Generic TV streaming sticks marketed as budget alternatives to official devices are running a sophisticated ad fraud scheme alongside renting users’ internet connections to strangers, according to new research from security firm Bitsight.

Threat researcher Pedro Falé discovered the operation by registering an expired domain previously used to coordinate activity across tens of thousands of H96 streaming devices globally. Upon inspection, Falé found the devices were transmitting data while spoofed as mobile phones from manufacturers including Samsung, Vivo, Huawei, and Xiaomi.
The devices all reported having the same two apps installed, created by Zhejiang Fengwo IoT Technology Ltd, a company founded in 2019 in mainland China operating under the Fengwo Group. According to Bitsight’s analysis, these apps coordinate an ad fraud network where the H96 devices click on ads hosted on AI-generated websites operated by Fengwo Group.
The sham websites contain machine-generated articles across finance, health, education, gaming, music and food categories, but only display ads when visited by devices with spoofed mobile profiles. Fengwo Group uses a Google-built visual programming language called Blockly to build these sites, allowing low-skilled operators to construct fraud routines without deep technical knowledge.
When selected for fraud tasks, H96 boxes are pushed modules that silently launch web browsers, visit websites, and click ads. The system uses vision and reasoning technology to identify ads and navigate sites like a human would.
Bitsight found H96 devices switch between two modes: when a TV is connected via HDMI, the boxes function as residential proxies, renting the user’s internet address to paying customers. When the TV is off, they switch to ad fraud operations. Falé said this dual-mode design likely exists because ad fraud is more resource-intensive and could interfere with streaming performance.
Based on telemetry from approximately 38,000 H96 devices phoning home to the expired Fengwo domain, Bitsight estimates the ad fraud network generates roughly $50,000 daily—not including substantial revenue from the residential proxy operations. Falé emphasized these are conservative estimates based on one older core domain.
Despite repeated FBI warnings about security risks, major retailers including Amazon, Best Buy, and Newegg continue selling hundreds of generic streaming device models bundled with unofficial Android versions. These devices are frequently marketed as ways to access streaming services without subscriptions but come with virtually no security protections, making home networks vulnerable to botnet attacks and other compromise.
Key facts
- H96 streaming sticks spoof themselves as mobile phones to click ads on AI-generated websites operated by Zhejiang Fengwo IoT Technology Ltd
- The devices operate in two modes: residential proxy when TV is on, ad fraud when TV is off
- Bitsight tracked approximately 38,000 devices and estimates the ad fraud operation generates around $50,000 daily
- Fengwo Group uses Google’s Blockly visual programming language to build sham websites and fraud routines
- The devices are pre-installed with residential proxy software that rents users’ internet addresses to third parties