Executive Overview
For years, security researchers and law enforcement agencies have sounded the alarm regarding the hidden dangers of generic, unbranded streaming hardware. These inexpensive, plug-and-play TV boxes—often marketed online by social media influencers as a hack for unlocking unlimited, free access to premium entertainment, live sports, and subscription-based streaming services for a single, low upfront fee—hide a sinister reality. While consumers believe they are scoring a bargain, they are unknowingly inviting a Trojan horse into their home networks.
Security experts have long warned that these pre-infected devices covertly weaponize home internet connections, renting out bandwidth to anonymous third parties through residential proxy software. However, a groundbreaking investigation by threat intelligence firm Bitsight reveals a much darker, far more sophisticated operation. These generic streaming boxes are not merely silent accomplices in data relay; they are active, autonomous participants in a sprawling, automated cybercrime ring.
According to Bitsight threat researcher Pedro Falé, popular budget streaming devices—specifically units belonging to the ubiquitous "H96" hardware family—routinely spoof their digital identities to masquerade as high-end mobile phones. These captive devices are systematically harnessed to execute fake ad clicks on a vast network of AI-generated websites. Controlled by a mainland Chinese entity known as the Fengwo Group, this criminal ecosystem defrauds online merchants and advertising networks out of tens of thousands of dollars daily.
This deep-dive investigation examines how these pre-infected streaming sticks operate, the ingenious use of visual programming languages to scale ad fraud, the mechanics of switching between proxy traffic and ad-click botnets, and why major e-commerce platforms continue to provide a storefront for these cybernetic security threats.
Detailed Chronology: Unmasking the H96 Ad Fraud Operation
The anatomy of this sophisticated ad fraud scheme came to light through a combination of serendipity, forensic persistence, and technical ingenuity.
The Expired Domain Discovery
The breakthrough occurred when Pedro Falé, a senior threat researcher at Bitsight, registered an expired domain name that had previously been utilized for telemetry by H96 streaming sticks. For years, this domain had quietly collected hardware diagnostic data and comprehensive inventories of installed applications from tens of thousands of H96 devices plugged into television sets globally.
Upon acquiring the domain, Falé gained an unprecedented vantage point, peering directly into the infrastructure of a complex ad fraud network. As incoming telemetry data began to flood his servers, Falé noticed a glaring discrepancy. The streaming boxes—hardware explicitly designed to remain stationary and connect to home networks via Ethernet or Wi-Fi—were reporting network handshakes and device profiles claiming to be mobile phones from prominent global manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.

“We noticed something was wildly wrong,” Falé remarked during his debrief with security journalists. “Multiple devices reporting to this factory Android TV Box backdoor were simply claiming to be phones.”
Tracing the Culprits: Zhejiang Fengwo IoT Technology
Drilling deeper into the telemetry data, Falé discovered that nearly all the reporting devices shared an identical configuration of two pre-installed software applications. Code attribution analysis tracked the provenance of these applications to Zhejiang Fengwo IoT Technology Ltd., an enterprise established in 2019 in mainland China that operates a sprawling digital portfolio under the banner of the Fengwo Group.
Further corporate and technical surveillance revealed that the Fengwo Group had registered multiple software patents matching the exact behavioral patterns and obfuscation techniques embedded within the H96 apps. Bitsight’s proprietary threat-hunting infrastructure, Bitsight TRACE, successfully mapped out a web of shell entities spanning Hong Kong, Singapore, and various single-person legal fronts designed to launder and collect monetization revenue, ultimately tracing the entire operation back to Zhejiang Fengwo.
The AI-Generated Web Ecosystem
The apps discovered on the H96 devices served as orchestrators for a captive traffic generation ring. When commanded, the boxes were directed to visit a network of sham websites operated by the Fengwo Group.
A forensic audit of these websites revealed a startling production scale: they were entirely machine-generated, featuring AI-crafted news articles, financial blogs, health advice columns, gaming write-ups, and music reviews. Crucially, Bitsight discovered that these pages were intentionally engineered with conditional logic—none of the sites displayed advertisements unless the visiting browser fingerprint matched the spoofed mobile profile of an infected H96 streaming box.
Supporting Context & Metrics: Code Blocks, Botnets, and Business Models
The operational efficiency of the Fengwo Group relies heavily on reducing overhead and technical barriers to entry, a strategy that marries modern generative AI with simplified software development.
Democratizing Fraud via Blockly
The primary domain utilized by the Fengwo Group—fwgcloud[.]com—fronts as a legitimate technology enterprise, claiming to "redefine the boundaries of human-AI interaction." The site boasts an inventory of over 120,000 "AI digital humans" available for rent, supposedly serving emotional companionship, creative design, and round-the-clock customer service. However, Bitsight’s technical analysis suggests this high-tech persona is largely a smoke screen designed to mask illicit activities.

Behind the public-facing facade, internal platform wikis linked to the Fengwo Group revealed a proprietary implementation of Blockly, an open-source visual programming language originally built by Google to teach children how to code.
Rather than requiring complex, hand-written scripts, low-skilled operators within the Fengwo organization use Blockly’s graphical drag-and-drop interface. Workers can assemble modular blocks of code to define distinct ad-fraud routines without understanding the underlying technical architecture. Once saved, these visual routines are automatically exported as JavaScript files and uploaded to cloud-based storage buckets (such as Amazon S3), ready to be deployed instantly across the botnet.
As Bitsight’s published report notes:
"An operator can drag blocks together in their Blockly editor to define each fraud routine given a task type. Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use."
Internal communications recovered by researchers captured a Fengwo developer boasting about this cost-cutting model: only a handful of elite developers were required to build the foundational template execution units, while lower-skilled operators could deploy them at scale.
Vision and Reasoning Systems
To bypass sophisticated anti-fraud filters deployed by advertising networks, simple script-based clicking is insufficient. The Fengwo framework integrates advanced vision and reasoning systems into a single automated interface.
When an H96 device receives a task module, it silently launches an automated web browser, navigates through the AI-generated news articles, manages active tabs, and correctly identifies advertisements using visual recognition logic—mimicking authentic human browsing behavior down to the mouse movements and dwell times.

The Duality of the Device: Proxy by Day, Fraud by Night
One of the most revealing insights from Bitsight’s telemetry analysis is how the hardware balances its multiple malicious responsibilities. Researchers observed that individual H96 devices were never utilized for residential proxy relay and ad fraud simultaneously.
Instead, the devices exhibit a clever operational switch:
- TV On (Active Streaming Mode): When an attached television transmits an active HDMI signal—signifying that the human owner is actually watching content—the box ceases its heavy background tasks and pivots strictly to functioning as a residential proxy, routing external web traffic through the user’s home IP address.
- TV Off (Idle Mode): The moment the television is turned off, the box senses the loss of the HDMI signal and immediately switches gears, dedicating its processing power and network connection to executing ad fraud workloads.
Security experts believe this division of labor is strictly pragmatic. Ad fraud operations are resource-intensive, consuming significant CPU, memory, and bandwidth. Running them concurrently with video streaming would likely cause stuttering, buffering, or total hardware failure, immediately alerting the unsuspecting consumer that something was amiss with their "free streaming box."
Financial Scale and Daily Revenue
Conservative estimates derived from telemetry capturing approximately 38,000 H96 boxes phoning home to a single expired Fengwo domain indicate that the ad fraud network generates close to $50,000 in daily revenue.
When factoring in additional revenue streams—such as the leasing of residential bandwidth to illicit proxy networks—the actual financial footprint of the enterprise is substantially higher. Falé emphasized that these calculations are heavily conservative, reflecting data from just one older core domain out of a broader, multi-pronged infrastructure.
Official Statements and Industry Warnings
The revelations surrounding the Fengwo Group corroborate longstanding warnings issued by international law enforcement and global cybersecurity leaders.
The FBI and Synthient Warnings
In alerts issued throughout recent years, the Federal Bureau of Investigation (FBI) has explicitly warned consumers about the cybersecurity and privacy dangers posed by unvetted, internet-connected Internet of Things (IoT) devices, particularly cheap media players and digital photo frames.

These warnings are underscored by ongoing tracking from threat intelligence firms like Synthient. In January, Synthient exposed how aggressive botnets—such as the infamous Kimwolf botnet—rapidly enslaved millions of cheap streaming boxes by exploiting security vulnerabilities embedded within both pre-installed residential proxy software and the base Android firmware.
Despite these high-profile warnings, major global e-commerce titans—including Amazon, Best Buy, and Newegg—continue to host third-party marketplace vendors selling hundreds of unbranded streaming boxes. These devices routinely bundle unofficial, unpatched modifications of Google’s Android operating system, often promoted via viral social media campaigns as loopholes for free, subscription-free entertainment.
Reaching Out to the Void
In an attempt to secure comment regarding Bitsight’s findings, KrebsOnSecurity contacted the Fengwo Group using the official corporate email address listed on fwgcloud[.]com. The inquiry was met with an automated delivery failure notice:
"Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now."
Whether this mailbox saturation was the result of incoming media inquiries, automated spam, or the sheer weight of a collapsing ad fraud infrastructure remains unconfirmed.
Future Outlook and Defensive Recommendations
As the intersection of cheap consumer IoT hardware, artificial intelligence, and automated cybercrime matures, the threat landscape continues to evolve. Cybercriminals are no longer satisfied with merely stealing bandwidth; they are building autonomous, AI-driven economic syndicates capable of manufacturing fake digital demand at scale.
The Broader Smart TV Ecosystem
The problem is not strictly limited to obscure, unbranded Chinese TV sticks. Recent industry disclosures—such as LG’s proactive moves to ban residential proxy software from smart TV applications—demonstrate that mainstream manufacturers are also grappling with the infiltration of malicious software ecosystems.

Actionable Guidance for Consumers and Enterprises
To mitigate the severe risks posed by pre-infected IoT devices, security professionals recommend a strict hierarchy of digital hygiene:
- Stick to Reputable Brands: Consumers should strictly purchase streaming hardware from globally recognized manufacturers (such as Google TV, Apple TV, Roku, or Amazon Fire TV devices bought directly from verified official stores).
- Verify OS Integrity: Google provides explicit documentation and certification checks allowing users to confirm whether a device is running an official, Google Play Protect-certified version of the Android TV operating system.
- Isolate IoT Networks: Home and enterprise users should never place unvetted budget hardware on their primary local area network (LAN). Deploying a segregated guest network or a dedicated VLAN for IoT devices ensures that if a streaming box is compromised, attackers cannot pivot to sensitive computers, Network-Attached Storage (NAS) drives, or personal mobile phones.
- Consult Public Threat Databases: Organizations like Synthient maintain public repositories (such as GitHub tracking lists) identifying specific consumer product names and IoT hardware known to ship with pre-installed residential proxy and ad fraud software.
Until regulatory bodies and major online marketplaces implement stringent pre-market security vetting for third-party IoT hardware, the onus remains on the consumer to ensure that their living room entertainment center does not double as an automated worker in a global cybercrime syndicate.
