Executive Overview
For years, cybersecurity analysts and federal law enforcement agencies have warned consumers against the purchase of off-brand, uncertified Android TV streaming boxes. Marketed on major e-commerce platforms with promises of unlimited premium content for a low, one-time fee, these budget devices have long been recognized as double-edged swords that secretly monetize the owner’s home internet connection by turning it into a proxy node.
However, a groundbreaking investigation by cybersecurity firm Bitsight reveals that the malicious footprint of these generic streaming devices extends far beyond simple bandwidth theft. Threat researchers have uncovered a sprawling, highly automated ad fraud scheme embedded within popular streaming brands like H96.
According to the investigation led by Bitsight threat researcher Pedro Falé, thousands of factory-preinfected streaming boxes around the globe are actively masquerading as mobile smartphones. Operating covertly in the background, these devices automatically navigate to AI-generated "ghost" websites, executing fake ad clicks and defrauding online merchants, advertising networks, and programmatic media platforms.
The operation has been traced back to a mainland China entity known as Zhejiang Fengwo IoT Technology Co., Ltd. (operating under the banner of the Fengwo Group). By leveraging low-code visual programming languages, multimodal artificial intelligence, and sophisticated device spoofing, the enterprise has constructed an ad-fraud pipeline capable of generating tens of thousands of dollars in illicit daily revenue while leaving legitimate online advertisers paying for ghost impressions.
Detailed Chronology and Technical Mechanics
1. The Telemetry Trap: Uncovering the Backdoor
The breakthrough in understanding this covert infrastructure occurred when Bitsight threat researcher Pedro Falé registered an expired domain name previously utilized by pre-installed malware on H96 Android TV devices. The domain had originally served as a telemetry endpoint, systematically harvesting hardware specs, installed application manifests, and network metrics from thousands of streaming sticks plugged into home televisions worldwide.

Upon analyzing the inbound traffic directed at this newly acquired sinkhole domain, Falé observed a striking technical anomaly: despite the incoming traffic originating exclusively from TV streaming hardware, nearly all of the reporting payloads claimed the underlying devices were high-end mobile phone models manufactured by brands such as Samsung, Vivo, Huawei, and Xiaomi.
"We noticed something was wildly wrong," Falé noted during his technical breakdown. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"
+-----------------------------------------------------------------------+
| INFECTED H96 TV BOX |
| |
| [ HDMI Signal Active? ] |
| | |
| +---> YES: Low CPU Mode --> Acts as Residential Proxy Relay |
| | |
| +---> NO: High CPU Mode --> Spoofs Mobile User-Agent |
| --> Executes AI-Driven Ad Clicks |
+-----------------------------------------------------------------------+
2. The Fengwo Connection and App Pipeline
Deep inspection of the device telemetry revealed that every infected TV box carried a identical pair of pre-installed applications developed by Zhejiang Fengwo IoT Technology Ltd. Founded in 2019 in mainland China, the company manages a commercial ad-publishing ecosystem under the name Fengwo Group.
A cross-examination of intellectual property databases confirmed that Fengwo Group holds multiple technical patents directly matching the core architecture of the spoofing and ad-interaction apps found inside the generic TV boxes. To collect revenue generated by this enterprise, the organization established a web of legal shell companies and proxy entities across Hong Kong and Singapore.
3. Low-Code Fraud Generation via Google Blockly
To streamline operations and minimize engineering overhead, the Fengwo Group integrated an internal implementation of Blockly—a visual, block-based programming tool originally developed by Google to teach children software development principles.

Rather than requiring senior engineers to manually write custom fraud scripts for every targeted ad platform, Fengwo developers created standardized technical templates. Low-skilled operators can drag and drop visual logic blocks inside a custom Blockly editor to configure specific ad-fraud tasks. Once saved, the editor automatically converts the visual workflow into executable JavaScript and pushes it to cloud-hosted Amazon Web Services (AWS) S3 buckets.
Internal developer documentation exposed during the investigation highlighted this strategy: senior engineers build the fundamental template execution environments, while junior operators build modular fraud routines using visual blocks. This architectural design substantially lowered operating costs while allowing rapid scaling of ad-fraud campaigns.
+-----------------------------------------------------------------------+
| BLOCKLY FRAUD SCRIPT PIPELINE |
| |
| [ Junior Operator ] |
| | |
| v (Drag-and-Drop Blocks: "Open Tab" -> "Find Ad" -> "Click") |
| [ Blockly Editor Interface ] |
| | |
| v (Automated Transpilation) |
| [ Fraudulent JavaScript Code ] |
| | |
| v (Deployed via AWS S3) |
| [ Target H96 Streaming Box ] |
+-----------------------------------------------------------------------+
4. Multimodal AI Integration and Human Emulation
When an H96 device receives an ad-fraud command, it dynamically pulls down the corresponding JavaScript module. The infected streaming stick opens a hidden background browser session, navigates to target URLs, creates dynamic tabs, and interacts with on-screen content.
To overcome modern ad-verification and bot-detection systems, the Fengwo Group fused three distinct vision and spatial reasoning systems into a single operational interface. This engine analyzes web pages in real-time, accurately differentiating between body content and ad banners, calculating realistic coordinates, and simulating natural human cursor movement and click behavior.
5. Adaptive Dual-Mode Operation: The HDMI Trigger
One of the most noteworthy findings of the Bitsight report is the dynamic resource-management strategy employed by the malware. Ad fraud requires rendering full web pages, executing complex JavaScript engines, and processing AI visual models—tasks that draw heavily on a device’s processor (CPU) and graphics unit (GPU). If performed while a user is attempting to stream a 4K movie, video playback would lag, alerting the owner to the anomaly.

To evade detection, the malware continuously monitors the streaming box’s HDMI output status:
- TV Status: ON (HDMI Active): The device assumes the user is actively watching content. It temporarily halts heavy ad-fraud operations and switches to Residential Proxy Mode, silently routing third-party bandwidth traffic while preserving media-playback performance.
- TV Status: OFF/STANDBY (HDMI Inactive): The device senses that the display is powered down or disconnected. It ramps up hardware allocation and initiates resource-intensive ad fraud jobs.
Supporting Context and Metrics
Estimated Financial Impact
Based solely on the 38,000 infected devices actively communicating with the single sinkholed telemetry domain, Bitsight calculates that this specific branch of the fraud ring nets approximately $50,000 per day in programmatic ad revenue.
| Metric | Estimated Value |
|---|---|
| Tracked Active Devices (Single Domain) | ~38,000 units globally |
| Estimated Daily Ad-Fraud Revenue | ~$50,000 USD / day |
| Estimated Annualized Scale (Conservative) | ~$18.2 Million USD / year |
| Secondary Revenue Streams | Residential proxy bandwidth monetization |
Security researchers stress that these figures represent an exceptionally conservative baseline. The Fengwo Group maintains dozens of additional command-and-control domains, meaning the true global footprint of infected devices—and the corresponding financial losses borne by digital advertisers—is likely several orders of magnitude larger.
The "AI Digital Humans" Front
The commercial website for the Fengwo Group (fwgcloud[.]com) advertises the company as a pioneer in artificial intelligence, claiming to maintain a fleet of more than 120,000 "AI Digital Humans" available for rent in roles ranging from 24/7 automated customer service to emotional companionship.
FWGCLOUD[.]COM
|
+-------------------------+-------------------------+
| |
[ PUBLIC FACADE ] [ ACTUAL BACKEND ]
"120,000 AI Digital Humans" 38,000+ Exploited TV Boxes
Customer Service & Companionship Residential Bandwidth Proxies
Low-Code AI Innovation Automated Programmatic Ad Fraud
Bitsight’s analysis suggests this public front is largely marketing misdirection designed to obscure the company’s real underlying asset: an illicit botnet composed of exploited consumer hardware.

Botnet Synergies: Proxies and Local Network Risks
The presence of pre-installed backdoors on generic streaming boxes poses risks that extend far beyond ad metrics. Because these devices run unverified, custom Android builds lacking basic authentication controls, they serve as vulnerable initial access points within home and enterprise networks.
In early 2026, proxy tracking service Synthient documented how malicious botnets—including the widespread Kimwolf botnet—exploited security vulnerabilities in pre-installed proxy applications to compromise millions of consumer streaming boxes, using them to execute lateral network pivots against local routers, smart devices, and connected storage units.
Official Statements and Industry Context
Law Enforcement and Regulatory Alerts
The Federal Bureau of Investigation (FBI) has issued repeated public warnings regarding uncertified Internet of Things (IoT) hardware and grey-market streaming sticks.
"Uncertified home internet-connected devices, particularly low-cost streaming media players and smart home appliances, frequently ship with compromised firmware capable of facilitating criminal activity, conducting network interception, and enabling large-scale digital fraud," the FBI noted in a cybersecurity advisory.
E-Commerce Proliferation and Response
Despite systemic security warnings, major online retail platforms—including Amazon, Best Buy, and Newegg—continue to host listings for hundreds of generic, unbranded Android TV boxes. Frequently promoted by social media influencers as cost-effective tools to bypass subscription paywalls, these devices enter consumer homes pre-configured with factory-installed malware.

Attempts by journalists and security researchers to secure official comments from the threat actors behind the network have proven unsuccessful. Inquiries sent to the corporate contact address listed on the Fengwo Group homepage (postmaster@fwgcloud[.]com) bounced back immediately due to overfilled mailboxes and inactive server endpoints.
Future Outlook and Mitigation Strategies
The discovery of the Fengwo Group’s ad-fraud network underlines an evolving threat model: consumer IoT devices are no longer merely targeted for Distributed Denial of Service (DDoS) botnets, but are increasingly being weaponized as commercial engines for complex digital ad fraud and bandwidth reselling.
+-------------------------------------------------------------------------+
| CONSUMER RISK REDUCTION CHECKLIST |
+-------------------------------------------------------------------------+
| [ ] Purchase streaming hardware exclusively from accredited OEMs. |
| [ ] Verify device Play Protect Certification via Android settings. |
| [ ] Isolate legacy or generic IoT hardware on a segregated Guest VLAN. |
| [ ] Audit connected home networks for unverified residential proxies. |
| [ ] Consult IoT vulnerability registries (e.g., Synthient trackers). |
+-------------------------------------------------------------------------+
Recommendations for Consumers and Enterprise Defenders
- Prioritize Certified Hardware Ecosystems: Consumers are strongly advised to purchase streaming devices exclusively from established, certified manufacturers. Google provides verification mechanisms allowing users to confirm whether a device runs an official, certified build of Android TV equipped with Google Play Protect.
- Audit IoT Device Registers: Network administrators and home users should consult public IoT vulnerability resources—such as Synthient’s maintained tracker of pre-infected consumer devices—to identify high-risk hardware, including budget streaming sticks and unbranded digital photo frames.
- Network Isolation: Any uncertified smart home appliance or budget streaming hardware should be restricted to a segregated Guest Virtual Local Area Network (VLAN) with limited local device access, preventing compromised firmware from executing lateral attacks across the broader home or enterprise network.
As AI tools continue to simplify visual automation and script generation, the convergence of cheap hardware, pre-installed supply-chain backdoors, and automated ad-clicking engines will remain an ongoing challenge for cybersecurity defenders and digital advertisers alike.
