Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks, a sophisticated scheme that has been meticulously uncovered by threat researcher Pedro Falcó from the security firm Bitsight.

Falcó, a dedicated threat researcher at Bitsight, was able to gain unprecedented insight into a vast and complex ad fraud network by registering an expired domain name. This domain was previously used to orchestrate a massive campaign of fake ad clicks across a particularly popular brand of these dubious streaming devices, known ominously as H96. His investigation, detailed in a recent report, paints a stark picture of how these seemingly innocuous devices are being weaponized for malicious purposes, extending far beyond the initial warnings about unauthorized internet usage.

The domain Falcó acquired was once a hub for telemetry, diligently collecting comprehensive hardware information and a complete inventory of installed applications from tens of thousands of H96 streaming sticks connected to televisions worldwide. However, a deep dive into the traffic funneled to this domain revealed a startling deception: nearly all of the TV boxes were transmitting data that falsely identified them as mobile phone models from a diverse array of manufacturers, including prominent names like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falcó stated, emphasizing the sheer incongruity of the situation. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Read This Before You Buy That TV Streaming Stick

This crucial discovery led Falcó to a significant revelation: all of the compromised devices reported the same two applications installed. These apps were developed by Zhejiang Fengwo IoT Technology Ltd., a company founded in 2019 in mainland China, which operates an extensive ad-publishing portfolio under the brand name Fengwo Group. Further scrutiny of the Fengwo Group’s activities unearthed multiple patents that directly corresponded to the inner workings of these deceptive applications, solidifying the link between the devices and the fraudulent operation.

Falcó meticulously documented his findings, stating, "Bitsight TRACE identified several Hong Kong, Singapore, and single-person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd., which operates under the Fengwo Group." His analysis of the apps revealed their central role in coordinating an ad fraud network. These H96 devices, unbeknownst to their users, were being exploited as a captive traffic source, systematically clicking on advertisements hosted on AI-generated websites meticulously crafted and operated by the Fengwo Group.

The deceptive nature of these websites was also brought to light by Bitsight. They discovered that these sites featured machine-generated news articles and graphics spanning a wide spectrum of categories, including finance, health, education, gaming, and food blogs. However, a critical observation was made: these sites displayed advertisements exclusively when the visiting device matched the spoofed mobile profile of the compromised H96 devices. This intricate targeting ensured that the fraudulent clicks appeared legitimate to advertising networks.

The Fengwo Group’s online presence, particularly through its domain fwgcloud[.]com, boldly proclaims its mission to "redefine the boundaries of human-AI interaction." The company boasts of creating over 120,000 "AI digital humans," available for rent for a variety of purposes, ranging from providing emotional companionship to offering 24/7 customer service and assisting with creative design. This ambitious marketing facade, however, masks a far more sinister operation.

Read This Before You Buy That TV Streaming Stick

Falcó’s investigation further revealed a deep technical connection between the Fengwo Group’s domain and the suspicious applications found on the H96 devices. The domain shared its SSL certificate data with other domains associated with the phone-spoofing mechanism, indicating a centralized control infrastructure. More intriguingly, the domain hosted an internal wiki platform that directly linked the Fengwo Group to a proprietary implementation of Blockly, a visual programming language developed by Google. Blockly was originally designed as an educational tool to help children learn the fundamentals of software development.

According to Bitsight’s report, the Fengwo Group leverages Blockly to construct their sham websites. This innovative, yet ethically dubious, application of the tool allows even low-skilled operators to assemble complex functionalities by dragging and dropping code blocks, bypassing the need for in-depth understanding of the underlying code. This significantly reduces their operational costs and broadens the pool of individuals capable of contributing to their fraudulent schemes. As Bitsight’s report states, "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type. Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.”

The efficiency of this method was further highlighted by a Fengwo Group app developer, who noted the significant advantages of using Blockly. The developer remarked that "only a small number of highly-skilled developers are needed to build the template execution-unit images," and that "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs." This strategic approach allows the Fengwo Group to scale its operations rapidly and cost-effectively.

When an H96 streaming stick is selected for a particular fraud task, it receives the appropriate Blockly module. These modules can orchestrate a range of clandestine activities, including silently launching a web browser, navigating to specific websites, browsing pages, managing browser tabs, and, crucially, clicking on advertisements. To ensure that these TV boxes, masquerading as mobile phones, can reliably interact with and click on ads displayed on the AI-generated websites, the Fengwo Group employs a sophisticated system. The Bitsight report observed that they "fuse three vision and reasoning systems into a single interface," enabling the bots to accurately identify advertisements on web pages and navigate through sites in a manner that closely mimics human behavior.

Read This Before You Buy That TV Streaming Stick

A critical aspect of the H96 devices’ operation, as discovered by Bitsight, is their dual functionality. The devices were found to be either relaying residential proxy traffic or actively participating in ad fraud, but crucially, never both simultaneously. The system is designed to dynamically switch between these roles. When an HDMI signal is detected from an attached television—indicating the user’s intention to stream video content—the device typically functions as a residential proxy. However, when the TV is powered off, it reverts to its dormant state, awaiting instructions for ad fraud tasks. Falcó theorizes that this strategic design is employed because the ad fraud activities are considerably more resource-intensive and could potentially disrupt the device’s primary function of streaming video content.

Despite repeated warnings from the FBI and leading figures in the cybersecurity industry regarding the inherent security and privacy risks associated with these streaming devices, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to stock hundreds of different models and brands. These devices often come bundled with unofficial versions of Google’s Android operating system and are frequently marketed, often through online influencers, as a cost-effective solution for accessing a vast array of streaming services and live broadcasts without the need for subscriptions.

Beyond enlisting users’ TV boxes into ad fraud networks, these off-brand streaming devices almost universally come with pre-installed residential proxy software. This software effectively rents out the user’s Internet address to anonymous paying customers, whose activities can range from aggressive content scraping firms and ticket scalpers to outright cybercriminals. Furthermore, the inherent insecurity of these generic and inexpensive TV boxes, which often lack robust authentication mechanisms, makes them an open invitation for further malicious activity once connected to a home or office network. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes by exploiting a complex interplay of security vulnerabilities present in both the residential proxy software and the streaming devices themselves.

Bitsight’s analysis tracked approximately 38,000 TV boxes globally communicating with the expired Fengwo Group domain. Based on this figure, the report estimates that this ad fraud network generates revenues of nearly $50,000 per day, not including the substantial income derived from the residential proxy component of their business. Falcó, however, stressed that these estimates are deliberately conservative and are based on telemetry from only one of the Fengwo Group’s older core domains, suggesting the actual revenue could be significantly higher.

Read This Before You Buy That TV Streaming Stick

Regarding the Fengwo Group’s claim of possessing 120,000 "digital humans," Bitsight’s report posits that this might be an elaborate marketing ploy or a strategic maneuver to deflect attention from their clandestine operations. "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size," Falcó noted in the report. "This could also be the case here."

If the Fengwo Group indeed commands tens of thousands of "AI humans," it appears none have been assigned to handle inquiries from their own website. KrebsOnSecurity attempted to solicit comments from the Fengwo Group by emailing the contact address provided on their homepage. However, the email bounced back with the message, "Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now," further underscoring the evasive nature of the operation.

In conclusion, as Bitsight’s comprehensive analysis demonstrates, when it comes to TV boxes and streaming sticks, prudence is paramount. It is strongly advised to opt for name brands from reputable manufacturers and to exercise extreme caution with any applications installed on these devices. It is worth noting that many legitimate-looking apps can also bundle residential proxy software. Google provides clear instructions for consumers to verify if a device utilizes the official Android TV OS and has Play Protect certification. Furthermore, Synthient maintains a continuously updated list of IoT devices known to be shipped with pre-installed residential proxy software and other malicious applications, serving as a valuable resource for consumers seeking to avoid compromised devices. This list extends beyond streaming sticks and boxes, as the FBI has previously warned, with residential proxy software also being found in other popular consumer IoT devices from various brands, particularly digital photo frames. The message is clear: buyer beware, and always prioritize security and transparency when integrating new devices into your digital life.