For years, cybersecurity experts have issued dire warnings regarding the perils of purchasing "unlocked" or generic TV streaming boxes. These devices, often marketed on major e-commerce platforms with the promise of unlimited, free content for a single, low-cost investment, have long been identified as potential security liabilities. While the primary concern has historically been their tendency to covertly rent out a user’s home internet connection to anonymous third parties, a groundbreaking new analysis has revealed a more sophisticated and sinister layer to this operation: these devices are routinely spoofing mobile phone traffic to systematically defraud advertisers.
This discovery provides a rare, behind-the-scenes look at how a massive, automated ad-fraud network functions, turning thousands of unassuming living room devices into a captive workforce for digital crime.
The Anatomy of an Ad-Fraud Botnet
Pedro Falé, a senior threat researcher at the security firm Bitsight, recently stumbled upon the inner workings of this sprawling infrastructure. His investigation began with a stroke of investigative luck: he registered an expired domain name that had previously been used by the "H96" brand of streaming boxes—a popular, inexpensive device often found on sites like Amazon.

The domain had served as a central hub for telemetry, periodically gathering comprehensive hardware information and logs of installed applications from tens of thousands of H96 streaming sticks plugged into televisions around the world. Upon analyzing the incoming data, Falé discovered a glaring discrepancy. While the devices were identified as TV streaming hardware, nearly all of them were transmitting data while masquerading as common mobile phone models from major manufacturers, including Samsung, Huawei, Vivo, and Xiaomi.
"We noticed something was wildly wrong," Falé told KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones."
The investigation revealed that all of the infected devices carried two specific applications developed by a mainland China-based entity known as Zhejiang Fengwo IoT Technology Ltd, which operates under the brand Fengwo Group. Founded in 2019, the company appears to be the architect of a complex ecosystem designed to extract profit from unsuspecting users’ internet connections and hardware resources. Bitsight’s research further traced the operation back to various shell identities across Hong Kong and Singapore, a common tactic used to mask the true origin of monetization efforts.

AI-Driven Deception and "Digital Humans"
The scope of the operation goes far beyond simple device spoofing. The H96 devices are utilized as a "captive traffic source" to interact with AI-generated websites controlled by the Fengwo Group. These websites are designed to cover a broad spectrum of mundane topics, ranging from food blogs and health tips to finance and gaming news. However, these sites remain dormant until they detect a visitor that matches the spoofed mobile profile of an H96 device. Once a match is confirmed, the site begins serving ads, which the H96 box then "clicks" on, creating fraudulent revenue for the operators.
The Fengwo Group’s own infrastructure, hosted at fwgcloud[.]com, brazenly claims to be "redefining the boundaries of human-AI interaction." The site boasts of a portfolio containing over 120,000 "AI digital humans" available for rent, supposedly capable of providing services ranging from customer support to emotional companionship.
Bitsight researchers discovered that the Fengwo Group utilizes a proprietary implementation of Blockly—a visual programming language originally created by Google to teach children how to code. By using a drag-and-drop interface, even low-skilled operators can assemble complex fraud routines without needing a deep understanding of software engineering. Once these routines are constructed, they are exported as JavaScript and deployed to the streaming boxes. The result is an efficient, low-cost system where a small team of highly skilled developers creates the templates, while an army of "execution units" runs on the thousands of compromised TV boxes globally.

When a device is tasked with a specific fraud assignment, it may silently launch a browser, navigate to specific pages, manage multiple tabs, and click on advertisements. To ensure these bots can effectively mimic human behavior and avoid detection by advertising networks, the Fengwo Group has integrated advanced vision and reasoning systems that allow the automated processes to identify ads and interact with webpages as a real user would.
The Dual Life of an Infected Device
One of the most concerning findings from the Bitsight report is the calculated nature of how these devices manage their resources. The researchers found that the H96 boxes typically operate in one of two modes, but rarely both simultaneously. When a device detects an active HDMI signal—indicating that the user is actually watching television—it functions primarily as a residential proxy, selling the user’s bandwidth. When the TV is turned off and the device is idle, it shifts into its more resource-intensive "ad fraud" mode.
This behavior suggests a deliberate attempt to keep the fraud operations from interfering with the device’s primary, advertised function, thereby extending the "lifespan" of the infection and avoiding consumer complaints.

Despite repeated warnings from the FBI and other law enforcement agencies regarding the risks associated with these devices, major retailers continue to sell them. These boxes often ship with unofficial, insecure versions of the Android operating system that lack proper authentication or security updates. Because they are rarely, if ever, patched, they remain vulnerable to a wide array of exploits.
The threat is not limited to ad fraud. In January, the proxy-tracking service Synthient documented how millions of similar devices were enslaved by botnets, taking advantage of the insecure nature of the pre-installed proxy software. Once a device is compromised, it becomes a permanent resident on the owner’s home or office network, potentially opening the door to further malicious activity.
The Cost of Convenience
The financial scale of this operation is significant. Bitsight’s analysis, based on telemetry from just one of the Fengwo Group’s core domains, identified approximately 38,000 active H96 devices. The firm estimates this network generates revenue approaching $50,000 per day—a figure that does not even account for the additional income generated through the residential proxy side of the business.

Whether the Fengwo Group actually possesses 120,000 "AI digital humans" or if the claim is merely a marketing facade remains unclear. Falé suggests that the company may use such grand claims to mask the true nature of its botnet, a common strategy among groups operating large-scale proxy services or DDoS infrastructure.
When KrebsOnSecurity attempted to reach the Fengwo Group for comment via the contact email listed on their website, the request failed, returning a bounce message indicating that the inbox was either full or receiving an overwhelming volume of traffic—a fittingly chaotic end to an inquiry into a company built on digital noise and deception.
As the industry grapples with this pervasive issue, the advice from security experts remains consistent: consumers should avoid generic streaming hardware and stick to reputable, name-brand devices that offer verified security updates. Furthermore, users should remain vigilant about the applications installed on their devices, as even legitimate-looking software can harbor malicious residential proxy components. Google provides resources for consumers to verify whether their device is running a certified version of Android TV, a step that, while simple, serves as a vital defense in an era where living room technology is increasingly being turned against the very people who own it.

