The Trojan Horse in Your Living Room: How Generic TV Boxes Are Fueling a Global Ad-Fraud Empire

the-trojan-horse-in-your-living-room-how-generic-tv-boxes-are-fueling-a-global-ad-fraud-empire-1

For years, cybersecurity researchers have issued a persistent, urgent warning regarding the “too good to be true” allure of generic, low-cost TV streaming boxes. These devices, often marketed as gateways to unlimited, free content for a one-time fee, are ubiquitous on major e-commerce platforms. However, beneath the promise of free entertainment lies a sinister reality: these devices act as sophisticated Trojan horses, turning your home internet connection into a clandestine weapon for cybercriminals.

A groundbreaking investigation by security firm Bitsight has now unmasked a sprawling, industrial-scale ad-fraud operation. The research reveals that these devices do more than just relay your bandwidth to strangers; they actively impersonate mobile devices to generate fraudulent revenue by clicking on advertisements across a vast network of AI-generated websites.

The Anatomy of an Ad-Fraud Operation

The investigation, led by Bitsight threat researcher Pedro Falé, began when he successfully registered an expired domain name previously used by the “H96” brand of streaming boxes. These devices are widely sold on platforms like Amazon and Newegg. The domain was intended for telemetry—a system used by manufacturers to collect hardware information and monitor installed applications on devices distributed globally.

What Falé discovered upon analyzing the incoming data stream was staggering. The vast majority of these streaming boxes—devices tethered to televisions—were reporting themselves as mobile phones from major manufacturers, including Samsung, Huawei, Vivo, and Xiaomi.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

“We noticed something was wildly wrong,” Falé told KrebsOnSecurity. “Multiple devices reporting to this factory Android TV Box backdoor were claiming to be mobile phones.”

By inspecting the software environment, Falé identified two specific, malicious applications pre-installed on these units. These apps were traced back to a mainland China-based entity known as Zhejiang Fengwo IoT Technology Ltd, operating under the umbrella of the "Fengwo Group."

Chronology of a Digital Heist

The sophistication of the Fengwo operation suggests a highly coordinated effort to bypass modern ad-verification systems. The process follows a distinct, automated lifecycle:

  1. The Supply Chain Injection: The malicious software is embedded into the firmware of the TV boxes at the factory level. By the time a consumer unboxes the device, it is already a compromised node in a global botnet.
  2. The Spoofing Mechanism: Upon connection to the internet, the device initiates a spoofing routine. It strips away its identity as an Android TV box and masquerades as a legitimate mobile handset. This is crucial because advertising networks typically pay higher premiums for mobile traffic, and mobile traffic is often subject to different (and sometimes less rigorous) fraud detection protocols.
  3. The AI-Driven Ad Fraud: When the television is powered off, the device shifts from its role as a residential proxy (renting out your IP address) to an active ad-fraud engine. It silently launches web browsers in the background, visits AI-generated news and content sites managed by the Fengwo Group, and clicks on ads.
  4. The Human-Mimicry System: To evade detection by ad networks, the Fengwo Group utilizes an advanced "vision and reasoning system." This interface allows the bot to navigate websites, manage browser tabs, and identify advertisements with the same behavioral characteristics as a human user, effectively tricking the fraud-detection algorithms of major advertising networks.

The "Blockly" Shortcut: Democratizing Cybercrime

One of the most concerning findings from the Bitsight report is the operational efficiency of the Fengwo Group. The company utilized an internal wiki platform that linked their operations to a proprietary implementation of Blockly, a visual programming language developed by Google to teach children how to code.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

In the hands of the Fengwo Group, Blockly became a tool for industrial-scale fraud. By dragging and dropping code blocks, even low-skilled operators could define complex fraud routines—such as which sites to visit, how long to stay, and which ad elements to interact with. Once saved, these routines are exported as JavaScript and deployed to cloud-based servers, allowing for the rapid scaling of the fraud operation with minimal technical oversight.

Internal communications from the developers, uncovered by Bitsight, reveal a cold, business-like approach to this criminality. They noted that their template-based execution units allowed them to maintain a small team of high-level developers while offloading the “execution” tasks to less skilled staff, thereby significantly reducing operating costs.

Supporting Data: The Scale of the Deception

Bitsight tracked approximately 38,000 H96 streaming boxes phoning home to a single expired domain. From this limited sample, researchers estimate that the ad-fraud network generates roughly $50,000 in revenue daily. Crucially, this figure does not include the additional, likely substantial, income generated by renting out the devices as residential proxies—a service often used by cybercriminals to hide their digital footprints while conducting credential stuffing, account takeovers, or scraping sensitive data.

The Fengwo Group’s own marketing claims to possess over 120,000 “AI digital humans” available for rent. While Bitsight researchers believe this may be a mixture of marketing hyperbole and a strategic facade to mask the true scale of their botnet, the potential reach of their infrastructure is immense.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The Silent Presence: Residential Proxies

Beyond the ad fraud, these devices serve as "residential proxies." This means the device acts as a gateway for third parties to route their internet traffic through your home network. When you purchase an H96 or similar uncertified device, you are essentially opening your home’s digital door to anyone willing to pay for access. This has been used by ticket scalpers, content scrapers, and, more dangerously, state-sponsored actors and cybercriminals to bypass IP-based security controls.

The danger is amplified by the fact that these devices are inherently insecure. They lack proper authentication and are frequently riddled with vulnerabilities. As documented by the security service Synthient in January 2026, various botnets—including the notorious “Kimwolf” network—have successfully enslaved millions of these devices, creating a cascading security risk that can impact every other device connected to your home network, including your laptop, phone, and smart home appliances.

Official Responses and Industry Accountability

The FBI has issued multiple alerts warning that internet-connected IoT devices are being leveraged to facilitate criminal activity. Despite these warnings, the supply chain for these devices remains largely unchecked.

Major e-commerce retailers, including Amazon, Newegg, and Best Buy, continue to list these products. While some platforms have begun to take limited action, the sheer volume of "white-label" brands makes it difficult to police. Many of these boxes are marketed by online influencers, who often fail to disclose the inherent security risks, further driving consumer adoption.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

In response to inquiries regarding the Fengwo Group, KrebsOnSecurity attempted to reach out to the company via their provided contact email. The request bounced back with a delivery failure notice: “Your message couldn’t be delivered… Their inbox is full, or it’s getting too much mail right now.”

Implications: A Call for Digital Hygiene

The implications of the Bitsight investigation are clear: the "cheap" TV box is a false economy. The hidden costs—in terms of privacy, security, and the degradation of the broader digital advertising ecosystem—are severe.

What can consumers do?

  • Prioritize Certification: Stick to name-brand devices from reputable manufacturers. Google provides clear instructions on how to verify if a device is built with the official Android TV OS and maintains Play Protect certification.
  • Audit Your Network: If you already own an unbranded streaming box, consider disconnecting it. If you must use it, isolate it on a separate "Guest" network that has no access to your primary devices or sensitive data.
  • Monitor Traffic: Use tools to monitor your network traffic for unusual activity, particularly if you see your device "phoning home" to unknown domains or participating in high volumes of outbound traffic when not in use.
  • Consult Reliable Lists: Services like Synthient maintain running lists of IoT devices known to ship with malicious proxy software. Check these lists before making any IoT purchase.

As the digital landscape becomes increasingly cluttered with AI-driven automation, the divide between legitimate tools and malicious infrastructure continues to blur. The Fengwo Group’s operation is a stark reminder that in the modern internet, if you aren’t paying for the product, you are often not just the product—you are the infrastructure being used to exploit others.