The Invisible Botnet: How Your Budget TV Box is Committing Global Ad Fraud

For years, security researchers have sounded the alarm regarding the “too good to be true” promises of budget TV streaming boxes. These devices, often marketed as gateways to unlimited, free premium content for a nominal one-time fee, have long been suspected of harboring dark secrets. While consumers hoped for a bargain, they inadvertently purchased a silent intruder for their home networks.

A groundbreaking investigation by the security firm Bitsight has now pulled back the curtain on a sophisticated, industrialized criminal operation hidden within these devices. The analysis reveals that these streaming boxes are not merely renting out the user’s bandwidth to anonymous third parties—a practice already known to be risky—but are actively participating in a massive, AI-driven ad fraud scheme designed to siphon millions of dollars from the global advertising ecosystem.

The Discovery: An Unexpected Identity Crisis

Pedro Falé, a lead threat researcher at Bitsight, stumbled upon the operation almost by accident. While investigating the command-and-control infrastructure of "H96" brand streaming devices—a popular line of generic TV boxes—Falé registered an expired domain that had previously been used for device telemetry.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Once he gained control of the domain, he began to see the data flowing from tens of thousands of H96 units globally. What he saw was alarming: while these devices were plugged into television sets, they were reporting themselves to the server as mobile phones. Specifically, they were spoofing their hardware identifiers to mimic high-end handsets from manufacturers like Samsung, Huawei, Xiaomi, and Vivo.

“We noticed something was wildly wrong,” Falé told KrebsOnSecurity. “Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones.”

By analyzing the data, Bitsight determined that every infected device was running two specific applications developed by Zhejiang Fengwo IoT Technology Ltd, a mainland China-based entity operating under the "Fengwo Group" banner. This discovery provided the "smoking gun" that linked the hardware to a centralized, malicious ad-fraud empire.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Chronology of a Digital Heist

The operation is as calculated as it is automated. The Fengwo Group appears to have built a turnkey system that weaponizes consumer electronics.

  • 2019: Zhejiang Fengwo IoT Technology Ltd is established in China, laying the groundwork for its portfolio of ad-publishing and AI-interaction services.
  • The Infiltration Phase: Fengwo integrates its proprietary code into the firmware of budget Android TV boxes at the factory level. By the time a customer unboxes the device, the “backdoor” is already active.
  • The Discovery Phase: Bitsight tracks approximately 38,000 devices communicating with the Fengwo domain. Through telemetry analysis, researchers uncover the device-spoofing mechanism and the reliance on AI-generated websites.
  • The Current State: The devices operate as a dual-threat system. When an HDMI signal is detected (indicating a user is actively watching TV), the box defaults to acting as a residential proxy—selling the user’s IP address to unknown actors. When the TV is turned off, the box shifts its processing power to the primary objective: simulated ad clicks.

Supporting Data: The Mechanics of Fraud

The sophistication of the Fengwo Group’s infrastructure is staggering. The group utilizes a visual programming language called "Blockly," originally developed by Google to teach children how to code. By building a proprietary implementation of Blockly, Fengwo allowed its low-skilled operators to drag and drop code blocks to create complex, automated fraud routines.

The AI-Generated Front

The fraud is conducted through a network of AI-generated websites masquerading as legitimate news, health, and finance portals. These sites are designed to look professional, but they contain a critical caveat: they do not display ads unless the visiting device presents a spoofed mobile user agent.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

To ensure the bots can bypass modern fraud-detection systems, Fengwo uses advanced "vision and reasoning" systems. These bots don’t just "click" a link; they navigate web pages, scroll through content, and manage browser tabs in a way that mimics human behavior.

Bitsight’s analysis indicates that the operation is highly profitable. Conservatively estimated, this single network generates nearly $50,000 in fraudulent revenue per day. When multiplied across the larger, undocumented infrastructure of the Fengwo Group, the total financial impact on the advertising industry likely reaches into the tens of millions of dollars annually.

The "Digital Human" Facade

The Fengwo Group’s own public-facing website, fwgcloud[.]com, paints a picture of a futuristic AI company, claiming to have created over 120,000 "AI digital humans" available for hire. However, researchers view this as a strategic smoke screen.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

“Historically, when dealing with proxy services or DDoS operations, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their true capabilities or botnet size,” Falé noted. This "legitimate" business front serves two purposes: it provides a veneer of credibility to potential partners, and it provides a plausible explanation for the massive server traffic generated by their botnet.

Official Responses and Industry Silence

Despite the clear evidence of large-scale criminal activity, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to list these devices. These retailers often rely on third-party marketplace sellers who rotate inventory quickly, making it difficult to enforce safety standards.

The FBI has issued multiple warnings regarding the security risks posed by uncertified, internet-connected IoT devices. Yet, the supply chain for these generic boxes remains porous. When KrebsOnSecurity attempted to reach the Fengwo Group for comment via the contact address listed on their official website, the email bounced back, indicating that the company’s infrastructure is either poorly maintained or overwhelmed by its own automated traffic.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Implications for the Consumer

The implications of this report extend far beyond ad fraud. The primary risk to the average consumer is the erosion of network security. By introducing a device with an open, pre-installed backdoor into a home or office network, users are effectively inviting cybercriminals to tunnel through their firewalls.

What You Can Do

  1. Verify Certification: Google provides resources to confirm if an Android device is Play Protect certified. Avoid any device that lacks this official seal of approval.
  2. Audit Your Network: Use tools to monitor traffic from IoT devices. If your TV box is frequently "phoning home" to unknown domains in the middle of the night, it is likely compromised.
  3. Stick to Reputable Brands: While brand-name streaming sticks (such as those from Roku, Apple, or Google) may cost more, they are subject to rigorous security audits and frequent, verified software updates.
  4. Awareness of "Free": Understand that in the world of IoT, "free" content often comes at the price of your data, your privacy, and your network integrity.

As the Bitsight report concludes, the "Fengwo" incident is likely just the tip of the iceberg. As long as cheap, insecure hardware continues to flood the market, botnet operators will continue to treat the average consumer’s living room as a private server farm for their criminal enterprises. The era of the "smart" home has arrived, but for those with generic streaming boxes, it has brought with it an uninvited, invisible guest.