Security firm Bitsight says it found an H96 TV box ad fraud operation in which cheap Android streaming devices pretended to be mobile phones, visited AI-generated websites and clicked ads for profit. The finding gives buyers another reason to treat bargain streaming sticks and TV boxes that promise cut-rate access to paid content as hostile hardware, not harmless living-room gadgets.
Pedro Falé, a threat researcher at Bitsight, told KrebsOnSecurity that he got visibility into the network after registering an expired domain that had been used to coordinate activity from H96 devices. Falé said the domain had collected telemetry from tens of thousands of boxes worldwide, including hardware details and installed app lists.
The strange part, according to Falé, was that many devices reporting to the domain did not identify themselves as TV boxes. They claimed to be phones from brands including Samsung, Vivo, Huawei and Xiaomi.
What did Bitsight find on H96 TV boxes?
Bitsight said the devices commonly reported two installed apps made by Zhejiang Fengwo IoT Technology Ltd, a mainland China company founded in 2019 that operates an ad-publishing business under the Fengwo Group name. Bitsight said it connected the company to the apps through infrastructure, SSL certificate data, app behavior and patents that matched the software’s methods.
According to Bitsight, the apps help run ad fraud by using the TV boxes as a captive traffic pool. The boxes load websites operated by Fengwo Group, where machine-made articles and graphics cover topics such as finance, health, education, games, music and food. Bitsight said those sites did not show ads unless the visitor matched the spoofed mobile profile used by the H96 devices.
Ad fraud, in this case, means the system tries to make fake visits and clicks look like real consumer activity so merchants and ad networks pay for traffic that did not come from an actual interested person. The victim is not just the advertiser. The box owner’s electricity, bandwidth and home IP address become part of the machinery.
Falé said the Fengwo Group’s own site claims the company has more than 120,000 “AI digital humans” available for uses including companionship, customer service and design. Bitsight treated that claim cautiously, saying it could be marketing cover rather than a literal description of the operation.
How did the ad-clicking system work?
Bitsight said Fengwo Group employees used a proprietary implementation of Blockly, Google’s visual programming language originally built to teach children coding concepts, to assemble fraud routines. In Bitsight’s account, operators could drag blocks together, export the routine as JavaScript and upload it to cloud storage, lowering the skill needed to create new tasks.
When a selected H96 box received a task, Bitsight said it could silently open a browser, visit pages, move through tabs and click ads. The report said the operation combined several vision and reasoning systems so the bots could identify ads on the page and interact with sites in a human-like way.
Bitsight also found the devices split their time between two abuses. When an attached TV showed an HDMI signal, meaning the owner was likely using the box, the device usually acted as a residential proxy. When the TV was off, it returned to waiting for ad-fraud jobs, according to Bitsight.
A residential proxy rents out a household internet connection to other users, making their traffic appear to come from that home. Security researchers and the FBI have warned that such services can be used by scrapers, ticket scalpers and criminals who want traffic to look less suspicious.
How big was the operation?
Bitsight said it observed about 38,000 TV boxes contacting the expired Fengwo Group domain. Based on that visibility, the firm estimated ad fraud revenue near $50,000 per day, excluding money from the residential proxy side. Falé said that estimate was conservative because it came from one older core domain.
KrebsOnSecurity reported that an email seeking comment from the Fengwo Group bounced because the listed mailbox could not receive the message.
The practical advice is boring because the safe answer usually is: buy streaming devices from reputable manufacturers, avoid no-name Android boxes with unofficial software, and be suspicious of apps that arrive preinstalled. Google says consumers can check whether a device uses official Android TV OS and has Play Protect certification. Synthient also maintains a public list of internet-connected devices known to ship with residential proxy software or malicious apps.
This story draws on original reporting from Krebs on Security.