Security experts have long warned about the dangers lurking within generic TV streaming boxes, often marketed with promises of unlimited content for a one-time fee. These devices, far from being a simple gateway to entertainment, have been discovered to secretly exploit users’ internet connections by renting them out to unknown third parties. A groundbreaking new analysis, however, reveals an even more insidious practice: these devices are routinely masquerading as mobile phones, actively clicking on advertisements displayed on AI-generated websites. This elaborate scheme, uncovered by security firm Bitsight, is designed to defraud online merchants and advertising networks on a massive scale.
Pedro Falé, a threat researcher at Bitsight, gained unprecedented access into this sprawling ad fraud network by acquiring an expired domain name. This domain had previously served as a command-and-control center for a particularly popular brand of these suspect streaming devices, known as H96. By registering the domain, Falé was able to observe the telemetry data being transmitted from tens of thousands of H96 streaming sticks globally. What he found was deeply concerning: nearly all of these devices, when reporting their identity, claimed to be mobile phones from a variety of manufacturers, including prominent brands like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falé stated. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Further investigation by Falé revealed a consistent pattern. All the devices reporting to the compromised domain had the same two applications installed. These apps were developed by Zhejiang Fengwo IoT Technology Ltd., a Chinese company founded in 2019, which operates an advertising platform under the umbrella of the Fengwo Group. Bitsight’s analysis of the Fengwo Group’s intellectual property uncovered multiple patents directly correlating with the functionality of these suspicious applications. Falé elaborated in a Bitsight report, "Bitsight TRACE identified several Hong Kong, Singapore, and single-person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group."
The H96 devices, acting as a captive traffic source, are orchestrated by these applications to generate fraudulent ad clicks on AI-generated websites operated by the Fengwo Group. Bitsight’s researchers discovered that these websites featured machine-generated news articles and graphics across diverse categories such as finance, health, education, gaming, music, and food blogs. Crucially, these sites only displayed advertisements when visited by devices that matched the spoofed mobile profiles emanating from the H96 devices.
The Fengwo Group’s online presence, particularly their domain fwgcloud[.]com, boasts about "redefining the boundaries of human-AI interaction" and claims to offer over 120,000 "AI digital humans" for rent, catering to needs ranging from emotional companionship to round-the-clock customer service and creative design. However, Falé’s analysis uncovered a deeper connection between the Fengwo Group’s domain and the ad fraud operation. The domain shared SSL certificate data with other domains linked to the apps found on H96 devices, specifically those responsible for the phone spoofing mechanism. More strikingly, an internal wiki platform on the Fengwo Group’s domain directly linked the company to a proprietary implementation of Blockly, a visual programming language developed by Google, originally intended to teach children software development.

Bitsight’s report details how Fengwo Group employees leverage Blockly to construct these sham websites. This allows operators with minimal technical expertise to assemble code blocks within the Blockly editor, effectively creating fraudulent routines without needing to understand the underlying code’s intricacies. As Bitsight notes, "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type. Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use." This approach significantly reduces the company’s operating costs, as confirmed by one of the Fengwo Group’s app developers who stated that "only a small number of highly-skilled developers are needed to build the template execution-unit images," while those creating execution units from templates have "significantly lower technical requirements."
When an H96 streaming stick is selected for a particular fraud task, it receives the appropriate Blockly module, enabling it to perform actions such as silently launching a web browser, navigating websites, browsing pages, managing tabs, and clicking on ads. To ensure these TV boxes, masquerading as mobile phones, can effectively click on ads, the Fengwo Group employs a sophisticated integration of "three vision and reasoning systems into a single interface." This allows the fraudulent bots to accurately identify advertisements on web pages and navigate sites in a manner that closely mimics human behavior, as highlighted in the Bitsight report.
A critical aspect of the H96 devices’ operation, as identified by Bitsight, is their dual functionality. These devices are either utilized for relaying residential proxy traffic or for participating in ad fraud, but never simultaneously. The analysis indicates a deliberate switch: when an HDMI signal is detected, signaling the user’s intent to stream video content, the device typically functions as a residential proxy. However, when the television is off, the device reverts to its ad fraud duties. Falé posits this arrangement is in place because ad fraud activities are more resource-intensive and could potentially disrupt the primary function of streaming video content.

Despite persistent warnings from the FBI and cybersecurity leaders regarding the security and privacy risks associated with these streaming devices, major e-commerce platforms such as Amazon, Best Buy, and Newegg continue to offer a vast array of models and brands. These devices often come pre-loaded with unofficial versions of Google’s Android operating system and are frequently promoted through online influencers as a cost-effective way to access a wide range of streaming services and live broadcasts without subscription fees.
Beyond enlisting users’ TV boxes into ad fraud networks, these off-brand streaming devices almost invariably come with pre-installed residential proxy software. This software effectively rents out the user’s internet address to anonymous paying customers, whose activities range from aggressive content scraping and ticket scalping to outright cybercriminal enterprises. Furthermore, the inherent insecurity and lack of authentication in these generic, low-cost TV boxes make them an open invitation for further network compromise. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes by exploiting a complex interplay of security vulnerabilities present in both the residential proxy software and the streaming devices themselves.
Bitsight’s investigation tracked approximately 38,000 TV boxes globally communicating with the expired Fengwo Group domain. Based on this figure, the report estimates that this ad fraud network generates revenue approaching $50,000 per day, excluding the substantial income derived from the residential proxy side of the business. Falé, however, stressed that these figures are highly conservative and are based on telemetry from only one of the Fengwo Group’s older core domains.

Regarding the Fengwo Group’s claim of possessing 120,000 "digital humans," Bitsight’s report suggests this may be a sophisticated marketing ploy or a tactic to obscure the true nature of the company’s operations. Falé noted, "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size. This could also be the case here."
If the Fengwo Group indeed commands tens of thousands of "AI humans," none appear to be dedicated to responding to inquiries from their own website. Attempts to contact the Fengwo Group via the email address provided on their homepage resulted in a bounced message indicating a full inbox.
Bitsight’s analysis strongly advises consumers to exercise caution when purchasing TV boxes and streaming sticks. It is recommended to opt for reputable brands from trusted manufacturers and to be highly selective about any applications installed on the device, as even legitimate-looking apps can bundle residential proxy software. Google provides instructions for consumers to verify if a device is built with the official Android TV OS and Play Protect certification. Additionally, Synthient maintains a public list of IoT devices known to ship with residential proxy software and other malicious applications pre-installed. This list extends beyond streaming sticks and boxes, as the FBI has warned that residential proxy software has also been found in other popular consumer IoT devices from various brands, particularly digital photo frames.

