Security experts have long warned about the dangers lurking within generic TV boxes that promise unlimited content for a one-time fee, revealing they secretly exploit users’ internet connections. A groundbreaking new analysis by threat researcher Pedro Falcó of Bitsight uncovers a far more insidious operation: these devices are routinely masquerading as mobile phones, clicking on ads on AI-generated websites to defraud online merchants and advertising networks.
Falcó’s investigation began when he acquired an expired domain name previously used by a popular brand of these streaming devices, H96. This domain served as a central hub for telemetry, collecting detailed hardware information and app lists from tens of thousands of H96 devices globally. Upon inspecting the data flowing to the domain, Falcó was astonished to discover that nearly all these TV boxes were reporting themselves as mobile phones from various manufacturers like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falcó stated. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Further analysis revealed that all these spoofing devices had two specific apps installed, both developed by Zhejiang Fengwo IoT Technology Ltd., a mainland China-based company operating an ad-publishing network known as Fengwo Group. This company has secured patents directly related to the functionality of these apps. Falcó detailed in a Bitsight report, "Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group."
The apps, according to Falcó’s analysis, are instrumental in coordinating an ad fraud network. They leverage the H96 devices as a captive audience, forcing them to click on advertisements hosted on AI-generated websites managed by the Fengwo Group. These websites feature machine-generated content across diverse categories, including finance, health, education, gaming, music, and food blogs. Crucially, ads only appear on these sites when a visiting device matches the spoofed mobile profile of the H96 devices, indicating a targeted fraud operation.
The Fengwo Group’s domain, fwgcloud[.]com, boasts about "redefining the boundaries of human-AI interaction" and claims to offer over 120,000 "AI digital humans" for rent, suitable for a range of services from companionship to customer support and design. Falcó noted that this domain shares SSL certificate data with the domains associated with the phone-spoofing apps on H96 devices. An internal wiki on the Fengwo Group’s domain further links them to a custom implementation of Blockly, a visual programming language developed by Google to teach children coding.

Bitsight’s report highlights that Fengwo Group employees utilize Blockly to construct these fraudulent websites. This allows operators with limited technical expertise to assemble code blocks, effectively automating the creation of complex fraud routines without needing to understand the underlying programming. "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type," the report explains. "Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use." One Fengwo Group app developer even commented on the efficiency of this method, stating that it significantly reduces operating costs by requiring fewer highly-skilled developers.
When an H96 device is selected for a specific fraud task, it receives the appropriate Blockly module, enabling actions such as silently launching web browsers, visiting websites, navigating pages, managing tabs, and clicking on ads. To ensure these spoofed mobile devices can effectively click on ads, the Fengwo Group employs a sophisticated system that integrates three vision and reasoning engines, allowing the bots to accurately identify ads and interact with websites in a human-like manner.
TV ON? PROXY. TV OFF? AD FRAUD.

Bitsight’s findings reveal a dual-purpose operation: the H96 devices are either relaying residential proxy traffic or engaging in ad fraud, but not simultaneously. When an HDMI signal is detected, indicating the user is actively streaming, the device typically functions as a residential proxy. Once the TV is off, it reverts to performing ad fraud tasks, likely because ad fraud is more resource-intensive and could disrupt video streaming.
Despite repeated warnings from the FBI and security experts regarding the risks associated with these streaming devices, major e-commerce platforms continue to offer a wide array of models. These devices often come pre-loaded with unofficial versions of Android and are marketed, sometimes through online influencers, as a cost-effective way to access numerous streaming services and live broadcasts without subscriptions.
Beyond enlisting user devices in ad fraud networks, these off-brand streaming devices almost invariably include pre-installed residential proxy software. This software essentially rents out the user’s internet address to anonymous customers, ranging from data scraping firms and ticket scalpers to cybercriminals. Furthermore, the inherent insecurity of these devices, often lacking proper authentication, makes them easy targets for exploitation. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly compromised millions of TV boxes by exploiting vulnerabilities in both the proxy software and the devices themselves.

SHOW ME THE MONEY
Bitsight tracked approximately 38,000 H96 devices globally communicating with an expired Fengwo Group domain. Based on this data, the ad fraud network is estimated to generate nearly $50,000 per day, not including revenue from the residential proxy operations. However, Falcó stresses that these figures are conservative, based on telemetry from only one older Fengwo Group domain.
The Fengwo Group’s claim of possessing 120,000 "digital humans" might be a marketing ploy or a tactic to obscure their true operations. Falcó suggests, "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size. This could also be the case here."

Attempts to contact the Fengwo Group via email proved futile, with messages bouncing back due to a full inbox, suggesting a lack of customer service or an intentional obfuscation.
In conclusion, Bitsight’s analysis strongly advises consumers to opt for reputable brands from trusted manufacturers when purchasing TV boxes and streaming sticks. Users should also exercise extreme caution with any apps installed on these devices, as many can bundle residential proxy software. Google provides instructions for verifying if a device runs the official Android TV OS with Play Protect certification. Additionally, Synthient maintains a list of IoT devices known to ship with malicious software pre-installed, including other consumer devices beyond streaming boxes, such as digital photo frames, reinforcing the FBI’s warnings about the widespread security risks in the IoT landscape.

