The Trojan Horse in Your Living Room: How Generic TV Boxes Are Fueling a Massive AI-Driven Ad Fraud Empire

For years, cybersecurity experts have issued dire warnings regarding the dangers of "bargain-bin" streaming devices—those generic, unbranded TV boxes that promise unlimited, subscription-free access to premium content for a singular, low-cost fee. While these devices are often marketed as a consumer’s gateway to "cord-cutting" freedom, a groundbreaking investigation by the security firm Bitsight has unveiled a much darker reality: these boxes are not merely streaming portals; they are active, weaponized nodes in a sprawling, automated criminal enterprise.

The latest findings reveal that these devices routinely spoof their identities to masquerade as mobile phones, silently clicking on advertisements on AI-generated websites. This sophisticated operation is designed to defraud online merchants and advertising networks, turning the innocent home streaming device into a cog in a global digital heist.

The Discovery: Peering into the H96 Botnet

The investigation began when Pedro Falé, a threat researcher at Bitsight, decided to take a proactive approach to understanding the mechanics behind these compromised devices. By registering an expired domain name that had previously been used for telemetry—data collection—on the popular "H96" brand of streaming boxes, Falé gained an unprecedented window into the botnet’s command-and-control structure.

The domain was originally designed to collect hardware information and lists of installed applications from tens of thousands of H96 units scattered across the globe. Upon inspecting the incoming data traffic, Falé made a startling discovery: the vast majority of these "TV boxes" were not reporting their true nature to the server. Instead, they were spoofing their user-agent strings, claiming to be high-end mobile devices from major manufacturers like Samsung, Vivo, Huawei, and Xiaomi.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

"We noticed something was wildly wrong," Falé told KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be phones." This deception is critical to the fraud model; by mimicking mobile traffic, the botnet operators can trigger higher payouts from advertising networks that prioritize mobile-based engagement.

Chronology of a Digital Heist

The investigation traced the operation back to a mainland China-based entity known as Zhejiang Fengwo IoT Technology Ltd, which operates under the broader umbrella of the "Fengwo Group." Founded in 2019, the company has successfully built a robust portfolio of ad-publishing tools that leverage these compromised IoT (Internet of Things) devices.

Phase 1: Infiltration and Telemetry

The H96 devices are shipped to consumers with malicious firmware pre-installed. Upon connecting to a home network, the device begins "phoning home" to Fengwo-controlled domains. The device systematically reports its status and receives instructions on which "task" to perform.

Phase 2: The Dual-Mode Mechanism

Bitsight’s analysis uncovered a highly efficient, context-aware operational routine. The devices utilize a two-pronged approach:

Read This Before You Buy That TV Streaming Stick – Krebs on Security
  1. Residential Proxy Mode: When the device detects an active HDMI signal—indicating the user is actually watching television—it functions as a residential proxy. This allows third parties to route their internet traffic through the user’s home IP address, effectively hiding their location. This is often used by cybercriminals, ticket scalpers, and data scrapers.
  2. Ad Fraud Mode: When the TV is turned off, the device shifts into "ad fraud" mode. It becomes a resource-heavy bot, silently launching a browser, navigating to AI-generated websites, and clicking on advertisements.

This separation of duties is deliberate; the operators avoid interfering with the user’s streaming experience, which would likely lead the victim to unplug or discard the device, thereby destroying the botnet’s infrastructure.

Phase 3: AI-Driven Monetization

The Fengwo Group maintains a network of sham websites featuring machine-generated news, health tips, and lifestyle content. These sites remain dormant until a device with a spoofed mobile profile visits them. Once the "bot" arrives, the site serves ads, and the device clicks them, generating fraudulent revenue for the operators.

The Industrialization of Fraud: The Blockly Ecosystem

Perhaps the most alarming aspect of the Bitsight report is the "industrialization" of this fraud. The Fengwo Group uses a proprietary implementation of Blockly, a visual programming language originally developed by Google to teach children how to code.

By creating a drag-and-drop interface, the Fengwo Group has lowered the barrier to entry for their operators. Employees do not need deep expertise in JavaScript or backend architecture; they simply connect logic blocks to define a fraud routine—such as "launch browser," "navigate to URL," "locate ad element," and "click."

Read This Before You Buy That TV Streaming Stick – Krebs on Security

This system is exported as executable JavaScript and pushed to Amazon S3 buckets, where the H96 devices download and execute the tasks. According to internal communications discovered by Bitsight, this modular design allows the company to operate with a minimal core team of highly skilled developers while offloading the day-to-day "execution" of fraud to lower-skilled workers. This strategy drastically reduces operating costs while scaling the volume of fraudulent clicks to an industrial level.

Supporting Data and Financial Implications

Bitsight tracked approximately 38,000 H96 TV boxes currently phoning home to a single legacy Fengwo domain. Conservative estimates suggest this specific segment of the network generates nearly $50,000 per day in fraudulent ad revenue.

This figure does not account for:

  • Revenue generated from the residential proxy side of the business.
  • Other domains or botnets operated by the Fengwo Group.
  • The "AI Digital Human" service, which the company claims involves over 120,000 digital entities available for rent.

While the "120,000 digital humans" claim may be a marketing facade or a way to obscure the actual size of their botnet, the scale of the infrastructure is undeniable. When KrebsOnSecurity attempted to contact the Fengwo Group for comment via their listed email address, the request bounced, with the server claiming the inbox was either full or overwhelmed—a fittingly ironic end to a request for comment on an automated, high-volume operation.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Official Responses and Industry Warnings

The FBI has repeatedly cautioned consumers about the dangers of using "unofficial" streaming devices. In a 2025 alert, the Bureau highlighted how these IoT devices are frequently leveraged to facilitate criminal activity, including the creation of massive botnets.

Despite these warnings, major e-commerce platforms—including Amazon, Best Buy, and Newegg—continue to list hundreds of these devices. Many are promoted by social media influencers as "must-have" tools for free television. The ease with which these devices can be purchased, combined with their lack of basic security authentication, makes them the perfect "low-hanging fruit" for bad actors.

Furthermore, the problem is not limited to TV boxes. As identified by the proxy tracking service Synthient, the residential proxy software found in these boxes has also been discovered in other IoT devices, including digital photo frames and smart home accessories.

Implications for the Digital Future

The implications of the Bitsight findings are far-reaching:

Read This Before You Buy That TV Streaming Stick – Krebs on Security
  1. Erosion of Trust in Online Advertising: The prevalence of bot-driven ad fraud devalues legitimate advertising, leading to increased costs for honest businesses and potential instability in the ad-tech market.
  2. Privacy and Liability: Users of these devices are inadvertently hosting criminal traffic on their home networks. If an H96 device is used to conduct a cyberattack or access illegal content, the residential IP address will point directly to the homeowner, creating significant legal and privacy liabilities.
  3. The Rise of "Easy" Crime: The use of visual programming languages like Blockly to coordinate botnets signifies a worrying trend: the "democratization" of cybercrime. By simplifying the technical requirements for fraud, companies like the Fengwo Group are making it easier than ever for malicious operations to scale.

Conclusion: A Call for Caution

The advice from security professionals is clear: If it sounds too good to be true, it is. Consumers should avoid "jailbroken" or "unofficial" streaming devices that promise unlimited content. Instead, they should stick to reputable, name-brand hardware from established manufacturers that offer consistent security updates and firmware support.

Google provides resources for consumers to verify if a device is running a certified version of Android TV. Furthermore, organizations like Synthient maintain updated lists of IoT devices known to ship with malicious proxy software. In an era where every device in the home is a potential entry point for attackers, the price of "free" television is, quite literally, your digital security.