For years, cybersecurity professionals have issued urgent warnings regarding the proliferation of “no-name” TV streaming boxes. These inexpensive devices, often marketed as gateways to “unlimited” streaming for a single, low price, have long been suspected of turning home networks into involuntary exit nodes for residential proxy services. However, a groundbreaking investigation by the security firm Bitsight has unveiled a far more insidious reality: these devices are not just sharing your bandwidth; they are actively engaging in a massive, AI-driven ad fraud campaign that is defrauding global advertisers out of millions of dollars.
The Discovery: Peering into the Machine
Pedro Falé, a lead threat researcher at Bitsight, stumbled upon the operation almost by accident. While monitoring telemetry data associated with a popular brand of generic streaming devices known as "H96," Falé noticed a domain name that had recently expired. Recognizing the potential for intelligence gathering, he registered the domain.
What he found within the traffic logs was a sophisticated command-and-control infrastructure. The devices, which were supposed to be simple media players, were routinely reporting hardware specifications that defied logic. While the devices were physically H96 TV boxes, their software was spoofing their identity to appear as high-end mobile phones from major manufacturers like Samsung, Huawei, Vivo, and Xiaomi.

“We noticed something was wildly wrong,” Falé told KrebsOnSecurity. “Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones.”
This wasn’t a glitch; it was a feature. By masquerading as mobile devices, the TV boxes could trick advertising networks into serving higher-value mobile-specific ads, which the devices would then "click" automatically, generating fraudulent revenue for a shadowy entity known as the Fengwo Group.
Chronology of an Ad Fraud Empire
The investigation into the Fengwo Group (Zhejiang Fengwo IoT Technology Ltd) reveals a calculated effort to build an automated, low-cost monetization engine.

- 2019: Zhejiang Fengwo IoT Technology Co., Ltd is founded in mainland China, establishing a portfolio of ad-publishing apps.
- The Development Phase: The company begins patenting software designed to automate ad interactions, leveraging Google’s Blockly—a visual programming tool originally intended for children—to allow low-skilled operators to drag-and-drop code blocks to create complex fraud routines.
- Deployment: Millions of H96 streaming devices are manufactured with pre-installed firmware that contains backdoors. These devices reach consumers globally through major e-commerce platforms like Amazon and Newegg.
- The Fraud Cycle: Once plugged into a home network, the devices begin phoning home. When the TV is off, the boxes transition into "ad fraud mode," using AI to navigate websites and click on advertisements.
- Current State: Bitsight estimates that at least 38,000 devices were actively reporting to the specific domain analyzed, generating roughly $50,000 in daily revenue—a figure the researchers believe is a conservative estimate.
The Architecture of Deception
The Fengwo Group’s operation is remarkably efficient, utilizing "AI digital humans" to bypass modern bot-detection systems. According to their website, fwgcloud[.]com, the company claims to have created over 120,000 "AI digital humans" for various tasks. While this may be a marketing facade to mask their botnet’s true scale, the underlying technology is real.
Bitsight discovered that the Fengwo Group employs a "fusion" of three distinct vision and reasoning systems. This allows the bot-infected TV boxes to "see" a webpage, identify an advertisement, and interact with it in a manner that mimics human behavior—scrolling, clicking, and navigating—thereby evading the fraud-detection algorithms used by major advertising networks.
The use of Blockly is particularly notable. By turning the construction of fraud routines into a "no-code" task, the Fengwo Group has minimized its reliance on high-level software engineers. As one developer noted in internal documentation found by Bitsight, this modular approach significantly reduces operating costs, allowing a small team to manage an expansive network of millions of compromised devices.

The Dual-Use Menace: Proxies and Fraud
One of the most alarming aspects of this investigation is the "dual-mode" nature of these devices. Bitsight found that the H96 boxes dynamically switch between roles depending on user activity.
When a user is actively watching television—detecting an HDMI signal—the device functions primarily as a residential proxy. In this state, it rents out the user’s home internet connection to third-party "customers," who use the IP address to scrape content, scalp tickets, or conduct cyberattacks.
When the user turns the television off, the device shifts into its second phase: the ad fraud engine. This intelligent switching ensures that the device’s performance as a media player is not compromised during use, effectively hiding the malicious activity from the owner. This dual-purpose design makes the device a persistent and highly profitable asset for the threat actors behind the Fengwo Group.

The Role of Global E-commerce
Despite consistent warnings from the FBI and independent security experts, major retailers continue to facilitate the distribution of these devices. Many of these streaming sticks are marketed as "subscription-free" alternatives to official platforms, using influencers and deceptive advertising to reach non-technical consumers.
These devices are inherently insecure. They run unofficial, "forked" versions of the Android operating system that lack Google’s Play Protect certification. They are frequently shipped with open ports and default credentials, making them vulnerable not only to the Fengwo Group but to other botnet operators, such as the infamous "Kimwolf" botnet, which has been documented enslaving millions of similar IoT devices.
Implications for the Consumer and Industry
The implications of this discovery are twofold:

- For the Consumer: Beyond the privacy violation of having one’s internet connection sold to criminals, there is the risk of network compromise. Because these devices lack authentication, they act as a "beachhead" into the user’s home network, potentially exposing laptops, smartphones, and sensitive data to attackers.
- For the Advertising Industry: The scale of this fraud is staggering. By spoofing mobile devices and utilizing AI to mimic human interactions, this network creates a "fake economy" that drains marketing budgets and undermines the trust in digital advertising.
Official Responses and Remediation
When KrebsOnSecurity reached out to the Fengwo Group for comment, the request was met with a bounced email notification, suggesting the company’s infrastructure is either overwhelmed or intentionally disconnected from external scrutiny.
Security experts, including the team at Bitsight, recommend a hard-line approach to these devices:
- Discard, Don’t Use: If you possess a non-branded, inexpensive streaming stick from an unknown manufacturer, the safest course of action is to stop using it immediately.
- Stick to Reputable Brands: Use only certified Android TV devices or mainstream alternatives like Apple TV, Roku, or Amazon Fire TV, which receive regular, vetted security updates.
- Network Segmentation: For those who must use generic IoT hardware, placing these devices on a separate "guest" Wi-Fi network can mitigate the risk of them accessing your primary computers and personal data.
As the digital landscape becomes increasingly saturated with low-cost, "smart" devices, the Bitsight report serves as a stark reminder: when a piece of technology is provided at a price that seems too good to be true, you—and your network bandwidth—are likely the product being sold. The era of the "smart" living room has inadvertently ushered in an era of persistent, automated, and invisible exploitation.
