Summary
- Bitsight researcher Pedro Falé registered an expired domain previously used to coordinate activity across roughly 38,000 H96 Android TV streaming sticks, exposing a large-scale ad fraud operation.
- The devices spoof themselves as mobile phones from brands including Samsung and Huawei, then click ads on AI-generated websites operated by a mainland China company called Zhejiang Fengwo IoT Technology Ltd.
- When a television is on and an HDMI signal is detected, the device functions as a residential proxy; when the TV is off, it reverts to ad fraud tasks.
- Bitsight estimates the operation generates close to $50,000 per day in ad fraud revenue from telemetry tied to just one older domain, with residential proxy revenue counted separately.
- Major retailers including Amazon, Best Buy, and Newegg continue to sell hundreds of models of these off-brand devices despite repeated warnings from the FBI and security researchers.
An Expired Domain Opens a Window
The investigation began with an opportunistic move. Pedro Falé, a threat researcher at Bitsight, registered an expired domain name that had previously been used to collect telemetry from H96-branded Android TV streaming sticks — a popular category of low-cost devices sold as a way to access streaming content without a subscription. What the domain returned was not routine diagnostics. Tens of thousands of devices were reporting in, and almost none of them were identifying themselves as television boxes. Instead, they were presenting as mobile phones from manufacturers including Samsung, Vivo, Huawei, and Xiaomi. “We noticed something was wildly wrong,” Falé told KrebsOnSecurity. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'”
The Fengwo Group and Its Ad Fraud Infrastructure
Falé traced the operation to Zhejiang Fengwo IoT Technology Ltd, a company founded in 2019 in mainland China that operates under the name Fengwo Group. All of the H96 devices he observed reported having the same two apps installed, both attributable to Fengwo. The company has registered patents that align with how those apps function, and Bitsight found shell identities in Hong Kong and Singapore being used to collect monetisation proceeds before the trail led back to the mainland Chinese entity.
AI-Generated Websites and Blockly-Built Fraud Routines
The spoofed mobile phone identity serves a specific purpose. Bitsight found that the Fengwo Group operates a portfolio of AI-generated websites spanning categories such as finance, health, gaming, and food. Critically, those sites only serve advertisements when the visiting device matches the spoofed mobile profile of an H96 device — meaning the fraud is deliberately concealed from ordinary visitors. The group uses a Google-developed visual programming language called Blockly, originally designed as a coding learning tool for children, to allow relatively low-skilled operators to assemble fraud routines by dragging code blocks together. According to Bitsight’s report, one of the Fengwo Group’s own app developers noted that this approach means “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.” The resulting fraud modules can instruct a device to silently launch a browser, visit websites, manage tabs, and click on ads.
TV On, Proxy Mode. TV Off, Fraud Mode.
Bitsight established that the devices switch between two distinct roles depending on whether a television is connected and active. When an HDMI signal is present — indicating a user is likely streaming content — the box operates as a residential proxy, renting the household’s internet connection to anonymous third-party customers. When the television is switched off, the device waits for ad fraud jobs to be pushed to it. Falé assessed that the separation exists because the ad fraud activity is resource-intensive enough to interfere with the device’s primary streaming function, which would draw unwanted attention from users.
Scale and Revenue Estimates
Based on the approximately 38,000 devices observed phoning home to the single expired domain, Bitsight estimates the ad fraud component of this operation generates close to $50,000 per day. Falé was explicit that this figure is conservative, derived from telemetry associated with just one older domain. Revenue from the residential proxy side of the operation is not included in that estimate. The Fengwo Group’s public-facing website claims the company has created more than 120,000 “AI digital humans” available for hire. Bitsight’s report raises the possibility this is a facade designed to make the company’s operations appear legitimate, noting that proxy and botnet operators have historically used innocuous-sounding public profiles to avoid scrutiny.
Broader Ecosystem Risk
The H96 devices are not an isolated case. Security researchers and the FBI have repeatedly warned that off-brand streaming sticks and boxes almost universally ship with residential proxy software pre-installed. These devices are sold in large volumes through mainstream retail channels and are frequently promoted by online influencers as a way to access content without subscription costs. In January, the proxy tracking service Synthient documented how multiple botnets had compromised millions of TV boxes by exploiting security vulnerabilities in both the streaming devices and the residential proxy software embedded in them. The risk extends beyond streaming devices: the FBI has also identified residential proxy software in other consumer IoT products, including digital photo frames.
Why it matters
For CISOs, the immediate concern is network hygiene. Any off-brand streaming device or IoT product connected to a corporate guest network, executive home office, or shared workspace is a potential residential proxy node and ad fraud endpoint operating entirely below the user’s awareness. The Fengwo operation demonstrates that these devices are not merely poorly secured — they are purpose-built to be exploited, with fraud infrastructure baked in at the firmware level. The switching behaviour between proxy and fraud modes makes detection harder, since activity only emerges when the device appears idle. Organisations with bring-your-own-device or home-working policies should consider whether consumer IoT devices on the same network segments as corporate traffic represent an acceptable risk.
What to do now
- Avoid purchasing or deploying off-brand, generic Android TV streaming sticks and boxes. Stick to devices from established manufacturers with verifiable supply chains.
- Verify that any Android TV device in use carries official Android TV OS certification and Google Play Protect certification using the verification process Google has published.
- Consult Synthient’s published list of IoT devices known to ship with residential proxy software or malicious pre-installed apps, and audit whether any such devices are present on your networks.
- Review guest and home-office network policies to ensure unmanaged consumer IoT devices are isolated from corporate traffic segments.
- Exercise caution with apps installed on any Android TV device, including certified ones, as residential proxy software has also been found bundled in third-party applications.
