For years, cybersecurity experts have issued dire warnings regarding the dangers of "bargain" TV streaming boxes—the nondescript, low-cost devices that promise users unlimited, subscription-free access to premium streaming content. While consumers often focus on the legal grey areas of such content, the real danger lies hidden in the hardware itself. A groundbreaking new investigation has revealed that these devices are not merely passive streamers; they are active, weaponized nodes in a sprawling, multi-million-dollar global ad fraud empire.
Recent analysis by security firm Bitsight has uncovered that these devices routinely spoof themselves as mobile phones to generate fraudulent clicks on AI-generated websites. By masquerading as common handsets from manufacturers like Samsung, Huawei, and Xiaomi, these TV boxes act as a massive, automated botnet, defrauding merchants and advertising networks on a scale previously underestimated.
The Anatomy of the Fraud: A Researcher’s Discovery
The investigation, led by Bitsight threat researcher Pedro Falé, began in an unconventional way: the acquisition of an expired domain name. This domain had previously served as a telemetry hub for the "H96" brand of streaming sticks—a popular, albeit notorious, line of budget TV boxes.
Upon securing the domain, Falé gained an unprecedented window into the inner workings of the device’s "factory-installed" backdoor. He discovered that the domain was not merely collecting basic hardware diagnostics; it was coordinating a sophisticated operation. Tens of thousands of these devices, scattered across living rooms worldwide, were transmitting data claiming they were mobile devices.

"We noticed something was wildly wrong," Falé told KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones."
Further forensic inspection revealed that all the compromised H96 units shared two specific applications. These apps were traced back to a mainland China-based entity known as Zhejiang Fengwo IoT Technology Ltd, operating under the "Fengwo Group."
Chronology: From Factory Floor to Ad Fraud Machine
The lifecycle of this fraud begins at the point of manufacture. These devices are designed to be "pre-infected," arriving at the consumer’s doorstep with malicious software embedded deep within the operating system.
1. The Deployment Phase
When a user plugs an H96 device into their television, the pre-installed Fengwo apps immediately begin to beacon out to command-and-control (C2) servers. These apps are designed to be persistent, surviving reboots and system updates.

2. The Spoofing Mechanism
The device utilizes a spoofing engine to alter its "User-Agent" strings and hardware fingerprints. By presenting itself as a high-end smartphone rather than a TV box, it gains access to mobile-specific advertising campaigns—which typically pay higher rates to advertisers than desktop or TV-based traffic.
3. The "AI Human" Ad Interaction
The Fengwo Group operates a network of thousands of AI-generated websites featuring machine-crafted news, finance, and lifestyle content. To the naked eye, these sites appear legitimate. However, they are designed to trigger ad delivery only when visited by a device matching the spoofed mobile profile. The bots then use automated vision systems to navigate the pages, scroll through content, and "click" on ads, mimicking the behavior of a real human user.
4. The Dual-Role Switching
Bitsight’s analysis uncovered a highly efficient operational strategy: the devices perform different functions based on the state of the television. When an HDMI signal is detected—meaning the user is actively watching content—the box acts as a residential proxy, renting out the user’s home IP address to third parties for data scraping or cybercriminal activities. When the TV is powered off, the device shifts its resources entirely toward ad fraud, running the automated botnet routines in the background.
The Role of "No-Code" Malice: The Blockly Connection
One of the most concerning findings in the Bitsight report is the Fengwo Group’s use of Google’s "Blockly" visual programming language. Originally developed as an educational tool to teach children how to code, the Fengwo Group has weaponized it to lower the barrier to entry for ad fraud.

By dragging and dropping code blocks, even low-skilled operators within the organization can define new fraud routines. These routines are exported as JavaScript and deployed via S3 buckets to the global network of TV boxes. According to the Bitsight report, this "low-code" approach drastically reduces operating costs, allowing a small team of developers to manage a massive fleet of bots. The developers themselves have boasted in internal communications that the system allows for the creation of execution units without requiring significant technical expertise, effectively democratizing cybercrime.
Supporting Data: The Scale of the Empire
The financial implications of this operation are staggering. Bitsight identified approximately 38,000 devices actively phoning home to just one of the Fengwo Group’s legacy domains. Based on this subset, researchers estimate the network generates at least $50,000 in illicit daily revenue from ad fraud alone.
This figure does not account for the additional income generated by the residential proxy side of the business. Residential proxy services are highly valued by cybercriminals because they provide traffic that appears to originate from legitimate, residential households, making it extremely difficult for security filters to block.
Furthermore, the Fengwo Group claims to have "120,000 AI digital humans" at their disposal. While this may be a marketing facade designed to attract clients or intimidate competitors, researchers suggest it could also be a legitimate reflection of the scale of their botnet’s "workforce."

Official Responses and Industry Implications
The prevalence of these devices has not gone unnoticed by law enforcement. The FBI has issued multiple warnings concerning home internet-connected devices, noting that they are frequently leveraged to facilitate criminal activity. Despite these warnings, major e-commerce platforms—including Amazon, Best Buy, and Newegg—continue to host listings for hundreds of off-brand, insecure streaming boxes.
These platforms often rely on automated vetting processes that fail to catch the sophisticated, deep-rooted backdoors present in these units. When KrebsOnSecurity attempted to reach the Fengwo Group for comment, the inquiry was met with an automated bounce-back message indicating that their email server was either overwhelmed or intentionally inaccessible.
The Consumer Impact: How to Protect Yourself
The implications for the average consumer are twofold: privacy loss and network insecurity. By using these devices, consumers are essentially allowing a third-party, potentially criminal organization to use their home internet connection as a launchpad for attacks against others.
Security Best Practices:
- Stick to Name Brands: Avoid "generic" or "off-brand" TV boxes. Manufacturers like Google, Apple, Amazon (Fire TV), and Roku are subject to greater scrutiny and have established security update pipelines.
- Verify Android Certification: Consumers can verify if a device is running an official, Google-certified version of the Android TV OS by checking the Google Play Protect certification status in the device settings.
- Consult Security Lists: Organizations like Synthient maintain updated lists of IoT devices known to ship with pre-installed proxy software. These lists often include not just TV boxes, but also digital photo frames and other "smart" home appliances.
- Network Segmentation: For those who insist on using experimental hardware, it is highly recommended to place these devices on a separate, "guest" VLAN (Virtual Local Area Network) to prevent them from accessing personal devices, such as laptops, smartphones, or NAS drives, on the primary home network.
The case of the Fengwo Group and the H96 streaming sticks serves as a stark reminder of the "Internet of Things" paradox: the more connected our homes become, the more vulnerable we are to unseen, automated threats. As cybercriminals continue to leverage AI and low-code tools to scale their operations, the responsibility ultimately falls on the consumer to exercise extreme caution when purchasing "too good to be true" technology.
