Cheap H96 TV Streaming Sticks Caught Spoofing Phones in $50k-a-Day Ad Fraud Operation
- CVE ID
- N/A
- Affected Products / Orgs
- H96 Android TV streaming boxes, Digital Advertising Networks, E-commerce Merchants
Consumers purchasing unbranded streaming hardware are unwittingly hosting a sophisticated ad fraud operation inside their living rooms. A new investigation by Bitsight threat researcher Pedro Falé revealed that thousands of generic H96 Android TV streaming sticks come pre-loaded with factory backdoors operated by mainland China-based Zhejiang Fengwo IoT Technology Co., Ltd (Fengwo Group). These cheap streaming devices secretly spoof themselves as mobile phones from manufacturers like Samsung, Vivo, Huawei, and Xiaomi, silently visiting AI-generated websites to click on digital advertisements and siphon an estimated $50,000 per day from online merchants and advertising networks.
Inside the Fengwo Group Ad Fraud Engine
The operation relies on continuous telemetry and remote command execution built directly into the firmware of H96 Android TV box hardware. Bitsight uncovered the infrastructure after registering an expired domain name (fwgcloud[.]com ecosystem) previously used by the threat actors to coordinate telemetry and bot commands. Upon inspecting incoming connection data from approximately 38,000 compromised devices worldwide, researchers discovered that nearly every streaming device was actively reporting false device metadata—impersonating mobile phone models rather than streaming media players.
Analysis of the onboard malicious applications traced back to Zhejiang Fengwo IoT Technology Ltd, an entity established in mainland China in 2019 that operates an ad-publishing portfolio under the Fengwo Group name. The group utilizes a low-barrier development setup powered by a custom implementation of Google’s Blockly visual programming language. Non-technical operators drag and drop modular code blocks to define specific ad fraud routines, which are then compiled into JavaScript, stored in Amazon S3 buckets, and pushed down to the captive H96 streaming sticks.
To maximize pay-per-click revenues and bypass traditional anti-fraud mechanisms, the Fengwo Group constructed thousands of sham websites spanning finance, health, gaming, and lifestyle topics using machine-generated text and images. These websites only render advertisements when accessed by requests matching the spoofed mobile signatures of the infected H96 devices. The client application fuses three distinct vision and reasoning AI systems into a unified interface, allowing the streaming stick to parse web pages, locate ad banners, manage browser tabs, and simulate human interaction patterns with high fidelity.
Dual-State Operations: Proxies when Live, Fraud when Dark
The malware running on the H96 Android TV box features dynamic workload switching based on physical hardware states. The devices actively monitor the HDMI output signal to determine whether a user is actively watching television:
- TV Powered On (HDMI Active): When an active HDMI connection is detected, the device suspends resource-intensive ad fraud scripts to avoid causing stream buffering or UI degradation that might alert the user. Instead, the box functions strictly as an IP-renting residential proxy node.
- TV Powered Off (HDMI Inactive): When the television is turned off, the malware switches back to heavy ad fraud tasks, launching silent background browser instances, executing Blockly JavaScript modules, and churning through automated click campaigns.
This dual-mode operational model highlights how low-cost Android TV devices routinely monetize consumer internet connections. Pre-installed residential proxy software rents the victim’s residential IP address out to anonymous paying customers, enabling web scrapers, ticket scalpers, and cybercriminals to route traffic while hiding behind clean residential IP addresses.
Operational Blast Radius and Ecosystem Impact
The blast radius of this campaign spans both enterprise advertising networks and home network environments. For digital advertisers and ad exchanges, the operation represents direct financial theft; fake traffic from tens of thousands of captive bots drains marketing budgets while delivering zero legitimate user engagement.
For end users and network administrators, these generic streaming sticks represent unauthenticated, persistent backdoors on internal subnets. Cheap Android TV devices typically run outdated, non-certified, and heavily modified Android builds devoid of basic security controls or vendor patching mechanisms. Once attached to a home or enterprise Wi-Fi network, an infected device provides malicious entities with a local foothold capable of scanning internal subnets, relaying malicious cybercrime traffic, or participating in broader botnets—such as those documented by proxy research firms like Synthient.
Defensive Actions and Remediation
Because generic Android streaming boxes like the H96 are compromised at the supply chain or firmware level, host-based remediation or antivirus cleanup is ineffective.
- Device Decommissioning: Disconnect and decommission generic or unbranded Android TV sticks (including H96 models) from residential and corporate networks. Replace them with hardware running officially certified operating systems from reputable vendors with documented patch management practices.
- Network Segmentation: If unverified smart home or streaming devices must remain connected, isolate them on a strictly segregated IoT VLAN with blocked inter-VLAN routing to prevent lateral movement to internal workstations, NAS units, or management interfaces.
- Ad Network Fraud Monitoring: Advertising platforms and online merchants should implement strict verification checks for traffic originating from suspicious IP clusters, auditing user-agent consistency against underlying web browser behavior and network-layer device fingerprints.
Related content
Anatomy of a Modern Supply Chain Attack — And Where Defenses Actually Break
Security NewsAdform Supply-Chain Attack Poisons Script to Swap Crypto Wallet Addresses
Security NewsAdform Adtech Script Compromised in Supply-Chain Crypto-Stealing Attack
Security NewsAI Harness Security: Trust Boundaries Create New Attack Vectors
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call