38,000 Streaming Sticks, One Ad Fraud Empire
Cheap, no-name TV streaming sticks and Android TV boxes sold on major online marketplaces have long been suspected of secretly renting out buyers' internet connections. A new analysis from Bitsight researcher Pedro Fale, reported by KrebsOnSecurity on July 30, 2026, shows the problem is worse than a simple bandwidth-sharing scheme: popular H96-brand streaming boxes are running a dual-purpose fraud operation that spoofs mobile phone identities, clicks on fake ads around the clock, and doubles as a residential proxy node — all without the owner's knowledge. Fale stumbled onto the scheme after registering an expired domain that had previously served as telemetry infrastructure for the devices, and found it was still receiving check-ins from roughly 38,000 boxes worldwide, tied to a Chinese firm estimated to be pulling in $50,000 per day from the fraud alone.
Incident Details
| Attribute | Value |
|---|---|
| Researcher | Pedro Fale, Bitsight |
| Primary device | H96-brand Android TV streaming boxes (generic/white-label TV boxes broadly implicated) |
| Threat actor | Zhejiang Fengwo IoT Technology Ltd, doing business as the "Fengwo Group" |
| Devices observed | ~38,000 checking in to a single reclaimed telemetry domain |
| Estimated revenue | ~$50,000/day from ad-fraud clicks alone (conservative, single-domain estimate) |
| Primary infrastructure | fwgcloud[.]com |
| Core technique | Device/identity spoofing, Blockly-based ad-click automation, residential proxy rental |
| Distribution | Sold under generic/white-label branding on major online retailers |
| Published | July 30, 2026, KrebsOnSecurity |
How the Devices Misbehave
The Discovery
Fale registered a lapsed domain that had previously coordinated fake ad clicks across the H96 line of streaming boxes. Because the domain had once been part of the devices' legitimate check-in infrastructure, Fale began passively receiving telemetry from tens of thousands of boxes still configured to reach it — full hardware fingerprints, installed app lists, and command traffic — giving an unusually clear window into an active fraud network without needing to reverse-engineer the malware from scratch.
Spoofing Phones, Not TVs
Nearly all of the traffic reaching Fale's domain identified itself as a mobile handset rather than a streaming box — claiming to be Samsung, Vivo, Huawei, and Xiaomi phone models. This spoofing is deliberate: ad networks pay more, and scrutinize traffic less, when it appears to originate from real mobile devices rather than obscure set-top boxes, so the fraud software fabricates a phone identity to blend in with legitimate mobile ad traffic.
A Dual-Purpose Fraud Scheme
The devices switch roles based on how the TV is being used. While the television is powered on and the owner is streaming content, the box quietly operates as a residential proxy — reselling the owner's home IP address to third parties who want traffic that looks like it's coming from an ordinary residential internet connection. When the TV is off and idle, the same hardware pivots to running automated ad-click fraud in the background, hitting AI-generated ad-stuffed websites to generate fraudulent revenue.
Low-Skill Fraud at Industrial Scale
To scale the operation, the Fengwo Group reportedly built its ad-fraud tooling on a modified version of Google's Blockly visual programming language — the same drag-and-drop framework used to teach children to code. This let operators with little to no technical background assemble and deploy new ad-click campaigns without writing traditional malware, dramatically lowering the barrier to running fraud infrastructure at scale. The company has separately claimed to have some 120,000 "AI digital humans" available for rent, though it did not respond to KrebsOnSecurity's request for comment — an email to its listed contact address bounced.
Impact Assessment
| Impact Area | Description |
|---|---|
| Consumer bandwidth and privacy | Home internet connections are silently resold as residential proxies, and device telemetry (hardware IDs, installed apps) is exfiltrated without consent |
| Household legal exposure | Traffic routed through the residential proxy can include scraping, credential stuffing, or other abusive activity that appears to originate from the device owner's IP |
| Ad industry losses | Estimated ~$50,000/day in fraudulent ad revenue from a single tracked domain, suggesting the full network's losses to advertisers are considerably larger |
| Retail supply chain trust | Devices are sold as ordinary consumer electronics on mainstream marketplaces with no indication of embedded fraud software |
| Network security posture | An always-on device conscripted into a proxy/fraud botnet undermines IP-reputation-based defenses for every network it sits on |
| Attribution and enforcement | Chinese-registered manufacturer (Zhejiang Fengwo IoT Technology Ltd) sits outside easy reach of Western regulators or consumer protection action |
Recommendations
For Consumers
- Stick to name-brand devices from established manufacturers (Roku, Google/Chromecast, Amazon Fire TV, Apple TV) rather than generic H96-style boxes sold under unfamiliar or white-label brands.
- Before buying an Android-based box, verify it carries official Android TV OS and Play Protect certification using Google's device-verification instructions — uncertified boxes are far more likely to ship with bundled fraud or proxy software.
- Be sparing with third-party apps installed on any streaming device; unofficial APKs and sideloaded apps are a common vector for bundled proxy SDKs.
- Periodically check your router's connected-device list and outbound traffic for a streaming box that is unusually active while the television is off.
- Consult Synthient's public list of known-compromised IoT/streaming devices before purchasing a low-cost box.
For IT Admins and Security Teams
- Treat consumer streaming devices on any network (including guest and BYOD networks) as untrusted IoT endpoints; place them on a segmented VLAN with restricted, allow-listed outbound access.
- Monitor for outbound connections to known ad-fraud and residential-proxy C2 infrastructure, including domains associated with
fwgcloud[.]comand similar Fengwo Group infrastructure. - Flag devices that generate outbound traffic patterns inconsistent with normal streaming behavior — steady background connections while the display is reported off is a strong indicator.
- Include no-name streaming and TV-box hardware in procurement and acceptable-use policies for any environment (offices, hospitality, healthcare waiting rooms) where such devices might be deployed.
- Feed known Fengwo/H96 telemetry domains into DNS filtering (Pi-hole, AdGuard Home, enterprise DNS security) to block check-ins even if a device is already compromised.
Key Takeaways
- Bitsight researcher Pedro Fale used a reclaimed, previously-legitimate telemetry domain to passively observe roughly 38,000 H96-brand Android TV boxes actively checking in to fraud infrastructure.
- The devices run a dual-purpose scheme: residential proxy resale while the TV is in use, and automated ad-click fraud while it's idle.
- Traffic is deliberately spoofed to appear as Samsung, Vivo, Huawei, and Xiaomi phone models, helping it evade ad-network fraud detection built around mobile traffic.
- The operation is linked to Zhejiang Fengwo IoT Technology Ltd ("Fengwo Group"), estimated to be generating ~$50,000/day in fraudulent ad revenue from a single tracked domain alone.
- Low-code tooling built on Google's Blockly framework let relatively unskilled operators build and run ad-fraud campaigns at scale, without traditional malware development skills.
- Consumers should avoid unbranded streaming sticks and TV boxes, verify Android TV OS/Play Protect certification, and treat any such device already in use as an untrusted network endpoint worth isolating and monitoring.