For years, cybersecurity professionals have warned about the dangers of purchasing low-cost streaming boxes marketed as gateways to unlimited content for a single payment. The primary concern centered on these gadgets quietly monetizing users' internet connections by leasing access to third parties. A fresh investigation now reveals an additional threat: these same devices impersonate smartphones to generate fraudulent clicks on artificially created websites as part of an elaborate scheme targeting merchants and ad networks.

Pedro Falé, a researcher at Bitsight, gained visibility into this ad fraud operation after acquiring an expired domain previously associated with H96 streaming devices, a particularly widespread brand in this category. The domain had served as a command center for coordinating fraudulent ad interactions across thousands of these boxes globally. Upon analyzing the traffic, Falé discovered something unexpected: nearly all devices were misrepresenting themselves as smartphones from manufacturers including Samsung, Vivo, Huawei, and Xiaomi.

We noticed something was wildly wrong. Multiple devices reporting to this factory Android TV Box backdoor were 'phones.'

Pedro Falé, Bitsight

Image: Bitsight.

Investigation revealed that all devices reported identical app installations created by Zhejiang Fengwo IoT Technology Ltd, a company established in 2019 in mainland China. This entity operates an advertising network under the Fengwo Group brand. The company has filed multiple patents corresponding to the functionality embedded in these applications.

Falé documented that the apps orchestrate an ad fraud network leveraging H96 devices as a captive audience to generate clicks on websites hosting machine-generated content. Bitsight identified that these sites feature algorithmically produced articles and imagery spanning finance, health, education, gaming, music, and food categories. A critical finding: advertisements only display when visitors match the spoofed mobile device profiles of the H96 boxes.

AI Digital Humans

The Fengwo Group's primary domain, fwgcloud[.]com, describes the organization as "redefining the boundaries of human-AI interaction" and claims to have developed over 120,000 "AI digital humans" available for rental purposes ranging from emotional support to round-the-clock customer service and creative work.

The homepage for fwgcloud dot com.

Falé identified that the Fengwo Group's domain shared SSL certificate information with other domains hosting the H96 apps, particularly those managing the phone spoofing functionality. The domain also maintained an internal wiki connecting the Fengwo Group to a customized version of Blockly, Google's visual programming framework originally created to teach software development to children.

Bitsight determined that Fengwo Group staff utilize Blockly to construct fraudulent websites, enabling operators with minimal technical expertise to assemble code segments without comprehending their underlying mechanics. The report noted that "An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type. Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn't need as much understanding of the underlying technicalities, as it is all set in place for ease of use."

The Blockly homepage.

Bitsight even uncovered remarks from a Fengwo Group developer highlighting these operational efficiencies, noting that "only a small number of highly-skilled developers are needed to build the template execution-unit images," and that "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company's operating costs."

When an H96 device receives assignment for a fraud operation, it downloads the corresponding Blockly module enabling tasks such as launching browsers silently, navigating websites, managing browser tabs, and clicking advertisements. To ensure the spoofed phones reliably interact with ads on AI-generated sites, Fengwo "fuses three vision and reasoning systems into a single interface," permitting the bots to locate advertisements and browse similarly to human users.

TV On? Proxy. TV Off? Ad Fraud

Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight.

Bitsight's analysis revealed that H96 devices operate in one of two modes but never simultaneously: they either relay residential proxy traffic or execute ad fraud operations. The distinction correlates with television status—when an HDMI signal indicates an active display, the device typically functions as a residential proxy. Once the television powers down, it transitions to awaiting ad fraud assignments.

Falé suggested this design reflects the resource demands of ad fraud operations, which could degrade the device's primary streaming capability if running concurrently.

Image: fbi.gov.

Despite sustained warnings from federal law enforcement and security experts regarding these devices' risks, major retailers including Amazon, Best Buy, and Newegg continue stocking hundreds of variants bundling unofficial Android builds, frequently promoted through online personalities as affordable alternatives to subscription streaming services.

Beyond their participation in ad fraud schemes, these budget streaming devices universally arrive with residential proxy software pre-installed, which monetizes users' internet addresses by renting them to paying clients ranging from data harvesting operations to ticket resellers and criminal enterprises. The devices' inherent security deficiencies and absence of authentication mechanisms compound risks when connected to home or office networks. In January, proxy monitoring service Synthient documented how multiple botnets had rapidly compromised millions of these boxes by exploiting vulnerabilities in both the proxy software and the devices themselves.

Show Me the Money

Bitsight tracked approximately 38,000 TV boxes globally communicating with the expired Fengwo Group domain. Based on this figure, the report estimates the ad fraud network generates roughly $50,000 daily in revenue, excluding substantial income from residential proxy operations. Falé cautioned these projections represent conservative estimates derived from telemetry from only one of Fengwo's established (though aging) domains.

Regarding Fengwo's assertion of possessing 120,000 "digital humans," Bitsight concludes this may constitute marketing hyperbole or a strategy to obscure the company's actual operations. "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size," Falé wrote. "This could also be the case here."

If Fengwo genuinely commands tens of thousands of "AI humans," none appear assigned to customer communications. KrebsOnSecurity's inquiry to the contact address on Fengwo's website returned an undeliverable message: "Your message couldn't be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it's getting too much mail right now."

Bitsight recommends consumers purchase streaming devices exclusively from established manufacturers and exercise restraint when installing applications, as many bundle residential proxy functionality. Google provides instructions for verifying whether a device runs official Android TV OS with Play Protect certification. Additionally, Synthient maintains a database of IoT devices known to ship with residential proxy software and malicious applications pre-loaded, encompassing not only streaming hardware but also items like digital photo frames, which the FBI has similarly flagged as vectors for proxy software distribution.

Source: Krebs on Security