For years, cybersecurity analysts and law enforcement agencies have warned consumers about the hidden dangers of unbranded Android TV streaming devices. Frequently advertised on major e-commerce platforms with promises of "unlimited free content" for a low, one-time fee, these budget electronics have long been suspected of secretly harvesting bandwidth and operating as nodes in residential proxy networks. However, a landmark investigation by threat intelligence firm Bitsight TRACE reveals a far more complex and lucrative criminal enterprise operating beneath the surface.
Research conducted by Bitsight threat researcher Pedro Falé demonstrates that hundreds of thousands of popular generic streaming devices—most notably those sold under the H96 brand—are equipped with factory-installed backdoors. Beyond selling users’ home internet connections to third parties, these devices are actively weaponized in an automated ad fraud operation. By spoofing mobile device signatures, running low-overhead drag-and-drop code scripts, and utilizing advanced artificial intelligence vision engines, these streaming sticks generate millions of fraudulent ad clicks on machine-generated websites.
The operation has been conclusively linked to Zhejiang Fengwo IoT Technology Co., Ltd. (operating commercially as the Fengwo Group), a mainland Chinese entity that orchestrates the infrastructure through a network of shell companies in Hong Kong and Singapore. Conservative estimates indicate that a single expired command-and-control (C2) domain linked to this ecosystem was generating nearly $50,000 per day in fraudulent advertising revenue, illustrating how cheap consumer IoT hardware is being systematically transformed into an engine for global digital fraud.
Detailed Chronology & Core Technical Analysis
+-----------------------------------------------------------------------------------+
| GENERIC ANDROID TV BOX OPERATIONAL CYCLE |
+-----------------------------------------------------------------------------------+
| |
| [ TV Turned ON / HDMI Active ] [ TV Turned OFF / HDMI Standby ] |
| | | |
| v v |
| Residential Proxy Mode Ad Fraud Bot Mode |
| - Minimal CPU/GPU overhead - High CPU/GPU processing |
| - Routes external user traffic - Launches headless browser |
| - Hides behind user's residential IP - Spoofs mobile hardware IDs |
| - Renders AI-generated websites |
| - AI Vision engine locates ads |
| - Executes automated clicks |
| |
+-----------------------------------------------------------------------------------+
The Telemetry Domain Hijack
The investigation began when Pedro Falé identified and registered an expired internet domain previously embedded as a telemetry and control endpoint within pre-infected H96 TV streaming sticks. Upon taking ownership of the domain, Bitsight TRACE began receiving incoming traffic from approximately 38,000 distinct H96 devices scattered across the globe.
The domain was designed to perform routine hardware checks, uploading complete system telemetry, hardware characteristics, and lists of installed applications from each active streaming unit. However, as Falé analyzed the incoming telemetry payloads, an immediate anomaly surfaced:
"We noticed something was wildly wrong. Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"
— Pedro Falé, Threat Researcher, Bitsight
While the physical devices communicating with the domain were undeniably Android-based television set-top boxes, the software layers running on them deliberately altered their system profile properties. The boxes reported themselves to C2 servers as flagship smartphone models manufactured by major telecommunications brands, including Samsung, Vivo, Huawei, and Xiaomi.
The Mobile Identity Illusion
In the digital advertising ecosystem, mobile ad impressions command significantly higher Cost-Per-Mille (CPM) rates and click-through values than desktop or smart TV impressions. E-commerce networks and advertising exchanges pay premium rates for mobile clicks under the assumption that mobile users exhibit higher engagement.
By faking hardware signatures at the operating system level, the H96 streaming devices transformed cheap, stationary TV hardware into fake high-value mobile inventory. The infected streaming sticks routinely pulled advertisement units and clicked on them, deceiving ad networks into paying premium mobile rates for non-human traffic generated by a stationary television box plugged into a wall outlet.
A central challenge for botnet operators who monetize consumer devices is avoiding detection by the owner. Heavy background processing—such as launching headless browsers, running JavaScript execution suites, and processing visual elements—causes video streams to buffer, frame rates to drop, and devices to overheat.
To circumvent this, the malware on the H96 devices monitors the status of the television’s HDMI connection:
TV Turned ON (HDMI Active): When an active HDMI signal is detected—indicating that the owner is actively watching video or navigating menus—the device suspends resource-intensive processes. During these windows, the streaming box operates primarily as a residential proxy node. It routes lower-overhead internet traffic for remote third parties, keeping local resource usage low enough to avoid lag.
TV Turned OFF (HDMI Inactive): When the user turns off the television set, placing the display in standby while leaving the TV box powered on and connected to Wi-Fi, the malware shifts modes. The device initiates full-scale ad fraud operations, using its available CPU and GPU capacity to run background browsers, visit targeted websites, and execute simulated ad clicks.
Blockly Scripting and AI Vision Integration
The operational infrastructure created by the Fengwo Group relies on custom modular software design that minimizes labor costs while maximizing fraud capability.
Analysis of the infected devices revealed two primary applications installed at the system level, both originating from Zhejiang Fengwo IoT Technology Ltd. Internal software documentation and SSL certificate linkages tied these applications to a customized implementation of Blockly—an open-source visual programming language originally developed by Google to teach children basic coding principles.
Using custom Blockly interfaces, Fengwo operators can create visual blocks representing complex web browsing behaviors—such as opening a browser tab, scrolling down a page, waiting a specified number of seconds, and clicking a hyperlink. The visual blocks are then converted into JavaScript files and distributed via Amazon Web Services (AWS) S3 buckets directly to infected TV boxes.
A software developer working for Fengwo noted in technical forums that this architecture allows "only a small number of highly-skilled developers" to build core execution templates, enabling low-skilled staff to construct thousands of unique fraud routines at minimal cost.
To ensure that these automated scripts interact effectively with digital advertisements, Fengwo built an ad-detection pipeline. The system combines three vision and reasoning models into a unified control interface. When an infected TV box navigates to a website, this vision system processes the page layout, identifies ad units, calculates their spatial coordinates, and generates natural mouse movement vectors to execute the click. This reduces pattern detection by anti-fraud algorithms that look for instantaneous, non-human click behavior.
The monetization pipeline behind the H96 ad fraud ring relies on a network of corporate entities designed to obscure the ultimate beneficiary while facilitating payments from global ad networks.
+---------------------------------------+
| Zhejiang Fengwo IoT Technology Co. Ltd|
| (Hangzhou, Mainland China) |
+---------------------------------------+
|
v
+---------------------------------------+
| Fengwo Group |
| (Ad Publishing Portfolio) |
+---------------------------------------+
|
+----------------------------------+----------------------------------+
| |
v v
+------------------------------------+ +------------------------------------+
| Hong Kong & Singapore Shell Cos. | | Single-Person Shell Identities |
| (Ad Network Payout Collection) | | (Monetization Account Registration) |
+------------------------------------+ +------------------------------------+
| |
+----------------------------------+----------------------------------+
|
v
+---------------------------------------+
| AI Content Sites & Ad Networks |
+---------------------------------------+
Bitsight TRACE traced payout rails through multiple corporate layers:
Commercial Brand: Fengwo Group (manages digital publishing portfolios and ad display accounts).
Shell Identities: Multiple corporate shells across Hong Kong and Singapore, alongside single-person legal registrations, used to open publisher accounts with advertising brokerages and receive wire transfers.
Content Infrastructure: Thousands of auto-generated websites covering topics like finance, lifestyle, healthcare, gaming, and technology. These sites feature machine-generated text and AI-created graphics designed to host ad units.
Crucially, Bitsight discovered that these AI content sites contained dynamic rendering rules: the websites displayed advertisements exclusively when visited by a device matching the spoofed mobile device profiles generated by the H96 boxes. Standard web browsers visiting these sites saw clean pages devoid of advertisements, preventing external security researchers and ad verification crawlers from easily documenting the active ad units.
Financial Estimates
Based on telemetry collected from the single captured domain, Bitsight compiled conservative metrics detailing the scale of the operation:
Metric
Measured Value
Tracked Active TV Box Nodes
~38,000 distinct devices
Estimated Daily Fraud Revenue
~$50,000 USD / day
Estimated Annualized Revenue
~$18.2 Million USD / year
Primary Targeted Hardware
H96 Brand Generic Android Streaming Sticks/Boxes
Spoofed Profiles
Mobile OS signatures (Samsung, Vivo, Huawei, Xiaomi)
Researchers emphasize that these figures represent a baseline minimum. Because the analysis relies on telemetry from an older, expired control domain, the overall operation—which likely utilizes dozens of active domains across multiple device brands—is almost certainly generating significantly higher revenue.
The Broader Proxy Economy: The Kimwolf Botnet Context
The discovery of the Fengwo Group’s ad fraud ring builds upon prior research into the IoT proxy ecosystem. In January, proxy monitoring service Synthient released an analysis detailing the growth of the Kimwolf botnet, which infected millions of unbranded Android TV boxes worldwide.
Synthient’s research showed that generic streaming media players often arrive from factories pre-loaded with unauthenticated remote administration software and proxy clients. Once connected to a residential network, these devices:
Expose local area networks (LANs) to external lateral movement, allowing attackers to scan and target vulnerable smart home hardware, routers, and connected storage units.
Monetize residential IP addresses by selling proxy access to external clients, including scalpers, web scrapers, and cybercriminals seeking to hide their true location.
Official Statements & Industry Responses
The revelation of Fengwo’s dual ad-fraud and proxy enterprise has highlighted ongoing systemic vulnerabilities in consumer technology supply chains.
Federal Law Enforcement Guidelines
The FBI has issued multiple warnings regarding off-brand, internet-connected devices sold through popular online marketplaces. The Bureau noted:
"Inexpensive IoT hardware, particularly unbranded media streaming boxes and digital photo frames, frequently ship with factory-installed malware. These devices bypass standard supply-chain safety checks and compromise home networks, acting as encrypted bridges for illegal activities."
Google Security Assessment
In response to queries regarding uncertified Android devices, Google emphasized the distinction between official Android TV OS devices and open-source Android forks installed on generic hardware:
Consumers should verify whether a media device is built using certified Android TV software. Uncertified devices lack Google Play Protect validation, meaning they do not undergo rigorous security testing and may contain pre-installed malicious applications capable of undermining user privacy and network integrity.
Google maintains a public verification guide allowing consumers to confirm whether a device model is certified by accessing the Play Protect status within the settings menu of their device.
Vendor Response and Outreach
During the investigation, security researchers attempted to contact the Fengwo Group directly through the communication channels provided on its primary domain (fwgcloud[.]com). The domain claims to specialize in "human-AI interaction" and advertises more than 120,000 "AI digital humans" available for commercial lease.
When journalist Brian Krebs sent an inquiry to the listed administrative address (postmaster@fwgcloud[.]com), the delivery failed immediately with an automated bounce message:
Diagnostic Code: 554 5.2.2 Service unavailable;
Recipient inbox is full, or it's receiving too much mail right now.
Bitsight researchers noted that the high profile of "AI digital humans" advertised on Fengwo’s commercial landing page is likely a public facade designed to account for the massive volume of automated network traffic originating from their infrastructure, disguising botnet activity as legitimate AI service calls.
Future Outlook & Consumer Safeguards
The integration of artificial intelligence vision models with low-code automation tools like Blockly marks an evolution in ad fraud tactics. Historically, ad fraud operations relied on simplistic HTTP requests or basic headless browser scripts that were relatively easy for anti-fraud vendors to identify and block. By equipping botnets with visual reasoning models capable of navigating dynamic web layouts, fraudsters can closely mimic real user behavior on a massive scale.
At the same time, the persistence of pre-infected devices on major retail platforms demonstrates the ongoing difficulty of securing hardware supply chains. Despite repeated security warnings, uncertified streaming boxes remain widely available online, often promoted by affiliate marketers and social media influencers as cost-effective alternatives to legitimate media players.
Mitigation Recommendations for Consumers and Organizations
To protect personal and corporate networks from IoT-borne threats, cybersecurity experts advise the following measures:
Procure Certified Hardware: Limit streaming hardware purchases to established brands (e.g., Google TV, Apple TV, Roku, Amazon Fire TV) that undergo regular firmware signing, patch management, and Play Protect certification.
Audit Active Connected Devices: Consult public threat intelligence indexes—such as the open-source hardware tracking repositories maintained by Synthient—to check if generic media devices or digital photo frames contain known pre-installed proxy components.
Isolate Consumer IoT Hardware: If unbranded IoT devices must be used, isolate them on a dedicated Guest Wi-Fi network or a segregated Virtual Local Area Network (VLAN). This prevents compromised hardware from accessing primary computing assets, personal files, or local network management portals.
Monitor Outbound Telemetry: Network administrators should monitor outbound DNS requests and traffic volume from IoT subnets. High volumes of outbound web requests during off-peak hours—particularly to unfamiliar advertising domains or cloud storage endpoints—frequently indicate background proxy or ad-fraud activity.
As ad networks and security researchers refine their detection mechanisms to counter AI-driven ad fraud, the threat actors behind these botnets will likely continue updating their firmware and evasion techniques. Securing the streaming ecosystem will require tighter supply chain oversight by major e-commerce retailers, aggressive legal action against corporate proxy facilitators, and broader public awareness of the true costs associated with "free streaming" hardware.