Silent Hijacking: How Generic Android TV Boxes Fuel a Multimillion-Dollar AI Ad Fraud Empire

Share
Silent Hijacking: How Generic Android TV Boxes Fuel a Multimillion-Dollar AI Ad Fraud Empire

Executive Overview

For years, cybersecurity analysts and intelligence agencies have raised alarms regarding the proliferation of generic, unbranded streaming devices sold across major e-commerce platforms. Marketed as economical solutions for accessing boundless content libraries and live television broadcasts for a single, low fee, these "plug-and-play" Android TV boxes have long been suspected of harboring covert monetization mechanisms. While prior investigations primarily exposed these devices as unauthorized conduits that quietly rent out residential internet connections as proxy nodes to anonymous third parties, a groundbreaking new threat analysis reveals a far more insidious architecture.

Security researchers at Bitsight have uncovered a sophisticated, industrial-scale advertising fraud network orchestrated by a mainland Chinese entity known as the Fengwo Group. Operating through pre-installed applications deeply embedded within popular generic streaming hardware—specifically devices sold under the H96 brand—this illicit infrastructure goes far beyond simple bandwidth resale. The operation systematically spoofs high-end mobile devices, navigating AI-generated web properties, and aggressively clicking on programmatic advertisements to defraud online merchants and ad networks.

By taking advantage of expired telemetry domains, threat researchers gained unprecedented visibility into a vast botnet comprising tens of thousands of infected units globally. The operation leverages clever automation tools, low-code frameworks like Google’s Blockly, and advanced computer vision to mimic human browsing behavior. Generating an estimated $50,000 daily from ad fraud alone—excluding supplementary revenues generated by residential proxy traffic—this discovery underscores the severe systemic risks inherent in unregulated Internet of Things (IoT) hardware and highlights the challenges regulators and retailers face in securing the digital supply chain.


Detailed Chronology & Investigative Discovery

The unravelling of the Fengwo Group’s ad fraud empire began when Pedro Falé, a threat researcher with security firm Bitsight, turned his attention to an expired domain name historically utilized for hardware telemetry by the H96 brand of Android TV streaming sticks.

Uncovering the Spoofed Infrastructure

For years, tens of thousands of H96 streaming devices plugged into television sets around the globe had been communicating with this specific domain to periodically transmit hardware profiles and installed application lists. When Falé successfully registered the expired domain name, he did not merely capture stray telemetry data; he opened a window into the inner workings of a complex command-and-control (C2) and ad-fraud coordination mechanism.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Upon inspecting the incoming traffic routed to the domain, Falé noticed an immediate anomaly. Devices identifying themselves as factory Android TV boxes were transmitting telemetry data claiming to be high-end mobile smartphones from globally recognized manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.

"We noticed something was wildly wrong," Falé remarked during interviews detailing the discovery. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Tracing the Culprits: Zhejiang Fengwo IoT Technology

A deeper forensic inspection of the traffic revealed that all spoofing devices shared the exact same two pre-installed applications. Code analysis traced these applications back to a mainland China-based enterprise founded in 2019: Zhejiang Fengwo IoT Technology Co., Ltd., operating publicly under the banner of the Fengwo Group.

Bitsight’s threat intelligence platform, Bitsight TRACE, tracked the financial monetization trails back through a web of shell entities spanning Hong Kong, Singapore, and single-person legal fronts. Ultimately, researchers tied the complex corporate structure directly to the mainland Chinese parent company.

The investigation revealed that the applications found on the H96 streaming sticks functioned as orchestration modules for an automated ad fraud ecosystem. The infected TV boxes served as a captive, unyielding traffic source programmed to visit specific web pages, cycle through tabs, and execute programmatic ad clicks.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The Illusion of "AI Digital Humans"

Investigating the corporate front behind the operation, researchers analyzed the primary domain operated by the Fengwo Group—fwgcloud[.]com. The platform’s public-facing narrative claimed to be "redefining the boundaries of human-AI interaction," boasting a portfolio of over 120,000 "AI digital humans" available for rent to handle everything from 24/7 customer service and emotional companionship to creative design tasks.

However, Bitsight’s technical analysis concluded that this futuristic artificial intelligence marketing veneer was likely a strategic facade designed to obscure the company’s true, illicit mechanics. Shared SSL certificate data linked the cloud domain directly to the application infrastructure responsible for the mobile phone spoofing mechanisms found on the H96 boxes. Furthermore, internal wiki platforms discovered on associated domains directly linked the Fengwo Group to proprietary implementations of Google’s Blockly—a visual programming language originally developed to help children learn software development fundamentals.


Supporting Context & Metrics: The Mechanics of Automated Fraud

The efficiency of the Fengwo Group’s operation lies in its utilization of low-code development frameworks and automated browsing routines, which drastically reduce operational overhead while maximizing fraudulent ad revenue.

Low-Code Infrastructure and the Blockly Integration

According to Bitsight’s telemetry and document analysis, the Fengwo Group leverages Google’s Blockly framework to streamline the creation of sham web properties and fraud task routines. By utilizing a visual drag-and-drop interface, low-skilled operators can assemble complex instruction sets without needing an advanced understanding of the underlying JavaScript or backend execution logic.

  • Template Execution Units: Highly skilled core developers build foundational template execution units.
  • Simplified Routine Deployment: Less-skilled operational staff drag code blocks together in the Blockly editor to define specific ad-fraud routines based on required task types.
  • Export and Execution: Once saved, routines are exported automatically as JavaScript and uploaded to Amazon S3 buckets, from where they are pushed down to target streaming devices.

This division of labor allows the enterprise to operate at scale while keeping staffing requirements and operational costs remarkably low. Internal communications discovered by researchers highlighted this exact business model, with developers noting that template-based task generation significantly reduced technical thresholds for day-to-day operations.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Human-Like Navigation via Vision Systems

To bypass automated fraud detection filters implemented by advertisers and programmatic ad networks, the Fengwo Group’s botnet does not simply rely on brute-force, mindless clicking. Instead, the framework integrates multiple vision and reasoning systems into a unified interface.

When an H96 device is selected for a fraud task, the pushed Blockly module silently launches a background web browser. The system navigates AI-generated web properties—which feature machine-generated news articles, financial blogs, health tips, and gaming reviews—and utilizes computer vision algorithms to correctly identify advertisements. The bots then scroll, linger, and interact with the page just like a human user would, ensuring the validity of the ad impression in the eyes of automated traffic verification systems.

The Dual-State Operation: Proxy by Day, Fraud by Night

One of the most revealing architectural discoveries made by Bitsight is that the H96 streaming boxes operate under a strict resource-allocation schedule. Devices were observed either relaying residential proxy traffic or executing ad fraud routines, but never performing both tasks simultaneously.

Researchers noted a distinct behavioral trigger:

  • TV On (HDMI Signal Detected): When the user turns on the television and the box detects an active HDMI signal—indicating human intent to stream media content—the device ceases ad-fraud operations and functions primarily as a residential proxy node.
  • TV Off (Idle State): Once the television is powered down, the streaming stick seamlessly switches back to waiting for, and executing, ad fraud jobs.

This careful throttling is designed to prevent the resource-intensive ad-fraud scripts from degrading system performance, which might otherwise alert the user that their streaming device has been compromised.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Scale and Financial Impact

While Bitsight’s monitoring focused primarily on a single, older core domain associated with the Fengwo Group, telemetry revealed approximately 38,000 active TV boxes globally phoning home to the infrastructure. Based on this conservative sample, researchers estimate that the ad-fraud network alone generates close to $50,000 in daily revenue.

When factoring in the supplementary income generated by renting out residential IP addresses to proxy networks, the actual financial footprint of the enterprise is substantially larger. This revenue stream highlights the lucrative nature of hardware-level supply chain compromises.


Official Statements & Industry Warnings

The findings from Bitsight align with a mounting body of evidence published by cybersecurity agencies and intelligence organizations worldwide regarding the dangers of unverified consumer IoT hardware.

Government and Intelligence Alerts

In recent years, the Federal Bureau of Investigation (FBI) and international cybersecurity authorities have issued formal warnings regarding home internet-connected devices facilitating illicit criminal activity. Official advisories emphasize that unbranded streaming boxes, digital photo frames, and smart-home accessories frequently ship from overseas manufacturers with pre-installed malicious software, including residential proxy utilities and botnet backdoors.

The FBI’s cyber division has repeatedly urged consumers to audit their home networks, restrict unrecognized device communications, and purchase hardware strictly from trusted, verified manufacturers that provide regular, automated security patches.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The Broader E-Commerce Dilemma

Despite persistent warnings from the cybersecurity community, major global e-commerce platforms—including Amazon, Best Buy, Newegg, and numerous international online marketplaces—continue to list and fulfill orders for hundreds of unbranded streaming boxes. Frequently promoted by online influencers as cost-free alternatives to legitimate cable and streaming subscriptions, these devices often run unverified, modified versions of the Android Open Source Project (AOSP) devoid of official Google Play Protect safety certifications.

Compounding the problem, proxy-tracking services like Synthient have documented extensive campaigns—such as the Kimwolf botnet—that actively exploit inherent vulnerabilities in cheap streaming hardware to rapidly enslave millions of devices into massive, multi-purpose botnets. These networks simultaneously engage in data scraping, credential stuffing, DDoS attacks, and programmatic ad fraud.


Future Outlook & Recommendations

The exposure of the Fengwo Group’s AI-powered ad fraud empire marks a critical turning point in the ongoing battle against software supply chain manipulation and IoT botnets. As threat actors increasingly leverage generative artificial intelligence, computer vision, and low-code automation to scale their operations, traditional perimeter defenses struggle to keep pace.

The Path Forward for Consumers

Security experts emphasize that mitigating the risks posed by compromised IoT hardware requires proactive vigilance from end-users:

  1. Stick to Name Brands: Consumers should exclusively purchase streaming media players from established, reputable manufacturers (such as Google, Roku, Apple, and Amazon Fire TV) that adhere to stringent security standards and provide ongoing firmware updates.
  2. Verify OS Integrity: Google provides clear documentation enabling consumers to verify whether a device runs the official Android TV OS and possesses valid Play Protect certification.
  3. Audit Network Traffic: Advanced users should implement network-level monitoring (such as Pi-hole or enterprise-grade firewalls) to detect unauthorized outbound telemetry or suspicious connections to known proxy and C2 domains.
  4. App Minimalism: Even on legitimate smart TVs and streaming sticks, users should exercise extreme caution when installing third-party applications, as many have been found to bundle residential proxy SDKs. Leading manufacturers, such as LG, have begun implementing platform-level bans on proxy software to combat these exact vectors.

Industry and Retail Accountability

Beyond consumer responsibility, growing pressure is mounting on e-commerce platforms to vet third-party vendors and remove unverified streaming hardware from their digital shelves. Without strict platform-level compliance standards and rapid product recall mechanisms, the marketplace will remain fertile ground for threat actors seeking to weaponize household living rooms into unwitting nodes for global cybercrime.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *