Inside the AI-Driven Ad Fraud Empire Trojanizing Off-Brand Smart TV Devices

Executive Overview

For years, cybersecurity professionals and federal law enforcement agencies have issued stark warnings regarding generic, off-brand streaming devices. Frequently sold online under promises of unlocked, subscription-free entertainment, these dirt-cheap TV boxes have long been known to secretly monetize the user’s home network by converting it into a residential proxy node. However, groundbreaking technical research reveals that these devices are performing an even more insidious, highly engineered secondary operation: executing massive, automated ad fraud.

A comprehensive investigation led by cybersecurity firm Bitsight has uncovered a sophisticated digital ad fraud campaign that transforms pre-infected Android TV boxes into a captive army of botnet nodes. Manufactured predominantly in mainland China and distributed globally through major e-commerce platforms, these streaming devices spoof their hardware profiles to masquerade as high-end mobile smartphones. Once masked, they silently navigate to AI-generated "Made-for-Advertising" (MFA) websites, using advanced computer-vision tools to click on digital advertisements, defrauding global ad networks and online merchants of millions of dollars.

At the epicenter of this global infrastructure is Zhejiang Fengwo IoT Technology Co., Ltd. (operating under the corporate banner Fengwo Group), a Chinese entity that orchestrates the fraud through a web of international shell companies, patented ad-publishing software, and customized visual programming tools originally designed to teach children how to code. Based on sinkholed telemetry data from just a single, expired command-and-control (C2) domain, analysts estimate that this single branch of the botnet generates upwards of $50,000 daily in fraudulent advertising revenues, operating completely unbeknownst to the consumers who plugged these devices into their living room televisions.


Detailed Chronology & Technical Mechanics

Discovery via a Sinkholed C2 Domain

The investigation began when Pedro Falé, a threat researcher with Bitsight’s TRACE team, registered an expired domain name that had previously been hardcoded into the firmware of popular off-brand TV boxes—most notably devices sold under the H96 brand moniker. The domain was originally deployed by the threat actors to collect telemetry data, routinely polling infected devices for hardware configurations, system performance metrics, and complete lists of installed applications.

Upon taking control of the domain and analyzing the incoming telemetry traffic from tens of thousands of active streaming sticks, Falé identified an immediate, striking technical anomaly. Despite the incoming traffic originating from television streaming boxes connected to residential networks around the globe, nearly every reporting device claimed to be a mobile smartphone manufactured by leading brands such as Samsung, Vivo, Huawei, or Xiaomi.

+-------------------------------------------------------------------+
|                  INFECTED H96 STREAMING BOX                        |
|                                                                   |
|  [TV OFF] ---> Ad Fraud Mode                                      |
|                - Spoofs Smartphone ID (Samsung/Xiaomi/etc.)       |
|                - Fetches Blockly Scripts via AWS S3              |
|                - Executes AI Vision/Reasoning Navigation          |
|                - Generates Fake Clicks on Fengwo MFA Websites     |
|                                                                   |
|  [TV ON]  ---> Residential Proxy Mode                                 |
|                - Detects HDMI Signal                              |
|                - Suspends CPU-Intensive Ad Fraud                  |
|                - Relays External Proxy Traffic for Third Parties  |
+-------------------------------------------------------------------+

"We noticed something was wildly wrong," Falé explained. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"

Read This Before You Buy That TV Streaming Stick

Tracing App Provenance to the Fengwo Group

Further inspection revealed that every reporting H96 device carried two specific, persistent system applications installed directly at the factory level. Deep-code analysis tied these applications directly to Zhejiang Fengwo IoT Technology Co., Ltd., an organization founded in 2019 in mainland China.

Bitsight’s research established that Fengwo Group maintains an extensive ad-publishing network and holds several domestic patents in China whose technical specifications precisely mirror the operational mechanisms of the rogue applications pre-installed on the H96 hardware. To collect advertising payouts while obscuring its corporate footprint, the entity deployed a network of single-person legal entities and shell identities across Hong Kong and Singapore.

Assembly-Line Exploitation via Custom Blockly Modules

One of the most remarkable aspects of the Fengwo Group’s ad fraud framework is its operational efficiency. Analysis of the domain’s SSL certificates led researchers to an internal technical wiki operated by the company. The documentation detailed a proprietary implementation of Google Blockly—an open-source, block-based visual programming language originally developed to help children learn software development logic.

By leveraging a custom Blockly editor, Fengwo’s core engineering team created template "execution units." Low-skilled operators within the organization could then drag and drop modular code blocks to construct complex fraud routines without needing to write raw JavaScript or understand underlying web protocols.

  1. Task Assignment: A central server selects an infected H96 device and assigns it a task payload.
  2. Blockly Module Push: The server delivers a compiled JavaScript routine derived from a custom Blockly layout stored in Amazon Web Services (AWS) S3 buckets.
  3. Execution: The TV box silently launches a background browser instance, accesses a targeted web page, manages browser tabs, and executes user interaction scripts.

In internal documentation reviewed by Bitsight, a developer for the enterprise highlighted these operational cost savings, noting that "only a small number of highly-skilled developers are needed to build the template execution-unit images," allowing operators with minimal technical training to manage daily fraud operations.

AI-Driven Vision Systems and Machine-Generated Media

To convert fake traffic into legitimate advertising revenue, the Fengwo Group constructed a network of Made-for-Advertising (MFA) websites populated entirely with AI-generated text and graphics across diverse topics including personal finance, healthcare, lifestyle, gaming, and education.

Read This Before You Buy That TV Streaming Stick

Crucially, these MFA sites implement strict access controls: they will not display monetized ad banners unless the incoming visitor matches the specific spoofed mobile device fingerprints injected by the H96 malware.

To ensure high conversion rates and evade automated bot-detection filters deployed by major advertising networks, the malware integrates three distinct AI vision and reasoning systems. This triple-layered system analyzes the visual layout of the webpage in real time, identifies advertisement frames, calculates human-like mouse movement vectors, and executes clicks, mimicking genuine user interaction.

State-Dependent Operation: The HDMI Trigger

To maximize monetization without raising the end-user’s suspicion, the malware monitors the host device’s physical hardware state—specifically whether an active video signal is being output via the HDMI port:

  • TV Powered On (Streaming Active): When the H96 box detects an active HDMI link (indicating the user is actively watching content), the resource-heavy ad fraud engine suspends its visual browsing tasks. The device instead shifts exclusively to acting as a low-overhead residential proxy, quietly relaying third-party network traffic.
  • TV Powered Off (Idle Device): When the attached television is turned off, the box resumes full operational capacity for ad fraud, utilizing the device’s CPU and memory to spin up headless browser instances and execute automated ad-clicking operations.

This conditional switching mechanism prevents system lag, frame drops, or bandwidth degradation during active television viewing, allowing the underlying compromise to remain unnoticed by consumers for months or years.


Supporting Context & Metrics

Financial Breakdown and Botnet Scale

Telemetry retrieved by Bitsight during the capture of a single expired telemetry domain illuminated the vast financial scale of the operation.

Metric Recorded Value / Estimate
Active Devices on Single Sinkhole ~38,000 unique H96 TV boxes
Estimated Daily Ad Fraud Revenue ~$50,000 USD (conservative baseline)
Annualized Ad Fraud Projection ~$18.2 Million USD (single domain subset)
Primary Target Hardware Off-brand Android AOSP Streaming Sticks (H96 series)
Pre-Installed Malware Attribution Zhejiang Fengwo IoT Technology Co., Ltd.
Associated IP Renting Model Concurrent Residential Proxy Service

Threat analysts emphasize that these metrics represent a highly conservative baseline. Because the analyzed domain was an older, legacy endpoint, the overall global footprint of the Fengwo Group’s active ad fraud infrastructure—spanning newer domains, alternative hardware brands, and secondary app ecosystems—is likely significantly larger.

Read This Before You Buy That TV Streaming Stick
ESTIMATED DAILY FRAUD REVENUE (SINGLE DOMAIN)
==================================================
Ad Fraud Clicks:     [$$$$$$$$$$$$$$$$$$$$] $50,000/day
Residential Proxy:   [$$$$$$$$$$] (Unquantified Revenue)
Total Monetization:  $50,000+/day

The "AI Digital Humans" Front

The primary public-facing portal for the Fengwo Group (fwgcloud[.]com) presents the firm as a cutting-edge technological entity specializing in conversational artificial intelligence. The website explicitly claims that the company maintains a portfolio of over 120,000 "AI digital humans" available for commercial lease, serving roles in 24/7 customer service, virtual companionship, and automated content generation.

However, security researchers note that in the cybercrime landscape, infrastructure operators frequently adopt commercial fronts to obscure the underlying scale of botnets or stress-testing services. Bitsight’s findings suggest that the advertised "120,000 AI digital humans" may simply be a public narrative designed to account for and legitimize the massive, automated web interactions generated by its global network of trojanized IoT devices.

Supply Chain Vulnerabilities and Broader IoT Exploitation

The presence of pre-installed backdoors in low-cost consumer electronics represents an ongoing, pervasive supply-chain vulnerability. Generic Android streaming boxes typically run uncertified distributions of the Android Open Source Project (AOSP). Lacking Google Play Protect certification, these devices are manufactured in environments with limited oversight, allowing malicious actors to embed unauthorized applications directly into system-level ROM images before distribution.

       [Shenzhen OEM/ODM Manufacturer]
                      |
        (Bakes Firmware with Backdoors)
                      |
                      v
       [E-Commerce Platforms (Amazon, etc.)]
                      |
        (Purchased by Global Consumers)
                      |
                      v
      +---------------+---------------+
      |                               |
[Residential Proxy Node]     [Ad Fraud Botnet Node]
 (Rents Residential IP)       (Spoofs Smartphone Fingerprint)

This vulnerability extends beyond streaming boxes. Industry tracking services such as Synthient have documented extensive botnet ecosystems—including the widespread Kimwolf botnet—that exploit security vulnerabilities in residential proxy tools and unauthenticated consumer IoT hardware. Beyond streaming sticks, residential proxy software and ad fraud backdoors are regularly discovered in bargain-brand smart home appliances, network-attached storage (NAS) drives, and connected digital photo frames sold through mainstream online marketplaces.


Official Statements & Industry Responses

Law Enforcement and Regulatory Alerts

Federal law enforcement agencies have intensified public efforts to warn consumers about the systemic security risks associated with unbranded IoT devices. In an explicit public advisory, the Federal Bureau of Investigation (FBI) warned that low-cost, uncertified home internet devices frequently serve as key nodes for international cybercrime syndicates.

"Uncertified, low-cost home internet-connected devices are frequently pre-configured or easily exploited to facilitate large-scale criminal activity, including network proxying, unauthorized data scraping, and financial fraud schemes."
Federal Bureau of Investigation (FBI) Cyber Division Advisory

Read This Before You Buy That TV Streaming Stick

Platform and Vendor Certifications

In response to the proliferation of trojanized Android hardware, Google has updated consumer guidance regarding streaming media players, advising users to verify whether a device runs an authentic, licensed version of the Android TV operating system equipped with official Play Protect verification.

Google’s official stance outlines distinct criteria for device security:

  1. Play Protect Status: Consumers should verify device certification directly within the system settings under the Google Play Store menu.
  2. AOSP Risk: Generic devices running basic mobile Android (AOSP) rather than official Android TV OS lack native security checks, leaving them vulnerable to firmware-level tampering.

Concurrently, major display manufacturers are taking direct infrastructure measures to mitigate exposure. Television manufacturer LG recently initiated strict policy enforcement prohibiting known residential proxy libraries from operating within its smart TV app ecosystem, seeking to prevent third-party developers from stealthily embedding proxy routines into legitimized Smart TV applications.

Outreach to the Fengwo Group

During the publication of the research, efforts were made to contact Zhejiang Fengwo IoT Technology Co., Ltd. for comment regarding Bitsight’s findings. Written inquiries transmitted to the primary point of contact listed on the company’s corporate web domain (postmaster@fwgcloud[.]com) were immediately bounced by mail transfer agents.

The automated system delivery failure cited resource exhaustion:

Diagnostic-Code: smtp; 552 5.2.2 Header size exceeds maximum limit /
Your message couldn't be delivered to postmaster@fwgcloud[.]com.
Their inbox is full, or it's getting too much mail right now.

Future Outlook & Consumer Protection Strategies

Industrial Implications for Digital Advertising

The discovery of the Fengwo Group’s Blockly-driven ad fraud engine signals a shift in the sophistication of automated ad fraud operations. By fusing cheap IoT hardware, visual programming interfaces, and vision-based AI reasoning, threat actors can successfully bypass conventional anti-fraud controls at low cost.

Read This Before You Buy That TV Streaming Stick

Ad networks are increasingly forced to re-evaluate how they assess mobile ad impressions. Device fingerprinting metrics that previously relied on reported user-agent strings, canvas rendering signatures, or touch event coordinates must now account for stateful anomalies where residential broadband IPs present mobile hardware signatures while exhibiting rigid interaction patterns.

Mitigation Strategies for Consumers and Organizations

To defend against rogue IoT devices and corporate supply-chain compromises, cybersecurity experts recommend the following baseline mitigation protocols:

  • Purchase Certified Hardware: Restrict procurement of smart TV hardware and streaming sticks to reputable, name-brand manufacturers (e.g., Apple TV, Google TV, Roku, or certified Fire TV devices) that maintain official Play Protect or equivalent platform assurances.
  • Audit Network Devices: Consult publicly updated IoT tracking lists—such as repository databases maintained by security intelligence firms like Synthient—to check if deployed hardware models match known proxy-infected hardware identifiers.
  • Network Segmentation: Isolate all consumer-grade IoT devices, smart displays, and non-essential hardware on a dedicated Guest Wi-Fi network or segregated VLAN. This prevents infected hardware from executing local network discovery or conducting lateral movement attacks against personal computers and network storage devices.
  • Inspect Device Certification: Check the security settings of Android-based devices to confirm that Google Play Protect status reads as fully certified. Uncertified devices should be immediately disconnected from the local network and decommissioned.

Leave a Reply

Your email address will not be published. Required fields are marked *