For years, cybersecurity analysts and law enforcement agencies have warned consumers against the purchase of off-brand, generic streaming set-top boxes promising "unlimited content" for a one-time fee. Historically, these cheap devices were known to quietly monetize their users’ internet connections by turning home networks into residential proxy nodes for third parties. However, a groundbreaking investigation by threat research firm Bitsight reveals that the true scope of this ecosystem is far more sophisticated and predatory than previously understood.
According to research led by Bitsight threat researcher Pedro Falé, popular budget streaming sticks—most notably sold under the brand name H96—are delivered from manufacturers with deep-seated backdoor malware already installed. Beyond operating as silent residential proxies, these devices actively spoof their identities as high-end mobile smartphones, navigating to networks of AI-generated content farm websites to commit automated ad fraud on a massive scale.
+-----------------------------------------------------------------------------------+
| H96 Android TV Box Supply Chain |
+-----------------------------------------------------------------------------------+
|
v
+---------------------------------+
| Pre-Installed Backdoor Telemetry|
+---------------------------------+
|
+-----------------+-----------------+
| |
v v
[HDMI Signal Active] [HDMI Signal Inactive]
(TV Turned ON) (TV Turned OFF)
| |
v v
+---------------------------+ +---------------------------+
| Residential Proxy Mode | | Mobile-Spoofing Ad Fraud |
| Relays third-party web | | Pushes Blockly JS routines|
| traffic to evade bans | | Clicks ads on AI websites |
+---------------------------+ +---------------------------+
The enterprise behind this operation has been traced to Zhejiang Fengwo IoT Technology Co., Ltd. (operating commercially as the Fengwo Group), a mainland Chinese firm established in 2019. By combining off-the-shelf low-code development tools, advanced AI vision models, and hardware-level supply chain manipulation, the group has constructed a silent ad-fraud ecosystem generating tens of thousands of dollars per day in fraudulent advertising revenue.
Detailed Chronology of the Investigation
1. The Sinkhole Discovery
The investigation began when Pedro Falé registered an expired domain name that had previously been hardcoded into the firmware of tens of thousands of H96 TV streaming devices. Originally deployed by the hardware manufacturers to collect device telemetry, system specifications, and app inventory logs, the domain fell out of registration, allowing Bitsight to set up a sinkhole to observe incoming traffic.
Upon analyzing the incoming telemetry payloads from tens of thousands of active streaming sticks plugged into living room televisions globally, Falé identified a striking anomaly: nearly all incoming data packets reported that the connected hardware consisted of mobile phones manufactured by major brands such as Samsung, Vivo, Huawei, and Xiaomi.
"We noticed something was wildly wrong," Falé explained during an interview with KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"
Incoming Telemetry ---> [ Bitsight Sinkhole ]
|
+---> Reported Hardware: Samsung, Vivo, Xiaomi, Huawei
+---> Actual Hardware: H96 Generic Android Set-Top Boxes
+---> Core System Apps: Developed by Zhejiang Fengwo IoT
2. Tracing the Corporate Footprint
A closer inspection of the app manifests transmitted across the sinkholed infrastructure revealed that every reporting device shared two specific background applications developed by Zhejiang Fengwo IoT Technology Ltd. Further cross-referencing of patent filings, domain registration data, and SSL certificates revealed a complex web of corporate structures.
Bitsight’s TRACE unit linked the operation to shell identities registered across Hong Kong and Singapore, designed to absorb and launder advertising revenue before funneling profits back to Zhejiang Fengwo’s primary corporate entity in mainland China.
An analysis of the applications uncovered an ingenious operational strategy: the utilization of Blockly, an open-source visual programming language originally developed by Google to teach children basic software engineering concepts.
The Fengwo Group modified Blockly into an internal development workflow. Low-skilled operators within the organization drag and drop code blocks inside a customized interface to configure tasks such as opening background browsers, loading pages, simulating touch events, and navigating tabs. Once constructed, the graphical workflow is automatically exported as JavaScript and pushed directly to Amazon Web Services (AWS) S3 storage buckets.
From there, infected H96 streaming devices fetch the updated JavaScript routines and execute them locally. Internal developer notes uncovered by Bitsight revealed that this workflow allowed the corporate leadership to employ non-technical staff to churn out ad-fraud campaigns, dramatically lowering operational overhead.
4. Hardware-Aware Task Scheduling: The HDMI Toggle
One of the most remarkable technical aspects of the campaign is its awareness of hardware state. Bitsight discovered that the malware actively monitors whether the television attached to the H96 set-top box is currently powered on by checking the state of the High-Definition Multimedia Interface (HDMI) output.
Television Powered ON (HDMI Active): The malware minimizes CPU usage and acts strictly as a residential proxy, routing third-party traffic across the home network. This prevents video buffering or UI lag that might alert the consumer to suspicious behavior.
Television Powered OFF (HDMI Inactive): The device shifts into high-compute ad-fraud mode. It downloads Blockly scripts, launches headless browser instances, spoofs mobile device signatures, and interacts with advertising networks.
+--------------------------------------------------------------------+
| HDMI Output Status Monitoring |
+--------------------------------------------------------------------+
|
+------------------------+------------------------+
| |
v v
[ HDMI Active ] [ HDMI Inactive ]
(User Watching TV) (TV Display Off)
| |
v v
+-------------------------------+ +-------------------------------+
| Residential Proxy State | | AI Ad Fraud Engine State |
| Low CPU usage, background | | High CPU/RAM utilization, |
| network traffic relaying. | | web browser, screen clicks. |
+-------------------------------+ +-------------------------------+
Supporting Context & Technical Metrics
AI-Generated Content Farms and Vision Engines
To complete the fraud loop, the Fengwo Group operates a vast network of AI-generated content websites spanning diverse niches, including personal finance, healthcare, online gaming, culinary blogs, and lifestyle advice. These websites are populated entirely by machine-generated text and auto-rendered graphics.
Crucially, Bitsight observed that these websites were hardcoded to suppress all advertising displays unless visited by an H96 device exhibiting the specific mobile device spoofing profile. This mechanism prevents security auditing tools and ad-verification crawlers from detecting the fraud.
[ H96 Device (Spoofed Mobile Headers) ] [ Standard Web Crawler / User ]
| |
v v
+------------------------------------+ +------------------------------------+
| Fengwo AI Content Farm Website | | Fengwo AI Content Farm Website |
+------------------------------------+ +------------------------------------+
| |
v v
[ Render Ads & Scripts ] [ Hide All Ads ]
| |
v v
[ Execute Fraudulent Clicks ] [ Clean Static Page ]
To make fake ad interactions appear authentic, the Fengwo Group integrated three distinct computer vision and reasoning models into a unified interface inside the TV box software. This system analyzes the visual layout of rendered web pages in real time, locates ad frames, and generates natural mouse movement and click vectors that mirror human behavior, effectively bypassing traditional fraud-detection algorithms.
Fraud Monetization and Financial Scale
Telemetry captured from just one expired domain registered by Bitsight logged approximately 38,000 distinct H96 devices phoning home over a limited observation window.
Metric
Estimated Value
Observed Active Fleet Size (Single C2 Domain)
~38,000 active devices
Estimated Daily Ad Fraud Revenue
~$50,000 USD (conservative)
Annualized Ad Fraud Revenue (Extrapolated)
~$18.2 Million USD
Secondary Revenue Streams
Residential proxy bandwidth monetization
Note: Bitsight stresses that these figures reflect data from a single legacy domain and represent only a fraction of the total infrastructure operated by the Fengwo Group.
+-------------------------------+
| 38,000 Active Devices |
| (Single Telemetry Sinkhole) |
+-------------------------------+
|
v
+-------------------------------+
| ~$50,000 Daily Revenue |
| (Ad Fraud Operations Only) |
+-------------------------------+
|
v
+-------------------------------+
| ~$18.2 Million Annual Income |
| (Excludes Proxy Bandwidth) |
+-------------------------------+
The "Digital Humans" Cover Story
The Fengwo Group maintains a public-facing corporate website (fwgcloud[.]com) marketing its services as an advanced artificial intelligence development firm. The company claims to have created over 120,000 "AI Digital Humans" available for hire across customer service, creative design, and digital companionship roles.
Bitsight’s report suggests this operational front serves a dual purpose: legitimizing large-scale cloud infrastructure expenditures and masking the company’s true nature as an ad-fraud syndicate and botnet operator.
"Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their botnet size," noted Falé in his report.
Official Statements & Industry Responses
Law Enforcement & Security Warnings
The findings highlight ongoing risks surrounding uncertified, white-label Internet of Things (IoT) hardware distributed globally. Federal authorities have repeatedly warned that low-cost smart devices often serve as entry points for cybercriminals.
+------------------------------------------------------------------------+
| FBI Cyber Division Public Warning |
+------------------------------------------------------------------------+
| "Uncertified internet-connected devices—including TV boxes, digital |
| photo frames, and smart home appliances—frequently feature compromised |
| default firmware designed to turn home networks into illicit proxies |
| and botnet nodes." |
+------------------------------------------------------------------------+
Marketplace & Platform Realities
Despite warnings from security analysts and government agencies, generic Android TV boxes remain widely accessible on major e-commerce platforms, including Amazon, Newegg, and eBay. Many of these devices are promoted on social media and video platforms by tech influencers who advertise them as budget-friendly alternatives for accessing premium streaming services without a subscription.
In parallel research, proxy tracking platform Synthient documented that millions of budget Android TV boxes had been enrolled in global bot networks like Kimwolf. These networks exploit unauthenticated local network services and pre-installed proxy modules to compromise local router infrastructure.
Regulatory and Partner Status
When KrebsOnSecurity reached out to the contact email address listed on the Fengwo Group’s domain (postmaster@fwgcloud[.]com), the message bounced with an automated error indicating that the recipient inbox was full or over capacity.
Google maintains clear technical recommendations regarding Android TV devices, advising users to ensure that any purchased unit carries official Play Protect certification and runs an authentic distribution of the Android TV OS.
Future Outlook & Defense Strategies
The Evolution of IoT Supply Chain Risk
The Fengwo Group campaign illustrates a shift in the monetization strategies of threat actors. Historically, cybercriminals relied on malware installed post-purchase via phishing or malicious downloads. Today, direct partnerships with upstream hardware manufacturers allow threat actors to embed malware into consumer electronics at the factory level.
By combining pre-installed firmware access, low-code script generation (Blockly), adaptive HDMI hardware state monitoring, and AI-driven navigation engines, the operators have built a resilient, low-maintenance fraud architecture that runs largely undetected by consumers.
Protective Guidance for Consumers and Enterprises
+-------------------------------------------------------------------------+
| Recommended Defense Protocol |
+-------------------------------------------------------------------------+
| 1. Purchase Certified Hardware |
| - Stick to recognized brands certified via Google Play Protect. |
| |
| 2. Perform Network Segmentation |
| - Place all streaming hardware and IoT devices on an isolated VLAN |
| or Guest Network to protect local resources. |
| |
| 3. Consult Known Threat Repositories |
| - Cross-reference new IoT brands with public tracking registries |
| (e.g., Synthient's known compromised product database). |
| |
| 4. Monitor Network Telemetry |
| - Inspect outgoing traffic from streaming devices when the TV display|
| is turned off to spot unauthorized background activity. |
+-------------------------------------------------------------------------+
As online advertisers and network providers work to identify and block automated ad fraud, threat syndicates will likely continue integrating generative AI tools to make bot traffic harder to distinguish from human behavior. Curbing these operations will ultimately require stricter supply chain auditing, improved vendor verification on e-commerce platforms, and greater consumer awareness regarding the risks of off-brand IoT hardware.