Threats

TV Streaming Sticks Expose Users to Ad Fraud

August 3, 2026 00:19 · 12 min read
TV Streaming Sticks Expose Users to Ad Fraud

Ad Fraud Network Exposed

Security experts have been warning about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee. A new analysis by Bitsight, a security firm, has found that these devices also spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation to defraud online merchants and advertising networks.

Pedro Falé, a threat researcher with Bitsight, was able to peer inside the ad fraud network by registering an expired domain name used to coordinate fake ad clicks across a popular brand of streaming devices known as H96. The domain was previously used for telemetry, collecting hardware information and installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe.

Spoofing Mobile Phones

Upon inspecting the traffic being funneled to the domain, Falé discovered that nearly all of the TV boxes transmitting data claimed to be mobile phone models from various manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. The researcher found that all of the devices reported having the same two apps installed, made by Zhejiang Fengwo IoT Technology Ltd, a company founded in 2019 in mainland China.

The apps help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group. The websites contain machine-generated news articles and graphics across various categories, but they only display ads when the device visiting the page matches the spoofed mobile profile of these H96 devices.

Fengwo Group's Operations

The Fengwo Group's domain, fwgcloud[.]com, claims the company is redefining the boundaries of human-AI interaction and has created over 120,000 AI digital humans available to rent for various purposes. However, Falé believes this could be a clever marketing scheme to avoid drawing suspicion to the company's operations.

The Fengwo Group's employees use a proprietary implementation of the Google-built visual programming language Blockly to build the sham websites. This allows low-skilled operators to drag blocks of code together in their Blockly editor without needing to understand the underlying code blocks.

Ad Fraud Revenue

Bitsight estimates that this ad fraud network brings in revenues of close to $50,000 daily, based on telemetry from just one of the Fengwo Group's core domains. However, Falé emphasizes that these estimates are highly conservative.

The H96 devices are either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. When the TV is off, the device switches back to waiting for ad fraud jobs, as its ad fraud activities are more resource-intensive and could interfere with the device's stated purpose of streaming video content.

Security Risks

Despite repeated warnings from the FBI and security industry leaders, major e-commerce providers like Amazon, Best Buy, and Newegg continue to sell hundreds of different models and brands of streaming devices that bundle unofficial versions of Google's Android operating system. These devices are frequently marketed as a way to access a broad array of streaming services and live broadcasts without a subscription.

These off-brand streaming devices almost universally come with residential proxy software pre-installed, which rents the user's internet address out to anonymous paying customers. This software can be used by aggressive content scraping firms, ticket scalpers, and outright cybercriminals.

Installing one of these devices on a home or office network only invites further mischief, as they are horribly insecure by default and bereft of any kind of authentication. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.

To avoid these risks, it's best to stick to name brands from reputable manufacturers and be sparing and careful with any apps installed on the device. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following specific instructions.


Source: Krebs on Security

Source: Krebs on Security

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free