Global Ad Fraud Network Exposed: How Cheap TV Boxes Are Exploiting Your Internet Connection

For years, cybersecurity professionals have issued stern warnings regarding the hidden dangers lurking inside inexpensive, generic TV streaming boxes. Often marketed as "all-in-one" solutions that promise unlimited access to premium content for a single, low price, these devices are frequently little more than trojan horses. While experts have long cautioned that these gadgets secretly turn home routers into residential proxies—effectively renting out a user’s internet bandwidth to anonymous third parties—a groundbreaking new investigation reveals the situation is far more sinister. A comprehensive analysis has uncovered that these devices are routinely spoofing their identities to mimic mobile phones, participating in a sophisticated, automated campaign designed to defraud online merchants and advertising networks on a massive scale.

Pedro Falé, a threat researcher at the security firm Bitsight, has pulled back the curtain on this sprawling digital ecosystem. By registering an expired domain name that was previously utilized to coordinate activity for a popular brand of streaming devices known as H96, Falé gained unprecedented visibility into the inner workings of a vast ad fraud operation. This domain had once served as a telemetry hub, tasked with harvesting granular hardware details and exhaustive lists of installed applications from tens of thousands of H96 units active in living rooms across the globe.

Upon analyzing the traffic directed to this domain, Falé made a startling discovery: despite the devices being television-based hardware, they were masquerading as a diverse array of mobile phone models from major manufacturers, including Samsung, Huawei, Xiaomi, and Vivo. "We noticed something was wildly wrong," Falé explained in an interview with KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones."

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The Infrastructure of Deception

The investigation identified two specific, recurring applications pre-installed on all the compromised devices. These applications were traced back to a mainland China-based entity known as Zhejiang Fengwo IoT Technology Ltd, which operates a portfolio of ad-publishing services under the moniker "Fengwo Group." Bitsight’s research suggests that the Fengwo Group is not merely an app developer but a central node in a well-organized fraud engine. By scrutinizing shell identities—ranging from single-person entities to corporate registrations in Hong Kong and Singapore—researchers successfully linked the monetization flow of the fraudulent clicks back to the Fengwo Group.

The mechanism used to facilitate this fraud is remarkably efficient. The H96 devices act as captive, automated traffic sources that "visit" websites generated by the Fengwo Group. These websites are populated with machine-generated content spanning a wide variety of topics, such as finance, health, music, gaming, and food. However, these sites remain dormant to standard visitors; they only serve advertisements when they detect that a visiting device matches the spoofed mobile profile of a compromised H96 unit. By ensuring the "traffic" appears to originate from legitimate mobile devices, the perpetrators can extract higher payouts from advertising networks that prioritize mobile users.

AI-Driven "Digital Humans" and Automated Fraud

The Fengwo Group’s public-facing presence, centered on the domain fwgcloud[.]com, presents a futuristic facade. The company claims to be "redefining the boundaries of human-AI interaction," boasting a catalog of over 120,000 "AI digital humans" that can be rented for tasks ranging from customer service and creative design to emotional companionship.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

However, beneath this polished exterior lies a far more utilitarian infrastructure. Bitsight discovered that the domain shared SSL certificate data with the infrastructure used to manage the phone-spoofing mechanism on the H96 sticks. Furthermore, the company maintains an internal wiki that reveals the use of Blockly, a visual programming language developed by Google. While Blockly is intended as an educational tool to help children learn software development, the Fengwo Group has repurposed it into a platform for low-skilled operators to construct complex fraud routines.

By dragging and dropping blocks of code, operators can define specific fraud tasks—such as launching a browser, navigating pages, managing tabs, and clicking on advertisements—without needing any deep understanding of the underlying software architecture. Once a routine is saved, it is exported as JavaScript and deployed to the devices. Bitsight’s report highlights a developer comment noting that this modular approach allows a small core of high-level engineers to create templates, while less skilled staff can execute them, significantly lowering operational overhead while maximizing the scale of the fraud.

To further increase the success of these operations, the Fengwo Group has implemented a "vision and reasoning" system. This interface allows the botnet to correctly identify and interact with advertisements on a webpage with a level of accuracy that mimics human behavior, making it difficult for standard ad-fraud detection software to flag the traffic as malicious.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The Duality of the Botnet

Perhaps most disturbing is the adaptive nature of these devices. Bitsight discovered that H96 units are capable of switching between two distinct roles: acting as a residential proxy or participating in ad fraud. The device’s primary duty appears to be tied to the state of the television itself. When the unit detects an active HDMI signal, indicating that a user is actively watching content, it functions as a residential proxy. When the TV is switched off, the device shifts its resources toward ad fraud tasks.

Researchers believe this binary behavior is intentional. Ad fraud is computationally intensive; if the device were to attempt both tasks simultaneously, it would likely suffer from performance degradation, potentially alerting the user that something is wrong with their streaming experience. By waiting until the device is idle, the operators ensure their botnet remains "invisible" to the average consumer.

Despite recurring warnings from the FBI and other security agencies regarding the privacy and security risks associated with unverified streaming hardware, these devices remain ubiquitous. Major e-commerce platforms, including Amazon, Best Buy, and Newegg, continue to host a plethora of brands that utilize unofficial, uncertified versions of the Android operating system. These boxes are frequently promoted by online influencers as an inexpensive gateway to free content, masking the fact that they are essentially pre-infected with spyware.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

A Global Scale of Revenue

The financial implications of this operation are significant. Bitsight tracked approximately 38,000 H96 devices connecting to a single, older Fengwo Group domain. Based on this subset of traffic, researchers estimate that the ad fraud network generates revenue exceeding $50,000 per day. It is crucial to note that this figure does not account for the additional income generated through the sale of residential proxy access, nor does it include revenue from other domains or botnet clusters that may be operating under the same umbrella.

When researchers attempted to contact the Fengwo Group via the email address listed on their website, the request was met with a server error, suggesting that the company’s infrastructure is either overwhelmed with traffic or that the contact information is intentionally non-functional. The claim of having 120,000 "AI humans" may be little more than a marketing ploy—a way to project an aura of legitimacy while concealing the true, industrial-scale nature of their botnet operations.

As the cybersecurity landscape continues to evolve, the case of the H96 streaming sticks serves as a stark reminder of the "hidden costs" of cheap consumer electronics. Security experts emphasize that the safest course of action is to rely on hardware from reputable, established manufacturers that provide consistent security updates and do not ship products with questionable pre-installed applications. For consumers, the message is clear: if a device promises unlimited, free access to premium content for a fraction of the cost, the user is likely not the customer—they are the product, and their home network is the utility.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Organizations like Synthient continue to track the proliferation of these compromised devices, maintaining lists of hardware known to include residential proxy software. As these botnets grow more sophisticated, incorporating AI-driven human behavior and modular, easy-to-use fraud platforms, the burden of security falls increasingly on the consumer to vet the technology they introduce into their homes and workplaces. The era of "plug-and-play" convenience has, for better or worse, become an era of "plug-and-protect."

Share:

Evan Lee Salim writes for Tech Maze.

Leave a comment