Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers, but a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. This alarming discovery, detailed in a new report from the security firm Bitsight, reveals a sophisticated ad fraud and residential proxy scheme orchestrated by a Chinese company known as Zhejiang Fengwo IoT Technology Ltd., operating under the Fengwo Group. The investigation highlights the serious security and financial implications for consumers unknowingly participating in these illicit activities.
The investigation was spearheaded by Pedro Falcão, a threat researcher at Bitsight. Falcão gained critical insights into this vast ad fraud network by registering an expired domain name that was previously used to coordinate fake ad clicks across a particularly popular brand of these streaming devices, known as H96. These H96 devices, readily available on major e-commerce platforms like Amazon, were found to be at the heart of this elaborate deception. Falcão’s initial access provided him with the ability to peer inside the network’s operations, uncovering a complex system designed for financial exploitation.

Falcão explained that the domain he acquired was initially employed for telemetry, collecting comprehensive hardware information and a complete list of installed applications from tens of thousands of H96 streaming sticks connected to televisions globally. However, upon scrutinizing the data traffic directed to this domain, he made a startling discovery: nearly all of the TV boxes were transmitting information that identified them as mobile phones from various manufacturers, including prominent brands like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falcão stated. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’" This deliberate misrepresentation was a key indicator of a coordinated fraudulent operation.
Further analysis revealed that all of these spoofed devices consistently reported having the same two applications installed. These applications were developed by Zhejiang Fengwo IoT Technology Ltd., a company established in 2019 in mainland China. This entity operates an extensive ad-publishing portfolio under the name Fengwo Group. Bitsight’s in-depth investigation into the Fengwo Group uncovered that the company had registered multiple patents directly corresponding to the internal mechanisms of these suspicious applications. Falcão elaborated in a Bitsight report, stating, "Bitsight TRACE identified several Hong Kong, Singapore, and single-person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group."
The core of the deception lies in how these H96 devices are utilized. Falcão’s analysis of the installed applications demonstrated their role in coordinating an ad fraud network. These streaming devices serve as a captive traffic source, generating fake clicks on advertisements displayed on AI-generated websites managed by the Fengwo Group. Bitsight’s researchers observed that these websites featured machine-generated news articles and graphics across a diverse range of categories, including finance, health, education, gaming, and food blogs. Crucially, these sites only displayed advertisements when the visiting device matched the spoofed mobile profile of the H96 devices, indicating a targeted and deliberate fraudulent strategy.

The Fengwo Group’s online presence, particularly through its domain fwgcloud[.]com, boasts of "redefining the boundaries of human-AI interaction" and claims to have created over 120,000 "AI digital humans" available for rent for various purposes, from emotional companionship to round-the-clock customer service and creative design. However, Falcão noted a significant technical link between the Fengwo Group’s domain and the apps found on the H96 devices. The domain shared its SSL certificate data with other domains associated with the phone-spoofing mechanism. Furthermore, an internal wiki platform linked the Fengwo Group directly to a proprietary implementation of Blockly, a visual programming language developed by Google and originally intended to help children learn software development.
Bitsight’s report detailed how Fengwo Group employees leverage Blockly to construct these fraudulent websites. This platform allows operators with minimal technical expertise to assemble code blocks visually, without necessarily understanding the underlying code’s functionality. As Bitsight’s report states, "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type. Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use." This approach significantly lowers the company’s operational costs and the barrier to entry for creating complex fraudulent schemes. A Fengwo Group app developer even highlighted these advantages, noting that "only a small number of highly-skilled developers are needed to build the template execution-unit images," and that "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs."
When an H96 streaming stick is selected for a specific fraudulent task, it is programmed to execute the appropriate Blockly module. This can involve silently launching a web browser, navigating to specific websites, browsing pages, managing tabs, and, critically, clicking on advertisements. To ensure these TV boxes, masquerading as mobile phones, can reliably interact with ads on the AI-generated websites, the Fengwo Group employs a sophisticated system that "fuses three vision and reasoning systems into a single interface." This allows the automated bots to accurately identify advertisements on web pages and navigate sites in a manner that mimics human behavior, further enhancing the deception.

A critical aspect of the H96 devices’ operation, as discovered by Bitsight, is their dual functionality. The devices are found to be either relaying residential proxy traffic or participating in ad fraud, but never simultaneously. When an HDMI signal is detected, indicating the user intends to stream content, the device typically functions as a residential proxy. However, when the TV is turned off, the device reverts to its ad fraud activities, waiting for instructions. Falcão posits that this separation is likely because ad fraud operations are more resource-intensive and could potentially interfere with the device’s primary function of streaming video content.
Despite repeated warnings from the FBI and numerous security industry leaders regarding the inherent security and privacy risks associated with these streaming devices, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to offer hundreds of different models. These devices often bundle unofficial versions of Google’s Android operating system and are frequently marketed, often through online influencers, as a cost-effective way to access a vast array of streaming services and live broadcasts without costly subscriptions.
Beyond enlisting user TV boxes into ad fraud networks, these off-brand streaming devices almost universally come with pre-installed residential proxy software. This software effectively rents out the user’s Internet address to anonymous paying customers, whose activities range from aggressive content scraping firms and ticket scalpers to outright cybercriminals. The lack of robust security measures and authentication on these generic, often inexpensive, TV boxes makes them an easy entry point for further malicious activity on home or office networks. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes by exploiting a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.

The financial implications of this operation are significant. Bitsight tracked approximately 38,000 TV boxes globally communicating with the expired Fengwo Group domain. Based on this number, the report estimates that this ad fraud network generates revenues nearing $50,000 per day, not including the substantial income derived from the residential proxy business. Falcão stressed that these figures are conservative estimates, based on telemetry from only one of the Fengwo Group’s older core domains.
Regarding the Fengwo Group’s claim of possessing 120,000 "digital humans," Bitsight’s report suggests this might be a clever marketing tactic or a way to obscure the true nature of their operations. Falcão noted in the report, "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size. This could also be the case here." Despite their claims of advanced AI capabilities, inquiries sent to the contact address listed on the Fengwo Group’s website bounced back with an "inbox full" message, indicating a lack of responsiveness or a deliberate attempt to avoid communication.
Ultimately, the findings from Bitsight serve as a stark warning. When it comes to TV boxes and streaming sticks, consumers are strongly advised to opt for reputable brands from trusted manufacturers. Furthermore, it is crucial to exercise caution and be selective about the applications installed on these devices, as many can bundle residential proxy software, as highlighted by recent research on LG smart TV apps. Google provides instructions for consumers to verify if a device utilizes the official Android TV OS and Play Protect certification. Additionally, resources like Synthient’s publicly maintained list of IoT devices known to ship with malicious pre-installed software can offer further guidance, extending beyond streaming devices to include other consumer IoT products like digital photo frames, which have also been found to be compromised. The message is clear: the allure of cheap, unlimited content comes with a hidden, potentially costly, price.

