For years, cybersecurity professionals have issued dire warnings regarding the perils of "unbranded" or generic Android-based TV streaming boxes. These devices, often marketed on major e-commerce platforms as low-cost gateways to "unlimited" free content, have long been suspected of harboring malicious software. However, a new, groundbreaking investigation by the security firm Bitsight has peeled back the curtain on a much more sophisticated—and lucrative—criminal enterprise.
Far from being simple media players, these devices have been weaponized as clandestine components in a massive, automated ad fraud network. By spoofing mobile devices and executing AI-driven browsing behaviors, these "living room" computers are defrauding advertisers of millions of dollars annually, all while turning your home internet connection into a tool for cybercrime.
The Discovery: Peering Inside the Machine
The investigation, led by Bitsight threat researcher Pedro Falé, began with a stroke of digital detective work. Falé identified a specific brand of popular streaming hardware, the "H96," which had been communicating with a domain that had recently expired. By registering this domain, Falé was able to intercept the telemetry data being sent from tens of thousands of these devices worldwide.
What he found was staggering. The devices, which are supposed to function as stationary media players, were reporting themselves to the server as high-end mobile smartphones from major manufacturers, including Samsung, Huawei, Vivo, and Xiaomi.

"We noticed something was wildly wrong," Falé told KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones."
Upon deeper inspection, Falé discovered that these devices were running specialized, pre-installed applications developed by a mainland Chinese entity known as Zhejiang Fengwo IoT Technology Ltd., operating under the umbrella of the "Fengwo Group." This firm, established in 2019, has turned the simple act of plugging in a streaming box into a high-stakes automated revenue stream for itself and its affiliates.
Chronology of a Digital Heist
The operation is a model of industrial-scale efficiency, relying on a sophisticated, multi-layered architecture:
- The Supply Chain Injection: The malicious software is baked into the firmware of the H96 and similar devices before they even leave the factory. Consumers receive a device that is essentially a "Trojan Horse," pre-loaded with the Fengwo Group’s ad-fraud applications.
- The Telemetry Phase: Once plugged in, the device calls home to its command-and-control servers, reporting hardware details and installed apps. This allows the operators to keep an inventory of their "botnet" fleet.
- The Context-Aware Switch: The software is designed to be stealthy. When the device detects an active HDMI signal—indicating the user is actually watching television—it remains relatively dormant or pivots to serving as a "residential proxy," renting out the user’s IP address to third parties.
- The Fraud Cycle: When the television is powered off, the device shifts into its primary profit-generating mode: ad fraud. It begins to navigate to AI-generated websites, clicking on advertisements to generate fraudulent revenue for the Fengwo Group.
- The Spoofing Layer: To maximize the value of these clicks, the bots spoof mobile device headers. Advertisers pay significantly more for traffic originating from mobile devices than from desktop or TV platforms, making the deception essential to the operation’s profitability.
The AI-Powered "Digital Human" Facade
The Fengwo Group is not merely running a simple script; they have integrated advanced AI tools to ensure their fraud remains undetected by standard ad-network security measures. Their public-facing website, fwgcloud[.]com, boasts that the company is "redefining the boundaries of human-AI interaction," claiming to offer over 120,000 "AI digital humans" for rent.

Bitsight’s analysis suggests this may be a smoke-screen. By mimicking human-like browsing patterns—visiting news articles, scrolling through content, and interacting with pages—these "digital humans" navigate websites in a way that appears authentic to anti-fraud systems.
Furthermore, the operation utilizes a proprietary implementation of Google’s Blockly, a visual programming language designed for children. By using a drag-and-drop interface, Fengwo’s operators can create complex fraud routines without needing advanced coding knowledge. This "low-code" approach to cybercrime allows the organization to scale its operations rapidly, keeping overhead costs remarkably low while maximizing the output of their botnet.
Supporting Data: The Scale of the Fraud
Bitsight’s report estimates that with roughly 38,000 devices currently phoning home to just one of the Fengwo Group’s older domains, the operation generates approximately $50,000 in revenue per day. This figure is conservative, as it does not account for the additional revenue generated through the sale of residential proxy bandwidth or the myriad other domains the group likely controls.
The infrastructure is built to last. By splitting the device’s capabilities—functioning as a proxy when the TV is on and an ad-bot when the TV is off—the criminals ensure the user rarely notices a significant dip in internet performance, allowing the infection to persist in homes for years.

Official Responses and Industry Warnings
Despite the clear evidence of malfeasance, these devices remain readily available on major global marketplaces, including Amazon, Best Buy, and Newegg. The Federal Bureau of Investigation (FBI) has issued multiple alerts warning that home internet-connected devices are being increasingly leveraged to facilitate criminal activity.
In early 2026, the service Synthient documented the "Kimwolf" botnet, which enslaved millions of similar devices by exploiting vulnerabilities in the very residential proxy software that these boxes ship with. Yet, the supply chain remains largely unregulated.
When KrebsOnSecurity attempted to reach the Fengwo Group for comment via the contact email provided on their website, the request was rejected by the mail server, which noted that the inbox was either full or receiving too much traffic—a fitting metaphor for an organization built on flooding the internet with fraudulent data.
The Implications for Consumers and the Web
The implications of this discovery are profound for three distinct groups:

1. For the Consumer: The primary danger is not just the loss of privacy, but the compromise of the home network. By introducing an insecure, "always-on" device into your local network, you are essentially opening a back door to any cybercriminal willing to pay for access to your IP address. These devices have no authentication protocols, making them easy targets for secondary infection by other botnets.
2. For the Advertising Industry: This fraud represents a massive drain on digital marketing budgets. When companies pay for ads, they expect human engagement. Instead, they are paying for "bot" clicks generated by a streaming box in a living room halfway across the world. This dilutes the value of digital advertising and forces honest publishers to compete with fabricated traffic.
3. For the Tech Ecosystem: The reliance on unofficial, unverified Android builds is the root of the problem. As Google has repeatedly emphasized, only devices that are "Play Protect" certified have been vetted for safety.
Recommendations for Security
- Audit Your Hardware: If you are using a generic, unbranded streaming box, replace it with a reputable, mainstream device (e.g., Apple TV, Roku, or a certified Google Chromecast).
- Check the List: Review the list of known compromised IoT devices maintained by security researchers like those at Synthient.
- Network Segmentation: For advanced users, place IoT devices on a "guest" or isolated network segment. This ensures that if the device is compromised, the attacker cannot easily pivot to your personal computers or sensitive data storage.
- Verify Certification: Always look for the Google Play Protect certification logo. If a device lacks this, it is likely running a modified, insecure version of Android that is ripe for exploitation.
The "H96" case serves as a stark reminder that in the modern era, the cost of a device is often subsidized by the compromise of the user’s digital integrity. As long as these boxes are permitted to flood the market, the battle against automated ad fraud and residential proxy abuse will remain an uphill climb for the cybersecurity community.
