NewsAgg

local preview
technology

Hacked TV Streaming Sticks Run Ad Fraud, Spoof Mobile Phones

Security researchers discovered that generic Android TV boxes secretly participate in click fraud schemes while also renting out users' internet connections to strangers.

Hacked TV Streaming Sticks Run Ad Fraud, Spoof Mobile Phones

Security researchers have uncovered a sophisticated ad fraud operation embedded in popular generic TV streaming devices, according to analysis by Bitsight threat researcher Pedro Falé.

Hacked TV Streaming Sticks Run Ad Fraud, Spoof Mobile Phones

The researcher investigated H96 brand streaming sticks after registering an expired domain previously used to coordinate the devices. Upon examining traffic, Falé discovered the TV boxes were spoofing themselves as mobile phones from manufacturers including Samsung, Vivo, Huawei, and Xiaomi, then clicking ads on AI-generated websites.

Bitsight traced the operation back to Zhejiang Fengwo IoT Technology Ltd, a mainland China company founded in 2019 that operates under the Fengwo Group brand. The company has registered patents matching the inner workings of apps found on the compromised devices.

The scheme works through a two-pronged approach. When a TV is connected and in use, the boxes function as residential proxies—renting the user’s internet connection to third parties. When the TV is powered off, the devices switch to ad fraud mode, visiting websites containing machine-generated content across finance, health, education, gaming, music, and food categories. The apps coordinate clicks on ads displayed only to devices spoofing the H96 mobile profile.

To streamline operations, Fengwo Group uses Google’s Blockly visual programming language, originally designed to teach children coding. This allows low-skilled operators to build fraud routines by dragging code blocks together without understanding the underlying technical details, according to Bitsight’s report.

The devices use advanced vision and reasoning systems to identify and click ads like humans would. Bitsight tracked approximately 38,000 TV boxes globally communicating with the Fengwo domain and estimated the ad fraud network generates close to $50,000 daily—not including residential proxy revenue.

These generic streaming devices, widely sold on Amazon, Best Buy, Newegg, and other retailers, come with minimal security. They typically arrive pre-loaded with residential proxy software and possess severe vulnerabilities. In January, proxy tracking service Synthient documented how multiple botnets rapidly enslaved millions of TV boxes exploiting these security flaws. The FBI and security industry leaders have repeatedly warned about risks from these devices.

Key facts

  • H96 streaming sticks spoof mobile phones from Samsung, Vivo, Huawei, and Xiaomi to participate in ad fraud
  • Zhejiang Fengwo IoT Technology Ltd, a mainland China company, operates the fraud network using apps with registered patents
  • The operation generates an estimated $50,000 daily from ad fraud alone, separate from residential proxy revenue
  • Devices switch between proxy mode (TV on) and ad fraud mode (TV off) to avoid interfering with streaming
  • Fengwo Group uses Google’s Blockly programming tool to allow non-technical operators to build fraud routines

Sources

← All posts