The Silent Hijack: How Your Budget TV Box is Fueling a Global Ad-Fraud Empire

For years, cybersecurity researchers have issued urgent warnings regarding the proliferation of low-cost, "no-name" Android TV streaming boxes. Marketed on platforms like Amazon and Newegg as a gateway to "unlimited" free streaming content for a single, low-cost investment, these devices are rarely the bargain they appear to be. Beyond the questionable legality of the streaming services they offer, these boxes serve as Trojan horses, silently transforming home networks into nodes for residential proxy networks.

Now, a groundbreaking investigation by the security firm Bitsight has peeled back another, more sinister layer of this operation. The analysis reveals that these devices are not merely passive proxies; they are active participants in a sprawling, sophisticated ad-fraud network. By spoofing mobile devices and leveraging artificial intelligence, these TV boxes are quietly clicking on advertisements across a vast array of AI-generated websites, siphoning millions of dollars from the digital advertising ecosystem.

The Anatomy of the Fraud

The investigation, led by Bitsight threat researcher Pedro Falé, began when he successfully registered an expired domain previously used for telemetry by the "H96" brand of streaming sticks—a popular line of devices frequently sold on major e-commerce marketplaces.

By gaining control of this domain, Falé was able to peer into the "phone home" traffic of tens of thousands of H96 devices globally. What he discovered was a sophisticated deception. While these devices were physically plugged into televisions, they were reporting their identities to the command-and-control server as mobile handsets—specifically, models from major manufacturers such as Samsung, Vivo, Huawei, and Xiaomi.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

"We noticed something was wildly wrong," Falé explained. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones."

Upon further inspection, Falé identified two specific applications pre-installed on every device he monitored. These apps, developed by a mainland China-based entity known as Zhejiang Fengwo IoT Technology Ltd (operating under the "Fengwo Group"), acted as the orchestrators of the fraud.

Chronology of an Investigation

The timeline of this discovery highlights the persistence of cybercriminals and the difficulty of securing the sprawling Internet of Things (IoT) landscape.

  • 2019: Zhejiang Fengwo IoT Technology Ltd is founded in mainland China, establishing the foundation for its ad-publishing portfolio.
  • Early 2025: The FBI releases a formal warning regarding the risks of home internet-connected devices, noting that many budget IoT devices are pre-loaded with malicious software.
  • January 2026: The proxy tracking service Synthient reveals that massive botnets, such as the "Kimwolf" network, have enslaved millions of TV boxes to facilitate cybercriminal activity, utilizing vulnerabilities in pre-installed residential proxy software.
  • July 2026: Pedro Falé of Bitsight registers an expired H96 telemetry domain, uncovering the direct link between these streaming sticks and a coordinated ad-fraud operation.
  • Present Day: Bitsight publishes its full report, exposing the Fengwo Group’s use of "AI digital humans" and automated "Blockly" coding interfaces to scale their fraudulent operations.

The "Fengwo" Ecosystem: AI-Driven Deceit

The investigation into the Fengwo Group revealed a highly organized, industrialized approach to ad fraud. The company’s domain, fwgcloud[.]com, presents a public-facing image of a tech-forward organization claiming to "redefine the boundaries of human-AI interaction." They boast of creating over 120,000 "AI digital humans" for various tasks, including customer service and design.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

However, Bitsight’s findings suggest that this "digital human" narrative may be a clever smoke screen. In reality, the Fengwo Group has been using these devices to visit thousands of machine-generated websites—news portals, health blogs, and gaming sites—filled with content designed specifically to trigger advertisements.

A critical component of this scheme is the use of Blockly, a visual programming language developed by Google to teach children how to code. The Fengwo Group adapted this tool to allow low-skilled operators to build and manage fraud routines. By dragging and dropping blocks of code, these operators can define complex tasks for the hijacked TV boxes: silently launching browsers, navigating to specific pages, managing tabs, and—most importantly—clicking on advertisements.

To evade detection by sophisticated advertising networks, the Fengwo Group implemented a "triple vision and reasoning" system. This allows the botnet to accurately identify ad placements on a webpage, mimicking human behavior so convincingly that the fraud remains undetected by standard security filters.

A Dual-Purpose Malicious Tool

Perhaps the most striking finding of the Bitsight report is the "scheduling" of these devices. Falé observed that the H96 boxes were programmed to switch roles based on user activity.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

When the device detects an HDMI signal—signaling that the owner is actively using the TV to stream video—the box prioritizes its function as a residential proxy. In this state, it rents out the user’s home IP address to third parties, who use it for everything from aggressive data scraping to large-scale ticket scalping.

When the TV is turned off, the box shifts its primary activity to ad fraud. This "load balancing" approach ensures that the resource-heavy fraud tasks do not interfere with the device’s primary performance, keeping the user oblivious to the fact that their hardware is acting as a dual-purpose botnet node.

Implications: The Cost of "Cheap" Tech

The financial scale of this operation is staggering. Based on telemetry from just one of the Fengwo Group’s core domains, Bitsight estimates that the ad-fraud portion of the business generates roughly $50,000 per day. When combined with the revenue generated from the residential proxy business, the total illicit haul is likely significantly higher.

For the consumer, the implications are severe. Beyond the violation of privacy and the degradation of network bandwidth, these devices pose a significant security risk to the entire home network. Because these budget boxes often run on unpatched, insecure versions of Android with zero authentication protocols, they act as an open door for hackers. Once a device is compromised, it can be used to scan other devices on the local network—smart thermostats, security cameras, and even personal computers—potentially leading to a complete breach of a user’s digital life.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Official Responses and Industry Outlook

Despite repeated warnings from the FBI and cybersecurity industry leaders, the retail availability of these devices remains high. Major e-commerce giants, including Amazon, Newegg, and Best Buy, continue to list these products, often supported by influencer-led marketing campaigns that promise "free access to premium content."

Attempts to reach the Fengwo Group for comment were unsuccessful. An email sent to the contact address on their homepage bounced, with a delivery failure notification stating that the inbox was either full or receiving too much traffic—a fittingly ironic end to an investigation into a company built on synthetic, fraudulent traffic.

How to Protect Yourself

Security experts emphasize that the best defense is to avoid "no-name" streaming devices entirely. Consumers should stick to name-brand hardware from reputable manufacturers, such as Google (Chromecast), Roku, or Apple.

Google provides specific guidelines for confirming that a device is running a certified, secure version of the Android TV OS. Furthermore, organizations like Synthient have begun publishing lists of known compromised hardware. If you suspect your streaming device is part of a botnet, the recommended course of action is simple: disconnect it from your network, perform a factory reset if possible, and replace it with a verified, secure alternative.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

As the lines between AI, botnets, and consumer electronics continue to blur, the "Fengwo" case serves as a stark reminder: when a piece of hardware promises the world for a fraction of the cost, the user—and their internet connection—is almost certainly the product.

Leave a Reply

Your email address will not be published. Required fields are marked *