Generic TV Streaming Boxes Weaponised for Ad Fraud and Botnet Proxy Services
Bitsight researcher Pedro Falé linked H96 streaming boxes to Fengwo Group infrastructure that alternated between residential proxying and ad fraud. Bitsight observed approximately 38,000 devices and estimated ad-fraud revenue near $50,000 per day.
Affected
Bitsight threat researcher Pedro Falé analysed infrastructure associated with H96-branded streaming boxes after registering an expired command domain. The devices reported spoofed mobile identities and contained two applications attributed to Zhejiang Fengwo IoT Technology, which operates as Fengwo Group.
The boxes operated in two mutually exclusive modes rather than running both schemes simultaneously. Bitsight found that a device detecting an active HDMI signal generally relayed residential proxy traffic; when the television was off, it waited for ad-fraud tasks. Falé assessed that this separation prevented the more resource-intensive ad fraud from disrupting video streaming.
For ad fraud, the devices masqueraded as mobile phones and visited AI-generated Fengwo Group sites whose advertisements appeared only to matching spoofed profiles. Remotely supplied routines could launch a browser, navigate pages and click advertisements.
Bitsight observed approximately 38,000 boxes contacting the expired domain globally. Based on that telemetry, it estimated the ad-fraud operation generated close to $50,000 per day, excluding proxy revenue; Falé described the estimate as conservative because it covered only one older core domain.
Users should avoid uncertified generic Android streaming devices and isolate consumer IoT equipment from sensitive systems. Network defenders and advertising platforms should account for devices that change behaviour according to whether they are actively being used.
Sources