Cheap Android TV Boxes Sold Online Secretly Function as Mobile Phone Spoofers to Fuel Global Ad Fraud Empire

The marketplace for consumer electronics has long grappled with the proliferation of low-cost, generic streaming devices promising endless entertainment for a nominal, one-time fee. For years, cybersecurity researchers and law enforcement agencies have warned that these bargain-priced hardware alternatives covertly transform residential internet connections into commercial proxies, renting out private bandwidth to anonymous third parties. However, a comprehensive new threat analysis has unveiled a far more insidious layer to this illicit trade. Beyond passive bandwidth monetization, a prominent family of generic Android TV boxes has been systematically weaponized to execute automated advertising fraud on a massive, global scale.
By spoofing mobile device signatures, clicking on AI-generated web traffic, and seamlessly transitioning between background botnet duties and user-initiated video streaming, these pre-infected devices operate as silent profit centers for overseas threat actors. The findings expose critical systemic vulnerabilities in the global supply chain of uncertified internet-of-things (IoT) devices, highlighting how everyday household gadgets are being exploited to bilk digital advertising networks and online merchants of millions of dollars annually.
Inside the Ad Fraud Operation: The Discovery of the H96 Network
The intricate mechanics of this global ad fraud enterprise came to light through the investigative work of Pedro Falé, a threat researcher with the cybersecurity firm Bitsight. Falé’s breakthrough occurred when he registered an expired domain name previously utilized for telemetry by a popular brand of generic Android streaming sticks known commercially as H96.
For years, these devices—widely distributed via major e-commerce platforms such as Amazon, Best Buy, and Newegg—had been shipping directly from factories pre-infected with telemetry and management software. The expired domain in question was originally responsible for periodically collecting exhaustive hardware profiles and full lists of installed applications from tens of thousands of H96 streaming sticks deployed in living rooms worldwide.

Upon analyzing the inbound traffic routed to the newly acquired domain, Falé discovered a striking anomaly. The vast majority of the television boxes transmitting data were reporting hardware identities that completely contradicted their physical nature. Instead of identifying as fixed-location Android TV units, the devices were vigorously claiming to be mobile smartphones manufactured by prominent industry leaders, including Samsung, Vivo, Huawei, and Xiaomi.
"We noticed something was wildly wrong," Falé remarked during an interview detailing the investigation. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’"
Tracing the Infrastructure to the Fengwo Group
A deeper forensic inspection of the applications installed across these phoning-home devices revealed a common denominator: two distinct software packages traced back to a corporate entity established in mainland China in 2019, known as Zhejiang Fengwo IoT Technology Ltd., which operates an extensive portfolio under the umbrella of the Fengwo Group.
Bitsight’s threat intelligence platform, Bitsight TRACE, successfully mapped the financial conduits of the operation. Researchers uncovered a complex web of shell identities operating out of Hong Kong, Singapore, and various single-person legal entities designed to aggregate monetization proceeds from the ad fraud campaigns. The trail ultimately led directly back to the Fengwo Group headquarters in mainland China. Further validation of the corporate connection emerged when researchers discovered multiple registered patents held by the Fengwo Group that precisely mirrored the inner workings and software architecture found within the pre-installed apps on the H96 devices.
The applications in question act as orchestrators for a captive traffic source. They command the compromised H96 television boxes to visit a vast network of AI-generated websites operated by the Fengwo Group. These sham web properties span a diverse array of categories, including financial advice, health blogs, educational portals, gaming forums, music reviews, and culinary websites.

Crucially, Bitsight discovered that these sites were entirely devoid of advertisements unless the incoming visitor matched the spoofed mobile profile transmitted by an H96 device. The web pages themselves—consisting of machine-generated news articles and synthetic graphics—exist solely to capture fraudulent ad impressions and clicks generated by the botnet.
The Mechanics of Low-Skill, High-Volume Fraud
The infrastructure supporting the Fengwo Group’s ad fraud empire relies heavily on operational efficiency and a unique software development framework. According to Bitsight’s findings, the company’s primary domain, fwgcloud.com, prominently advertises its capabilities in human-AI interaction, claiming to offer more than 120,000 "AI digital humans" available to rent for tasks ranging from emotional companionship to round-the-clock customer service and creative design.
However, security analysts believe this high-tech facade may serve a dual purpose: providing a legitimate-looking corporate cover while obscuring the true scale and nature of the underlying botnet operations. Technical analysis of the domain’s SSL certificates and internal documentation revealed a direct link between the Fengwo Group and a proprietary implementation of Blockly, a Google-built visual programming language originally designed to teach children how to write software code.
By leveraging Blockly, the operators behind the Fengwo Group significantly lowered the technical barriers required to execute complex cyber fraud. Employees and low-skilled operators can drag and drop visual blocks of code within a user-friendly editor to define specific ad-fraud routines without needing to understand the underlying technical execution. Once saved, these routines are automatically exported as JavaScript modules and uploaded to cloud storage buckets, such as Amazon S3.
Internal communications uncovered by Bitsight highlighted the strategic advantage of this design. One Fengwo Group developer explicitly noted that the architecture requires only a small cohort of highly skilled engineers to build foundational template execution units. From there, lower-skilled operators can deploy customized fraud tasks at minimal operating cost.

When an H96 streaming stick is selected for an ad fraud task, it receives a targeted Blockly module. The module silently initiates a web browser in the background, navigates to designated web pages, manages browser tabs, and executes clicks on advertisements. To ensure maximum efficacy and mimic authentic human behavior, the Fengwo Group integrates a sophisticated tri-system of vision and reasoning tools. This interface enables automated bots to accurately identify advertisements amidst complex webpage layouts and navigate digital storefronts just as a human consumer would.
Dual-Role Hardware: TV On Equals Proxy, TV Off Equals Fraud
One of the most revealing discoveries of the Bitsight analysis is the operational scheduling programmed into the compromised H96 devices. Researchers observed that the streaming sticks never executed ad fraud and residential proxy traffic simultaneously.
Instead, the devices operate on a strict conditional logic governed by the television’s power state. When a user powers on their television and an active HDMI signal is detected—signalling an intent to stream legitimate video content—the H96 box temporarily suspends its ad fraud duties and functions purely as a residential proxy node. As soon as the television is turned off, the hardware seamlessly pivots back to awaiting instructions for background ad fraud tasks.
Security experts deduce that this resource allocation is intentional. Because ad fraud operations involving automated browser rendering and machine-vision navigation are intensely resource-heavy, running them concurrently with high-definition video streaming would severely degrade device performance, causing stuttering, buffering, or crashes that would immediately alert the consumer to foul play.
The Broader Threat Landscape and E-Commerce Complicity

The exposure of the H96 ad fraud scheme underscores a pervasive vulnerability within the global consumer electronics market. Despite repeated, explicit warnings issued by the Federal Bureau of Investigation (FBI) and international cybersecurity agencies regarding the inherent risks of utilizing unverified, low-cost streaming devices, major e-commerce platforms continue to host and distribute countless brands running uncertified, modified builds of Google’s Android operating system.
Influencer marketing campaigns across social media frequently champion these inexpensive boxes as loopholes for accessing premium cable broadcasts and subscription-based streaming libraries for free. In reality, consumers who purchase these devices unwittingly welcome advanced persistent threats directly into their home networks.
Beyond ad fraud, these generic streaming sticks universally arrive with pre-installed residential proxy software. This software commercializes the user’s home internet connection, routing malicious or anonymous third-party traffic through their residential IP address. According to tracking data from proxy intelligence firm Synthient, this infrastructure has been heavily abused by automated actors ranging from aggressive data scrapers and ticket scalpers to sophisticated cybercrime syndicates. In January, Synthient documented a massive campaign where botnets such as Kimwolf enslaved millions of vulnerable TV boxes by exploiting compounded security flaws present in both the proxy software and the underlying device firmware.
Quantifying the Impact and Financial Scale
While the full financial footprint of the Fengwo Group’s operations remains difficult to calculate precisely due to distributed shell companies and rotating domains, Bitsight’s conservative telemetry offers a stark window into the profitability of IoT-based fraud.
By monitoring approximately 38,000 active H96 TV boxes connecting to a single, older telemetry domain, researchers estimate that the ad fraud network generates upwards of $50,000 per day in revenue. This figure accounts solely for ad impressions and clicks, omitting the substantial secondary revenue streams generated through the simultaneous renting of residential proxy bandwidth. Because this estimate relies on telemetry from only a fraction of the threat actor’s active infrastructure, industry experts believe the true financial yield of the enterprise is significantly higher.

Attempts by security journalists to reach the Fengwo Group for comment via the contact email listed on their corporate domain yielded automated delivery failure notifications, with server administrators reporting that the inbox was completely full due to an overwhelming volume of incoming mail.
Mitigating the Risk: Consumer Guidance and Industry Action
The revelations surrounding the H96 streaming boxes and the Fengwo Group highlight an urgent need for heightened consumer vigilance and stricter regulatory oversight within the digital supply chain. Security analysts strongly advise consumers to avoid purchasing generic, unbranded streaming hardware from third-party marketplace vendors, recommending instead that households invest exclusively in certified name-brand devices from reputable manufacturers.
Furthermore, users are encouraged to audit their existing IoT ecosystems and exercise extreme caution when installing unauthorized third-party applications, many of which quietly bundle residential proxy services. Google provides official support guidelines allowing consumers to verify whether an Android TV device is built with legitimate OS integration and Google Play Protect certification. Additionally, threat intelligence organizations like Synthient maintain publicly accessible registries cataloging consumer IoT products known to ship with pre-installed malicious software or proxy routines—extending beyond TV sticks to include vulnerable connected devices such as digital photo frames.
As ad fraudsters continue to weaponize machine learning, computer vision, and unsuspecting consumer hardware, the intersection of IoT security and digital advertising integrity remains a critical frontline in modern cybersecurity defense.







