripping anti-fraud tripwires, the Fengwo Group integrates multiple vision and reasoning systems into a single interface. This advanced capability allows the automated bots to accurately identify an advertisement on a webpage and navigate the digital environment in a manner that closely mimics human behavior.

Television On Means Proxy, Television Off Means Fraud

One of the more fascinating technical insights uncovered during Bitsight’s investigation is how the malware manages device resources to avoid detection by the end user. The researchers discovered that the H96 devices alternate between two distinct operational modes: relaying residential proxy traffic and participating in ad fraud. Crucially, however, the devices never engage in both activities simultaneously.

The telemetry data revealed that when these streaming boxes detect an active HDMI signal from an attached television set—signalling that the human owner is actively using the device to stream video content or watch television—the box defaults to functioning as a residential proxy. Conversely, the moment the television is turned off, the box immediately pivots away from proxy duties and switches back to executing waiting ad fraud tasks.

Falé noted that this behavioral split is almost certainly intentional, implemented because the ad fraud routines are significantly more resource-intensive and would likely interfere with the device’s primary marketing purpose of streaming video content smoothly over the internet. If the fraud operations ran continuously while the user was watching a movie or a live broadcast, the resulting lag, buffering, or performance degradation would likely arouse suspicion and prompt the user to disconnect or investigate the hardware.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Despite persistent and escalating warnings issued by the Federal Bureau of Investigation and cybersecurity industry leaders regarding the severe security and privacy risks associated with unverified streaming hardware, major e-commerce platforms such as Amazon, Best Buy, Newegg, and numerous others continue to offer hundreds of different models and brands for sale. These devices frequently bundle unofficial, modified versions of Google’s Android operating system and are aggressively marketed across social media platforms by online influencers as a cost-effective way to bypass subscription fees and access a vast array of premium streaming content and live television broadcasts.

In addition to enlisting unsuspecting users’ hardware into large-scale ad fraud networks, these generic streaming devices almost universally arrive with residential proxy software pre-installed directly into the firmware. This software covertly rents out the owner’s home internet protocol address to anonymous, paying third-party customers. These network renters span a wide spectrum of actors, ranging from aggressive data-scraping corporations and automated ticket scalpers to malicious cybercriminals operating illicit online enterprises.

Compounding the problem is the fact that because these generic streaming boxes are manufactured cheaply and are profoundly insecure by default, they completely lack proper authentication protocols. Installing such a device on a home or corporate office network effectively invites a wide array of cyber threats. Earlier this year, in January, proxy tracking and threat intelligence service Synthient documented how multiple automated botnets had rapidly compromised and enslaved millions of similar TV boxes by exploiting a complex web of security vulnerabilities present within both the pre-installed residential proxy software and the underlying streaming device operating systems.

Global Scale and Financial Impact

Bitsight reported that its telemetry tracking identified approximately 38,000 distinct TV boxes globally that were continuously phoning home to the expired Fengwo Group domain. Based purely on this conservative sample size, the security firm estimates that this specific ad fraud network generates daily revenues approaching $50,000, a figure that notably excludes the substantial revenues reaped from the residential proxy side of the commercial operation. Falé emphasized, however, that these financial estimates are highly conservative because they rely exclusively on telemetry data gathered from just one of the Fengwo Group’s core and older domains.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Regarding the Fengwo Group’s bold public claims of controlling more than 120,000 "AI digital humans," Bitsight’s analysis concludes that this narrative may simply be a clever marketing facade designed to obscure their true activities and prevent regulatory scrutiny or law enforcement suspicion. Historically, threat researchers tracking large-scale proxy networks and distributed denial-of-service operations have frequently observed malicious actors constructing outwardly legitimate corporate fronts to mask the true scale and nature of their botnet infrastructure.

When KrebsOnSecurity attempted to reach out to the Fengwo Group for comment by emailing the designated contact address listed on the company’s official homepage, the message immediately bounced back with an automated delivery failure notice stating that the recipient’s inbox was either entirely full or experiencing an overwhelming volume of incoming mail.

As Bitsight’s extensive analysis clearly demonstrates, consumers looking to purchase television streaming hardware are strongly advised to stick exclusively to well-known brand names from reputable, established manufacturers. Furthermore, users should exercise extreme caution and restraint regarding any additional applications they choose to install on their devices, as many third-party apps have also been found to covertly bundle residential proxy software.

Google officially advises consumers to verify whether a given streaming device is built using the legitimate, certified Android TV operating system equipped with Google Play Protect by following official verification guidelines. Additionally, threat intelligence firms like Synthient maintain publicly accessible lists of Internet of Things products known to have shipped to consumers with pre-installed proxy software and malicious applications. Security experts remind the public that these hidden threats extend beyond television streaming sticks and boxes, with residential proxy software frequently discovered embedded within other popular consumer IoT devices, particularly digital photo frames purchased from unverified online vendors.

Leave a Reply

Your email address will not be published. Required fields are marked *