Online Security & Privacy

The Hidden Cost of Cheap Streaming: How Generic TV Boxes Are Fueling a Global Ad Fraud Empire

Security experts have been sounding the alarm for years regarding the risks associated with generic, low-cost TV streaming boxes that promise unlimited content for a one-time fee, but a new investigation reveals the threat is far more pervasive and sophisticated than previously understood. While early warnings focused on these devices turning home networks into residential proxies for cybercriminals, a groundbreaking analysis by the security firm Bitsight has exposed a massive, automated ad fraud operation. These devices are not merely passive proxies; they are actively masquerading as mobile smartphones to commit large-scale digital advertising fraud, generating tens of thousands of dollars in illicit revenue every day for a shadowy network linked to mainland China.

The operation, which centers on the popular H96 brand of streaming sticks, functions through a complex, two-tier exploitation model. According to Pedro Falé, a threat researcher at Bitsight, the devices are programmed to toggle their malicious activities based on the status of the television. When a user is actively watching content—signaled by an HDMI connection—the device operates as a residential proxy, effectively renting out the user’s home internet bandwidth to third parties. When the television is powered off, the device shifts its primary function to a high-intensity ad fraud botnet.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

Unmasking the Spoofing Mechanism

The discovery began when Bitsight researchers registered an expired domain that had previously served as a telemetry server for H96 devices. By monitoring the traffic flowing into this domain, Falé discovered that the streaming boxes were systematically misrepresenting their hardware profiles. Although the devices were physically stationary Android-based TV boxes, their outbound telemetry claimed they were high-end mobile smartphones, specifically mimicking models from major manufacturers such as Samsung, Vivo, Huawei, and Xiaomi.

This "spoofing" is a critical component of the fraud. Advertising networks pay significantly higher premiums for traffic originating from mobile devices compared to desktop or TV-based environments. By masquerading as mobile phones, the H96 botnet makes its automated, machine-generated clicks appear more valuable and legitimate to ad exchanges. The research team identified that these devices were pre-loaded with specific applications developed by Zhejiang Fengwo IoT Technology Ltd, a Chinese entity operating under the "Fengwo Group" banner.

The Fengwo Group and the AI-Driven Fraud Ecosystem

Further investigation into the Fengwo Group revealed a highly organized infrastructure designed to minimize human intervention and operational costs. The group manages a portfolio of AI-generated websites featuring content across diverse categories, including finance, health, gaming, and food. These sites are essentially "hollow" shells; they display ads only when they detect a visitor—or a bot—that mimics the mobile phone profile of an infected streaming device.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The technical backbone of this operation relies on a proprietary implementation of Blockly, a visual programming tool originally created by Google to teach children the basics of software development. By using this drag-and-drop interface, low-skilled operators within the Fengwo Group can assemble complex ad-fraud routines without needing to write raw code. These routines are then exported as JavaScript and deployed to cloud-based S3 buckets, where they are pushed to the H96 devices as needed.

To ensure the "clicks" look genuine, the Fengwo Group has integrated advanced vision and reasoning systems into their software. These systems allow the bot-infected TV boxes to identify ads on a webpage, navigate menus, and interact with site content in a manner that closely replicates human behavior, effectively bypassing basic fraud detection filters utilized by major advertising networks.

Chronology of the Threat

The rise of the "cheap streaming box" phenomenon tracks closely with the expansion of the global IoT (Internet of Things) market.

Read This Before You Buy That TV Streaming Stick – Krebs on Security
  • 2019: Zhejiang Fengwo IoT Technology Ltd is established in mainland China, laying the foundation for what would later become an extensive ad-publishing and software-development portfolio.
  • 2023–2024: Security researchers begin noticing an uptick in "malware-as-a-service" models, where budget-friendly consumer hardware is shipped with pre-installed backdoor software.
  • January 2026: The proxy-tracking service Synthient reports that millions of TV boxes worldwide have been enslaved by botnets, marking a significant escalation in the scope of IoT-based network exploitation.
  • July 2026: Bitsight releases its findings on the Fengwo Group, detailing the link between residential proxies, device spoofing, and the use of AI to generate synthetic, ad-monetized content.

Supporting Data and Financial Impact

The sheer scale of the Fengwo Group’s operations is staggering. Bitsight telemetry tracked approximately 38,000 H96 devices phoning home to a single, expired domain. Based on this subset, analysts estimate that the ad-fraud component alone generates approximately $50,000 in revenue per day. This figure is considered a conservative estimate, as it only accounts for one of the group’s older telemetry domains. When combined with the revenue generated from the residential proxy business—where the company rents out thousands of home IP addresses to potentially malicious actors—the total financial intake is likely significantly higher.

The company’s own marketing claims to possess a network of 120,000 "AI digital humans" available for hire. While researchers remain skeptical of the literal interpretation of this claim, they suggest it may be a euphemism for the sheer number of automated, bot-controlled profiles at the company’s disposal. As Falé noted in his report, such claims are often part of a deliberate effort to create an "inconspicuous facade" to distract from the reality of their large-scale botnet operations.

Official Responses and Industry Accountability

The FBI has repeatedly issued warnings regarding the security risks of internet-connected consumer devices, particularly those that bypass official certification processes. Despite these warnings, major e-commerce platforms such as Amazon, Best Buy, and Newegg have struggled to police the influx of unverified streaming devices sold through their marketplaces. Many of these devices are marketed by online influencers as "must-have" tools for accessing free content, often masking the underlying security vulnerabilities from the consumer.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

The response from the entities involved has been telling. When KrebsOnSecurity attempted to reach the Fengwo Group for comment through the contact information provided on its website, the emails were returned as undeliverable due to "full inboxes," suggesting a lack of legitimate customer support or a deliberate attempt to avoid external scrutiny.

Broader Implications for the Digital Economy

The implications of this discovery extend far beyond the privacy of the individual consumer. For the digital advertising industry, this represents a multi-billion-dollar tax on legitimate businesses. When advertisers pay for clicks that are generated by bots rather than human consumers, they are essentially subsidizing the very criminal enterprises that are exploiting their customers.

Furthermore, the presence of these devices on private home and office networks presents a significant security risk. By allowing an unknown third party to control a device on a local network, users are inadvertently opening a door for further malicious activity, including network reconnaissance, data exfiltration, and the facilitation of illegal activities such as ticket scalping and content scraping.

Read This Before You Buy That TV Streaming Stick – Krebs on Security

For consumers, the advice from security experts is clear: the risk of using "dirt cheap", unbranded streaming hardware far outweighs the benefits of free, often unauthorized content. Google provides a certification process for Android TV OS devices, and users are strongly encouraged to verify that their hardware is certified by the Play Protect program. Reputable manufacturers provide consistent security updates and do not engage in the practice of bundling residential proxy software or ad-fraud modules.

As the industry moves forward, the "Fengwo case" serves as a stark reminder of the hidden costs of the modern internet. When a piece of technology is provided at a price that seems too good to be true, it is almost certain that the user is not the customer—they are the product, and their digital footprint is being sold, spoofed, and exploited on a global scale. The ongoing efforts by firms like Bitsight and Synthient to catalog and expose these botnets are crucial, but they also highlight a systemic failure in the hardware supply chain that continues to prioritize low costs over the fundamental security and privacy of the global internet population.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button