NEWS

Read This Before You Buy That TV Streaming Stick

Bitsight researcher Pedro Fale traced 38,000+ H96 Android TV boxes secretly running ad fraud and residential-proxy malware for China's Fengwo Group.

Dylan H.

News Desk

September 28, 2026
7 min read
Read This Before You Buy That TV Streaming Stick

38,000 Streaming Sticks, One Ad Fraud Empire

Cheap, no-name TV streaming sticks and Android TV boxes sold on major online marketplaces have long been suspected of secretly renting out buyers' internet connections. A new analysis from Bitsight researcher Pedro Fale, reported by KrebsOnSecurity on July 30, 2026, shows the problem is worse than a simple bandwidth-sharing scheme: popular H96-brand streaming boxes are running a dual-purpose fraud operation that spoofs mobile phone identities, clicks on fake ads around the clock, and doubles as a residential proxy node — all without the owner's knowledge. Fale stumbled onto the scheme after registering an expired domain that had previously served as telemetry infrastructure for the devices, and found it was still receiving check-ins from roughly 38,000 boxes worldwide, tied to a Chinese firm estimated to be pulling in $50,000 per day from the fraud alone.


Incident Details

AttributeValue
ResearcherPedro Fale, Bitsight
Primary deviceH96-brand Android TV streaming boxes (generic/white-label TV boxes broadly implicated)
Threat actorZhejiang Fengwo IoT Technology Ltd, doing business as the "Fengwo Group"
Devices observed~38,000 checking in to a single reclaimed telemetry domain
Estimated revenue~$50,000/day from ad-fraud clicks alone (conservative, single-domain estimate)
Primary infrastructurefwgcloud[.]com
Core techniqueDevice/identity spoofing, Blockly-based ad-click automation, residential proxy rental
DistributionSold under generic/white-label branding on major online retailers
PublishedJuly 30, 2026, KrebsOnSecurity

How the Devices Misbehave

The Discovery

Fale registered a lapsed domain that had previously coordinated fake ad clicks across the H96 line of streaming boxes. Because the domain had once been part of the devices' legitimate check-in infrastructure, Fale began passively receiving telemetry from tens of thousands of boxes still configured to reach it — full hardware fingerprints, installed app lists, and command traffic — giving an unusually clear window into an active fraud network without needing to reverse-engineer the malware from scratch.

Spoofing Phones, Not TVs

Nearly all of the traffic reaching Fale's domain identified itself as a mobile handset rather than a streaming box — claiming to be Samsung, Vivo, Huawei, and Xiaomi phone models. This spoofing is deliberate: ad networks pay more, and scrutinize traffic less, when it appears to originate from real mobile devices rather than obscure set-top boxes, so the fraud software fabricates a phone identity to blend in with legitimate mobile ad traffic.

A Dual-Purpose Fraud Scheme

The devices switch roles based on how the TV is being used. While the television is powered on and the owner is streaming content, the box quietly operates as a residential proxy — reselling the owner's home IP address to third parties who want traffic that looks like it's coming from an ordinary residential internet connection. When the TV is off and idle, the same hardware pivots to running automated ad-click fraud in the background, hitting AI-generated ad-stuffed websites to generate fraudulent revenue.

Low-Skill Fraud at Industrial Scale

To scale the operation, the Fengwo Group reportedly built its ad-fraud tooling on a modified version of Google's Blockly visual programming language — the same drag-and-drop framework used to teach children to code. This let operators with little to no technical background assemble and deploy new ad-click campaigns without writing traditional malware, dramatically lowering the barrier to running fraud infrastructure at scale. The company has separately claimed to have some 120,000 "AI digital humans" available for rent, though it did not respond to KrebsOnSecurity's request for comment — an email to its listed contact address bounced.


Impact Assessment

Impact AreaDescription
Consumer bandwidth and privacyHome internet connections are silently resold as residential proxies, and device telemetry (hardware IDs, installed apps) is exfiltrated without consent
Household legal exposureTraffic routed through the residential proxy can include scraping, credential stuffing, or other abusive activity that appears to originate from the device owner's IP
Ad industry lossesEstimated ~$50,000/day in fraudulent ad revenue from a single tracked domain, suggesting the full network's losses to advertisers are considerably larger
Retail supply chain trustDevices are sold as ordinary consumer electronics on mainstream marketplaces with no indication of embedded fraud software
Network security postureAn always-on device conscripted into a proxy/fraud botnet undermines IP-reputation-based defenses for every network it sits on
Attribution and enforcementChinese-registered manufacturer (Zhejiang Fengwo IoT Technology Ltd) sits outside easy reach of Western regulators or consumer protection action

Recommendations

For Consumers

  • Stick to name-brand devices from established manufacturers (Roku, Google/Chromecast, Amazon Fire TV, Apple TV) rather than generic H96-style boxes sold under unfamiliar or white-label brands.
  • Before buying an Android-based box, verify it carries official Android TV OS and Play Protect certification using Google's device-verification instructions — uncertified boxes are far more likely to ship with bundled fraud or proxy software.
  • Be sparing with third-party apps installed on any streaming device; unofficial APKs and sideloaded apps are a common vector for bundled proxy SDKs.
  • Periodically check your router's connected-device list and outbound traffic for a streaming box that is unusually active while the television is off.
  • Consult Synthient's public list of known-compromised IoT/streaming devices before purchasing a low-cost box.

For IT Admins and Security Teams

  • Treat consumer streaming devices on any network (including guest and BYOD networks) as untrusted IoT endpoints; place them on a segmented VLAN with restricted, allow-listed outbound access.
  • Monitor for outbound connections to known ad-fraud and residential-proxy C2 infrastructure, including domains associated with fwgcloud[.]com and similar Fengwo Group infrastructure.
  • Flag devices that generate outbound traffic patterns inconsistent with normal streaming behavior — steady background connections while the display is reported off is a strong indicator.
  • Include no-name streaming and TV-box hardware in procurement and acceptable-use policies for any environment (offices, hospitality, healthcare waiting rooms) where such devices might be deployed.
  • Feed known Fengwo/H96 telemetry domains into DNS filtering (Pi-hole, AdGuard Home, enterprise DNS security) to block check-ins even if a device is already compromised.

Key Takeaways

  1. Bitsight researcher Pedro Fale used a reclaimed, previously-legitimate telemetry domain to passively observe roughly 38,000 H96-brand Android TV boxes actively checking in to fraud infrastructure.
  2. The devices run a dual-purpose scheme: residential proxy resale while the TV is in use, and automated ad-click fraud while it's idle.
  3. Traffic is deliberately spoofed to appear as Samsung, Vivo, Huawei, and Xiaomi phone models, helping it evade ad-network fraud detection built around mobile traffic.
  4. The operation is linked to Zhejiang Fengwo IoT Technology Ltd ("Fengwo Group"), estimated to be generating ~$50,000/day in fraudulent ad revenue from a single tracked domain alone.
  5. Low-code tooling built on Google's Blockly framework let relatively unskilled operators build and run ad-fraud campaigns at scale, without traditional malware development skills.
  6. Consumers should avoid unbranded streaming sticks and TV boxes, verify Android TV OS/Play Protect certification, and treat any such device already in use as an untrusted network endpoint worth isolating and monitoring.

Sources