For years, security researchers have issued a persistent, urgent warning: those inexpensive, "all-in-one" streaming boxes promising free access to premium content are rarely the bargain they appear to be. While consumers have been cautioned about the risk of these devices turning their home internet into a pipeline for illicit traffic, a groundbreaking new analysis has revealed a more sinister reality. These devices are not just passive conduits; they are active participants in a sophisticated, automated scheme to defraud online merchants and advertising networks on a massive scale.
A comprehensive investigation by the security firm Bitsight has uncovered that millions of generic TV streaming boxes—most notably the popular H96 brand—are routinely spoofing themselves as mobile phones. This deception allows them to simulate human behavior, clicking on ads across a sprawling network of AI-generated websites, siphoning millions of dollars from the digital advertising ecosystem.
The Discovery: Peering Into the Machine
The investigation began with a piece of digital detective work. Pedro Falé, a lead threat researcher at Bitsight, identified a dormant, expired domain that had previously been used for device telemetry—the process by which these boxes "phone home" to report their status. By registering the expired domain, Falé gained a front-row seat to the internal mechanics of a global botnet.
What he found was striking. Tens of thousands of H96 streaming sticks were transmitting detailed hardware information, yet nearly all of them claimed to be mobile phones manufactured by industry giants like Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falé told KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were claiming to be phones."

This wasn’t a glitch; it was a deliberate design choice. By mimicking high-end mobile devices, the boxes could bypass security filters that prioritize mobile traffic, tricking advertising networks into paying for clicks that were never made by a human hand.
Chronology of a Digital Heist
The operation is as calculated as it is vast. The investigation traced the infrastructure back to a mainland China-based entity known as Zhejiang Fengwo IoT Technology Co., Ltd., operating under the umbrella of the "Fengwo Group." Founded in 2019, the company has built a complex, multi-layered ecosystem designed to monetize these hijacked devices.
1. The Pre-Infection Phase
These TV boxes arrive at the consumer’s doorstep "pre-infected." They are shipped with malicious software already integrated into the device’s firmware. Upon being plugged into a home network, the devices immediately establish a connection to command-and-control servers, waiting for instructions.
2. The Duality of Function
Bitsight’s analysis revealed a "switch" mechanism within the devices. When a user turns on their television and provides an HDMI signal, the box shifts into "proxy mode," effectively renting out the user’s internet bandwidth to third-party buyers—often for the purpose of scraping data or facilitating cyberattacks. However, when the TV is powered off, the device shifts into "ad fraud mode," utilizing the idle processing power to interact with the web.

3. The Execution of Fraud
When in ad-fraud mode, the devices execute scripts designed to visit websites operated by the Fengwo Group. These sites, filled with machine-generated news, health advice, and lifestyle blogs, are essentially "hollow" shells. They do not display ads to real users; they only serve them to the spoofed mobile profiles of the infected TV boxes.
Supporting Data: The Scale of the Operation
The financial scale of this operation is staggering. Based on telemetry from just one of the Fengwo Group’s older domains, Bitsight tracked approximately 38,000 active devices. Conservatively, the firm estimates this specific segment of the network generates roughly $50,000 in fraudulent revenue per day. When extrapolated to the total number of devices circulating globally, the annual haul for such an operation likely reaches into the tens of millions of dollars.
To manage this, the Fengwo Group utilizes "Blockly," a visual programming language originally developed by Google to teach children how to code. By using a drag-and-drop interface, the group’s operators—who need not be expert programmers—can construct complex ad-fraud routines. These routines are exported as JavaScript and deployed to cloud-based servers, where they are pushed to the captive H96 devices to perform tasks such as launching browsers, navigating web pages, and clicking on ads.
To avoid detection by fraud-prevention software, the Fengwo Group has implemented a "vision and reasoning system." This interface allows the bots to "see" the page, identify legitimate ad placements, and navigate the interface with human-like randomness, making the fraudulent clicks nearly indistinguishable from genuine user behavior.

The Myth of the "Digital Human"
The Fengwo Group’s public-facing website, fwgcloud[.]com, boasts that the company is "redefining the boundaries of human-AI interaction." It claims to offer over 120,000 "AI digital humans" for services ranging from customer support to emotional companionship.
However, Bitsight suggests this is likely a facade. "Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size," Falé explained. By masquerading as a legitimate AI services firm, the Fengwo Group hides its true nature as a botnet operator in plain sight.
Official Responses and Industry Accountability
Despite repeated warnings from the FBI and cybersecurity experts, the supply chain for these devices remains largely unchecked. Major e-commerce platforms—including Amazon, Best Buy, and Newegg—continue to host listings for hundreds of off-brand streaming boxes. Many of these products are marketed by online influencers, who often fail to disclose the inherent security risks of the hardware.
When KrebsOnSecurity attempted to reach the Fengwo Group for comment via the contact information on their website, the request was met with a automated bounce-back notice, indicating the inbox was either full or overwhelmed by traffic—a fittingly impersonal end for a company built on automated deceit.

Implications for the Consumer and the Internet
The implications of this report are far-reaching. First, the presence of these devices on a home or office network creates a significant security vulnerability. Because these boxes are often built with poor authentication and unpatchable firmware, they serve as a beachhead for malicious actors to gain access to the rest of the local network.
Second, the "residential proxy" software pre-installed on these devices is a major privacy concern. When a user’s IP address is rented out to strangers, the owner of that internet connection may be held liable for the traffic originating from their network, which can include everything from illegal file sharing to sophisticated cyberattacks.
Protecting Your Network
For consumers, the advice from cybersecurity experts is clear:
- Stick to Reputable Brands: Avoid "no-name" streaming boxes. Opt for devices from established manufacturers like Apple, Roku, Google, or Amazon (Fire TV), which are subject to regular security updates and rigorous oversight.
- Verify Android Certification: Google provides a list of certified Android TV devices. If a box is not on the list, it is likely running an unauthorized, insecure version of the OS.
- Audit Your IoT Devices: Use resources like the list maintained by the security firm Synthient, which tracks IoT devices known to ship with malicious proxy software.
- Network Segmentation: If you must use a questionable IoT device, isolate it on a "guest" network to prevent it from communicating with sensitive devices like your personal computer, smartphone, or banking applications.
The Fengwo Group scandal serves as a stark reminder that in the digital age, hardware is never just hardware. When a product is priced "too good to be true," the cost is almost always paid in the form of your privacy, your bandwidth, and your security. As the internet continues to evolve, the ability to discern legitimate technology from a "Trojan horse" will be the most essential skill for the modern consumer.








