Cheap Android TV streaming boxes are being quietly conscripted into a botnet that masquerades as premium smartphones to defraud advertisers and resell home broadband as residential proxy bandwidth, according to researchers tracking a campaign they call Fuyao.[1][2][3] Security firm Bitsight has linked the operation to mainland China–based Zhejiang Fengwo IoT Technology Co., Ltd., also known as Fengwo Group, which appears to sit at the center of a sprawling ad-fraud and proxy business built on compromised consumer hardware.[1][4][5]
Bitsight’s TRACE team reports that Fuyao’s code is shipped preinstalled on off-brand Android TV boxes, including H96-branded devices, where it modifies system properties so the hardware reports itself as popular phone models from Samsung, Huawei, Xiaomi, and Vivo instead of a low-cost streaming box.[1][3][4] Once active, the malware-driven apps browse attacker-controlled, AI-generated websites packed with advertising slots that only serve content to what appear to be mobile devices, then repeatedly trigger ad views and clicks while presenting the spoofed phone identities to escape basic anti-bot defenses.[1][2][4] The same codebase supports a second operational mode: when the TV box detects an HDMI connection, it tends to shift into residential SOCKS5 proxy service, forwarding strangers’ internet traffic through the owner’s home network; when the HDMI signal disappears, it returns to ad-fraud tasks.[2][3][9]
Portuguese researcher Pedro Falé gained deeper visibility into Fuyao by registering an expired telemetry domain used by the infected boxes, revealing tens of thousands of devices that phoned home with identical app and configuration fingerprints linked to Fengwo Group.[4][5] In one segment of the infrastructure, Bitsight observed roughly 38,000 boxes contacting a single Fengwo-controlled domain and estimated that the ad-fraud component alone could generate close to $50,000 in daily revenue, excluding what the operators earn by reselling proxy access to third parties.[4] Bitsight describes the broader Fuyao enterprise as a modular Android TV botnet that marries more than 120,000 AI-generated “digital humans” with campaigns scripted in the Blockly children’s coding environment, and notes that monetization is funneled through shell companies registered in Hong Kong and Singapore.[1][4][6]
The Fuyao revelations land in an ecosystem already riddled with insecure and sometimes outright malicious Android TV boxes. In 2023, the Electronic Frontier Foundation highlighted streaming devices built on AllWinner and RockChip chipsets that shipped with BianLian-family malware out of the box, quietly enrolling buyers into a general-purpose attack botnet.[7] Separate research has documented serious vulnerabilities in other third-party TV boxes, including CVE-2020-27402, which allows local privilege escalation to root on HK1 Box S905X3 hardware via an exposed /system/xbin/su binary accessible over UART or Android Debug Bridge according to the National Vulnerability Database and GitHub’s advisory record.[13][15] More recently, CVE-2026-58378 was assigned to Allwinner H616 TV Box TV98, where Android Debug Bridge is enabled and reachable over the network in production, giving an attacker who secures authorization the ability to gain full root control of the device as detailed in vendor-agnostic advisories and vulnerability databases.[12][14] These issues affect different products than the H96 boxes tied to Fuyao, and there is no public evidence that Fuyao exploits them directly, but together they underscore pervasive supply-chain and configuration weaknesses across low-cost streaming hardware.[7][12][13][14]
Researchers and law enforcement have been warning for years that generic Android TV boxes marketed on promises of “free” or pirated content can effectively become unmonitored computers on home and small-business networks, a concern echoed in a 2025 advisory from the FBI urging owners to scrutinize unknown streaming devices, keep firmware current, and disconnect suspicious hardware.[3] In its Fuyao reporting, Bitsight advises enterprises to treat inexpensive, unbranded Android TV devices as untrusted endpoints, isolate them on separate network segments with strict egress controls, and consider removing them entirely when they are not business-critical.[1][2][4] Home users are similarly urged to review router logs and endpoint telemetry for unusual outbound connections, disable ADB and remote management features when possible, apply vendor firmware updates where they exist, and favor mainstream streaming platforms with documented security update processes over unvetted imports.[7][12][14] At present there is no public CVE identifier or vendor advisory specific to the preinstalled Fuyao apps, leaving remediation largely in the hands of buyers and network defenders who must decide whether to quarantine or retire affected devices.[1][2][4]
References
- Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud
- Criminals used AI and children’s coding software to build a …
- Cheap Android TV Boxes Pose as Phones and Turn …
- Off-Brand H96 Android TV Boxes Tied to Ad Fraud and …
- Michele Chubirka’s Post
- Building an Ad-Fraud Empire with AI and Kids’ Coding Blocks
- Android TV Boxes Sold on Amazon Come Pre-Loaded with Malware
- ⚠️ Cheap Android TV boxes are posing as Samsung …
- CVE-2026-58378 | Tenable®
- NVD
- ADB Remote Root Access in Allwinner H616 TV Box TV98
- CVE-2020-27402 – GitHub Advisory Database
