Security experts have long warned about the dangers of cheap, generic TV streaming boxes that promise limitless content for a one-time fee, revealing they often secretly exploit your internet connection for illicit purposes, but a new groundbreaking analysis uncovers an even more sophisticated scheme: these devices are now actively impersonating mobile phones to generate fraudulent ad clicks on AI-generated websites, funneling profits to a sprawling network defrauding online merchants and advertising platforms.

Pedro Falcão, a threat researcher at the security firm Bitsight, gained unprecedented access into this vast ad fraud operation by acquiring an expired domain name previously used to orchestrate fake ad clicks from a particularly popular brand of these suspicious streaming devices, known as H96. Falcão’s investigation, detailed in a comprehensive report, reveals a disturbing pattern of deception and exploitation that goes far beyond the initial concerns about unauthorized content streaming.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The domain Falcão secured was once utilized for telemetry, collecting detailed hardware information and a complete list of installed applications from tens of thousands of H96 streaming sticks globally. However, upon examining the traffic directed to this domain, Falcão was astonished to discover that nearly all the TV boxes were reporting themselves as mobile phones from various manufacturers, including prominent brands like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falcão stated. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Further scrutiny revealed that all these devices consistently reported having the same two applications installed, both developed by Zhejiang Fengwo IoT Technology Ltd., a Chinese company founded in 2019. This entity operates an extensive ad-publishing network under the umbrella of Fengwo Group. Bitsight’s investigation uncovered that Fengwo Group has registered numerous patents directly corresponding to the internal mechanisms of these suspicious apps. Falcão elaborated in his report, "Bitsight TRACE identified several Hong Kong, Singapore, and single-person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group."

The analysis of these applications indicates they are instrumental in coordinating an ad fraud network. The H96 devices serve as a captive source of traffic, generating artificial clicks on advertisements hosted on AI-generated websites operated by Fengwo Group. These websites, Bitsight discovered, feature machine-generated news articles and graphics spanning diverse categories such as finance, health, education, gaming, music, and food blogs. Crucially, these sites only displayed advertisements when visited by devices mimicking the spoofed mobile profiles of the H96 devices.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Intriguingly, the domain for Fengwo Group, fwgcloud[.]com, boldly claims the company is "redefining the boundaries of human-AI interaction" and boasts the creation of over 120,000 "AI digital humans" available for rent for various purposes, from emotional companionship to round-the-clock customer service and creative design. However, Falcão noted a more technical connection: the Fengwo Group’s domain shares SSL certificate data with other domains linked to the phone-spoofing mechanism within the H96 devices’ apps. Furthermore, an internal wiki platform on the Fengwo Group’s domain directly connects the company to a proprietary implementation of Blockly, a visual programming language developed by Google to facilitate learning software development, particularly for children.

Bitsight’s findings suggest that Fengwo Group employees leverage Blockly to construct their fraudulent websites. This allows operators with minimal technical expertise to assemble code by dragging and dropping blocks, bypassing the need to understand the underlying code’s functionality. "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type," the Bitsight report explains. "Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use." This approach significantly reduces operational costs by lowering the technical skill requirements for developers.

Falcão explained that when a user’s H96 streaming stick is selected for a specific fraud task, it receives the appropriate Blockly module, which can instruct it to silently launch a web browser, navigate to websites, browse pages, manage tabs, and click on ads. To ensure these devices, masquerading as mobile phones, can reliably interact with ads on the AI-generated websites, Fengwo Group employs a sophisticated integration of three vision and reasoning systems. This allows the automated bots to accurately identify advertisements and navigate web pages in a manner that closely mimics human behavior.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The dual nature of these H96 devices was also brought to light by Bitsight’s investigation. The devices were found to be either relaying residential proxy traffic or engaging in ad fraud, but never simultaneously. The analysis indicated that when an HDMI signal from an attached television is detected – signaling the user’s intent to stream video – the device typically functions as a residential proxy. However, when the TV is off, it reverts to its ad fraud duties. Falcão theorizes this separation is implemented because ad fraud activities are more resource-intensive and could potentially disrupt the device’s primary function of streaming video content.

Despite repeated warnings from the FBI and leading cybersecurity firms about the security and privacy risks associated with these streaming devices, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to offer a vast array of models. These devices often come pre-loaded with unofficial versions of Google’s Android operating system and are frequently marketed, often through online influencers, as a cost-effective way to access a wide range of streaming services and live broadcasts without subscription fees.

Beyond their involvement in ad fraud networks, these off-brand streaming devices almost universally come with pre-installed residential proxy software. This software effectively rents out the user’s internet address to anonymous paying customers, who range from aggressive web scraping companies and ticket scalpers to outright cybercriminals. The inherent insecurity of these generic, inexpensive TV boxes, coupled with a lack of authentication, makes them an open invitation for further network intrusions. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes by exploiting a combination of security vulnerabilities within both the residential proxy software and the streaming devices themselves.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Bitsight’s tracking identified approximately 38,000 TV boxes globally communicating with the expired Fengwo Group domain. Based on this figure, the report estimates that this ad fraud network generates close to $50,000 per day, not including the substantial revenue derived from the residential proxy operations. However, Falcão stressed that these figures are conservative and based on telemetry from only one of Fengwo Group’s older core domains. Regarding Fengwo Group’s claim of possessing 120,000 "digital humans," Bitsight’s report suggests this might be a strategic marketing ploy or a method to deflect attention from their illicit activities. "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size," Falcão noted. "This could also be the case here."

Should Fengwo Group indeed command tens of thousands of "AI humans," they appear to have not allocated any resources to responding to inquiries from their own website. Attempts by KrebsOnSecurity to solicit comment from Fengwo Group via the contact email provided on their homepage were met with a bounced-back message stating, "Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now."

As Bitsight’s analysis starkly illustrates, when it comes to TV boxes and streaming sticks, it is strongly advised to opt for reputable brands from trusted manufacturers. Furthermore, users should exercise caution and be selective with any applications they choose to install on these devices, as many can also bundle residential proxy software. Google provides guidance for consumers to verify if a device is built with the official Android TV OS and Play Protect certification. Additionally, Synthient maintains a public list of IoT devices known to ship with residential proxy software and other malicious applications pre-installed, highlighting that this issue extends beyond streaming devices to other consumer IoT products like digital photo frames.