A recent, groundbreaking analysis by security firm Bitsight has unveiled a sophisticated ad fraud operation deeply intertwined with popular, low-cost TV streaming devices, revealing that these devices not only secretly rent out user internet connections but also actively participate in an elaborate scheme to defraud online merchants and advertising networks by spoofing themselves as mobile phones interacting with AI-generated websites.

For years, security experts have issued stern warnings about the inherent risks associated with generic TV boxes promising boundless content streaming for a one-time fee, cautioning that they covertly exploit users’ internet connections by leasing them to unknown third parties. However, this latest research, spearheaded by Bitsight threat researcher Pedro Falcó, delves into a far more insidious aspect of these devices: their role in a sprawling ad fraud network. Falcó gained unprecedented access to this complex operation by acquiring an expired domain name previously used by a prominent brand of these streaming devices, known as H96, to coordinate fraudulent ad clicks.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Falcó’s investigation revealed that the domain he obtained was instrumental in collecting telemetry data from tens of thousands of H96 streaming sticks globally, gathering comprehensive hardware information and a complete list of installed applications. Upon scrutinizing the traffic directed to this domain, a startling pattern emerged: nearly all the data transmitted by these TV boxes claimed to originate from various mobile phone models, including those from well-known manufacturers like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falcó stated. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Further analysis uncovered that all these devices consistently reported having the same two applications installed. These apps were developed by Zhejiang Fengwo IoT Technology Ltd., a Chinese company founded in 2019 that operates an ad-publishing portfolio under the umbrella of Fengwo Group. Bitsight’s deep dive into Fengwo Group’s activities uncovered registered patents that precisely matched the internal workings of these suspect applications. "Bitsight TRACE identified several Hong Kong, Singapore, and single-person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group," Falcó detailed in a report released by Bitsight.

Falcó’s examination of the applications indicated their crucial role in orchestrating an ad fraud network. These H96 devices serve as a captive traffic source, systematically clicking on advertisements hosted on AI-generated websites managed by the Fengwo Group. Bitsight researchers discovered that these websites featured machine-generated news articles and graphics spanning diverse categories such as finance, health, education, gaming, and food blogs. Crucially, these sites only displayed advertisements when the visiting device matched the spoofed mobile profile originating from the H96 devices.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The domain for Fengwo Group, fwgcloud[.]com, boasts that the company is "redefining the boundaries of human-AI interaction" and claims to have developed over 120,000 "AI digital humans" available for rent for various purposes, ranging from emotional companionship to round-the-clock customer service and creative design. Falcó noted that this domain shared SSL certificate data with other domains associated with the phone-spoofing mechanism found on the H96 devices. Furthermore, an internal wiki platform on the Fengwo Group’s domain directly links the company to a proprietary implementation of Blockly, a visual programming language developed by Google, originally intended for educational purposes to help children learn software development.

According to Bitsight, Fengwo Group employees leverage Blockly to construct these sham websites. This approach allows individuals with limited technical expertise to assemble code by dragging and dropping blocks, bypassing the need to understand the underlying code’s functionality. "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type," Bitsight’s report explained. "Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use." One of Fengwo Group’s app developers even highlighted these advantages, remarking that "only a small number of highly-skilled developers are needed to build the template execution-unit images," and that "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs."

Falcó elaborated that if a user’s H96 streaming stick is selected for a particular fraud task, it will be programmed with the appropriate Blockly module, enabling actions such as silently launching a web browser, navigating websites, browsing pages, managing tabs, and clicking on advertisements. To ensure these TV boxes, masquerading as mobile phones, can effectively click on ads displayed on the AI-generated websites, the Fengwo Group integrates three vision and reasoning systems into a single interface. This sophisticated setup allows the bots to accurately identify advertisements on web pages and navigate sites in a manner remarkably similar to human behavior, as observed in the Bitsight report.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Bitsight’s investigation revealed a dual operational mode for the H96 devices: they either function as residential proxies or engage in ad fraud, but never simultaneously. Intriguingly, when an HDMI signal is detected, indicating the user intends to stream video content, the device typically operates as a residential proxy. Conversely, when the TV is off, it reverts to its ad fraud duties, awaiting new tasks. Falcó posits that this arrangement is likely to prevent the resource-intensive ad fraud activities from interfering with the device’s primary function of streaming video content.

Despite repeated warnings from the FBI and prominent figures in the cybersecurity industry regarding the security and privacy risks associated with these streaming devices, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to offer hundreds of models and brands. These devices often come pre-loaded with unofficial versions of Google’s Android operating system and are frequently marketed, sometimes through online influencers, as a cost-effective solution for accessing a vast array of streaming services and live broadcasts without subscription fees. Beyond enlisting user TV boxes into ad fraud networks, these off-brand streaming devices almost universally include pre-installed residential proxy software. This software effectively rents out the user’s internet address to anonymous paying customers, who range from aggressive content scraping firms and ticket scalpers to outright cybercriminals. Moreover, due to their inherent insecurity and lack of authentication, these generic and inexpensive TV boxes pose a significant risk when connected to home or office networks, inviting further malicious activity. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly compromised millions of TV boxes by exploiting a combination of security vulnerabilities in both the residential proxy software and the streaming devices themselves.

Bitsight tracked approximately 38,000 TV boxes globally communicating with the defunct Fengwo Group domain. Based on this number, the report estimates that this ad fraud network generates revenues of close to $50,000 per day, not including the substantial income from the residential proxy operations. However, Falcó stressed that these figures are conservative estimates, derived from telemetry data of only one of Fengwo Group’s older core domains. Regarding Fengwo Group’s claim of possessing 120,000 "digital humans," Bitsight’s report suggests this may be a clever marketing tactic or a means to deflect attention from the company’s actual operations. "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size," Falcó wrote in the report. "This could also be the case here."

Read This Before You Buy That TV Streaming Stick – Krebs on Security

If Fengwo Group indeed commands tens of thousands of "AI humans," they do not appear to have allocated any resources to responding to inquiries from their own website. KrebsOnSecurity attempted to contact Fengwo Group via the email address provided on their homepage, but the message bounced back with the notification: "Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now."

As Bitsight’s analysis clearly demonstrates, when it comes to TV boxes and streaming sticks, it is advisable to opt for reputable name brands from trusted manufacturers. Furthermore, users should exercise caution and be judicious with any applications they choose to install on these devices, as many can bundle residential proxy software. Google advises consumers to verify if a device is built with the official Android TV OS and Play Protect certification by following their provided instructions. Additionally, Synthient maintains a running list of IoT devices known to ship with pre-installed residential proxy software and other malicious applications. It’s important to note that this list extends beyond streaming sticks and boxes; as the FBI has warned, residential proxy software has also been discovered in other popular consumer IoT devices from less common brands, particularly digital photo frames.