For years, cybersecurity experts have issued urgent warnings regarding the proliferation of "too-good-to-be-true" streaming hardware. These generic Android-based TV boxes, often sold on major e-commerce platforms for a one-time fee, promise users unlimited access to premium content, live sports, and global broadcasting services without the need for subscriptions. However, a groundbreaking investigation by the security firm Bitsight has peeled back the curtain on a far more sinister reality: these devices are not just streaming entertainment; they are serving as silent, involuntary participants in a sprawling, sophisticated ad-fraud operation.
While previous reports focused on how these boxes rent out a user’s residential internet connection as a proxy for anonymous—and often criminal—traffic, new analysis reveals a deeper level of compromise. These devices are being programmed to spoof mobile phones, systematically clicking on advertisements across AI-generated websites to defraud global advertising networks of millions of dollars annually.
The Discovery: Peering Inside the Botnet
The investigation was spearheaded by Pedro Falé, a lead threat researcher at Bitsight. Falé’s breakthrough came when he managed to register an expired domain that had previously been used for telemetry by the H96 brand, a particularly popular series of streaming sticks. By seizing control of this domain, Falé gained an unprecedented vantage point into the command-and-control infrastructure that orchestrates these devices.
What he found was a vast, complex ecosystem of deception. The domain was designed to collect granular telemetry data, including hardware specifications and a comprehensive list of installed applications from tens of thousands of H96 streaming sticks plugged into televisions worldwide. Upon analyzing the traffic flowing through this domain, Falé noticed an immediate anomaly.

“We noticed something was wildly wrong,” Falé told KrebsOnSecurity. “Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones.”
Despite the physical reality of the hardware, the devices were reporting themselves to advertising networks as premium smartphones from major manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. This masquerade is essential for the fraud to function, as advertising networks pay significantly higher premiums for traffic originating from mobile devices than they do for desktop or unknown TV-based hardware.
Chronology of a Digital Heist
The operation’s sophistication lies in its automation and its ability to operate largely undetected by the end-user. According to Bitsight’s findings, the operation can be traced back to a mainland China-based entity known as Zhejiang Fengwo IoT Technology Co., Ltd., operating under the umbrella of the "Fengwo Group."
Founded in 2019, the Fengwo Group appears to have built a turnkey solution for ad fraud. Bitsight discovered that all affected H96 devices were pre-installed with two specific applications developed by the company. The timeline of this operation reveals a highly disciplined approach to monetization:

- Deployment: Thousands of devices are shipped globally with pre-installed, malicious firmware and software that grants the Fengwo Group persistent, "backdoor" access to the system.
- Telemetry and Profiling: The devices communicate with the Fengwo infrastructure, providing details about their location, network status, and hardware.
- The Switch: The software is programmed to distinguish between active and idle states. When a user is actively streaming content (detected by an active HDMI signal), the box functions as a standard residential proxy, renting out the user’s bandwidth.
- The Fraud: When the television is turned off—but the device remains plugged into power—the box switches to its primary mission: ad fraud. It launches automated browsing routines, navigating through AI-generated news and content sites and clicking on ads.
- Monetization: The Fengwo Group collects the resulting ad revenue, which Bitsight estimates to be at least $50,000 per day from just one of the company’s older command domains.
Supporting Data: The AI-Driven Engine of Deceit
The scale of this operation is amplified by the use of machine learning. The Fengwo Group hosts a variety of websites covering finance, health, gaming, and food. These sites are populated by AI-generated news articles and graphics, creating a convincing façade of legitimate digital media.
Crucially, these sites are "smart"—they do not display ads to regular visitors. The ad-delivery mechanisms are triggered only when the visiting device matches the specific spoofed mobile profile associated with the H96 botnet.
Bitsight also uncovered evidence that the Fengwo Group uses a proprietary implementation of Google’s "Blockly," a visual programming language originally designed for education. By utilizing Blockly, the company allows low-skilled operators to build sophisticated fraud routines by dragging and dropping blocks of code. This modular approach significantly reduces the cost of maintaining the operation, as the company requires only a handful of highly skilled engineers to build the core templates, while junior staff can manage the execution units.
To ensure the bots can navigate websites like real humans, the group employs a "vision and reasoning" system. This technology allows the bot to identify the location of ads on a page and interact with the content—scrolling, clicking, and managing tabs—in a way that mimics human behavior, thereby evading the automated fraud-detection filters used by major advertising platforms.

Official Responses and Industry Implications
The implications of this report are severe. Despite persistent warnings from the FBI and other cybersecurity agencies regarding the risks of using uncertified IoT devices, major e-commerce retailers continue to facilitate the distribution of these products.
The FBI has previously alerted the public that home internet-connected devices are frequently used to facilitate criminal activity, yet the market for "dirt cheap" streaming hardware remains largely unregulated. These boxes typically run unofficial, "forked" versions of the Android operating system that lack the security updates and integrity checks found in certified Android TV products.
When asked for comment, the Fengwo Group remained silent. Attempts to contact the company via the address listed on its website, fwgcloud[.]com, resulted in bounced emails, with the company’s server claiming that the inbox was either full or overwhelmed by incoming traffic. This lack of transparency is a hallmark of the operation, which Bitsight suggests may be intentionally cultivating an aura of mystery to prevent researchers from accurately gauging the true size of its network.
The Broader Security Landscape
The H96 case is merely the tip of the iceberg. In January, the proxy tracking service Synthient documented how multiple botnets have "enslaved" millions of similar TV boxes by exploiting vulnerabilities in both the pre-installed proxy software and the devices’ insecure operating systems.

The security community is now shifting its focus toward a broader range of IoT devices. Residential proxy software has been detected in digital photo frames, smart cameras, and other household gadgets. The common thread among these products is a complete lack of authentication and a reliance on cheap, insecure software stacks.
How to Protect Your Network
For consumers, the advice from security experts is clear:
- Stick to Reputable Brands: Avoid generic streaming sticks. If a device promises "free" access to premium content, it is almost certainly compromising your security.
- Verify Certification: Ensure that any Android-based TV device is "Play Protect" certified. You can verify this through Google’s official support documentation.
- Network Segmentation: If you must use a questionable IoT device, place it on a "guest" network that is isolated from your primary computers, NAS drives, and sensitive financial data.
- Consult Research: Resources such as the list maintained by Synthient on GitHub provide an up-to-date catalog of known problematic hardware.
As the digital landscape becomes increasingly dominated by AI-driven automation, the battle between cybersecurity researchers and criminal syndicates like the Fengwo Group will only intensify. This incident serves as a stark reminder that in the age of the Internet of Things, the price of "free" is often your privacy, your bandwidth, and your participation in a global criminal enterprise.
