Security researchers have uncovered a sophisticated ad fraud operation embedded in generic TV streaming devices, according to analysis by threat researcher Pedro Falé at security firm Bitsight.

The investigation began when Falé registered an expired domain previously used by H96 streaming devices—a popular brand of unauthorized Android TV boxes sold on major e-commerce platforms. Upon analyzing traffic to the domain, Falé discovered that nearly all devices transmitting data were claiming to be mobile phones from manufacturers including Samsung, Vivo, Huawei, and Xiaomi.
“We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’” All devices reported having the same two apps installed, both created by Zhejiang Fengwo IoT Technology Ltd, a mainland China company founded in 2019 that operates the Fengwo Group ad-publishing portfolio.
The apps coordinate an ad fraud network using H96 devices as traffic sources to click advertisements on AI-generated websites operated by Fengwo Group. These websites contain machine-generated news articles and graphics across finance, health, education, gaming, music, and food categories. Crucially, the sites display ads only when visited by devices matching the H96 spoofed mobile profiles.
Bitsight found that Fengwo Group uses a Google-built visual programming language called Blockly to build the fraudulent websites. This allows low-skilled operators to drag code blocks together without understanding underlying mechanics. When an H96 device is selected for a fraud task, it receives the appropriate Blockly module, which can silently launch browsers, visit websites, and click ads. The system uses three vision and reasoning systems to identify ads and navigate sites like a human would.
Interestingly, Bitsight discovered the devices operate in two modes: when a television is connected via HDMI, the boxes function as residential proxies, renting the user’s internet connection to third parties. When the TV is off, they switch to performing ad fraud tasks—likely because ad fraud requires more processing power and could interfere with streaming.
Bitsight tracked approximately 38,000 TV boxes globally connecting to the expired Fengwo domain and estimates the ad fraud network generates roughly $50,000 daily, though researchers emphasized these figures are conservative estimates based on telemetry from just one older domain.
These generic streaming devices, widely sold on Amazon, Best Buy, and Newegg, have been repeatedly flagged by the FBI for security and privacy risks. Beyond ad fraud, they come pre-installed with residential proxy software that rents users’ internet addresses to unknown customers, including content scrapers, ticket scalpers, and cybercriminals.
Key facts
- H96 streaming devices spoof themselves as mobile phones to click ads on AI-generated websites
- The fraud operation is connected to Zhejiang Fengwo IoT Technology Ltd, a mainland China company
- Bitsight tracked approximately 38,000 devices globally participating in the scheme
- The ad fraud network is estimated to generate around $50,000 daily
- Generic TV boxes switch between residential proxy mode (when TV is on) and ad fraud mode (when TV is off)
- These devices are widely sold on major e-commerce platforms despite FBI warnings