H96 TV Boxes Tied to Massive AI-Driven Ad Fraud Scheme

Thousands of inexpensive H96-branded Android TV streaming boxes sold through major online marketplaces are being quietly conscripted into a dual-purpose botnet that fuels AI-driven advertising fraud and covert residential proxy services, according to new research from Bitsight and reporting by KrebsOnSecurity[1][2][15].

Pedro Falé, a threat researcher at Bitsight, gained an inside view of the operation after registering an expired domain previously used as a telemetry hub for one popular H96 model, allowing him to observe tens of thousands of devices phoning home from living rooms around the world[1][2]. The data showed the boxes falsely identifying themselves as a wide range of Android phones from manufacturers including Samsung, Vivo, Huawei and Xiaomi, a tactic designed to make fraudulent ad traffic appear as legitimate mobile visits[1][2]. Falé found that affected devices consistently shipped with two preinstalled applications linked to Zhejiang Fengwo IoT Technology Co., Ltd., part of the Fengwo Group, whose patent filings and infrastructure closely match the behavior of the ad-fraud toolkit uncovered in the field[1][2][15].

Bitsight’s report, which refers to the underlying botnet infrastructure as the “Fuyao Enterprise,” describes how the Fengwo Group uses a visual programming environment based on Google’s Blockly to let low-skilled operators assemble fraud routines by dragging and dropping code blocks, which are then exported as JavaScript and delivered to compromised boxes as task modules[2][15]. Once a module is pushed to a selected H96 device, it can silently launch a browser, navigate through AI-generated websites, manage tabs and click on ads, guided by computer vision models that identify ad placements and mimic human interaction patterns[1][2][15]. The group publicly markets more than 120,000 “AI digital humans” for rent under the fwgcloud domain, but investigators say that behind the scenes those same systems help orchestrate large-scale ad-fraud workflows backed by the captive traffic generated from hijacked TV boxes[1][2][15].

Researchers observed a deliberate split between how the devices are monetized depending on whether the attached television is in use: when an HDMI signal indicates the TV is on, the box primarily acts as a residential proxy relay, selling the user’s IP address to third parties for activities ranging from aggressive web scraping to credential-stuffing and other cybercrime; when the TV is off, the device switches to waiting for new ad-fraud jobs[1][2]. Bitsight tracked roughly 38,000 TV boxes communicating with the reclaimed Fengwo domain and estimated that the ad-fraud component alone could be generating close to $50,000 per day, not including what the operators earn from proxy traffic; the firm stressed that these figures are conservative and likely represent only a slice of the broader ecosystem of compromised Android-based streaming hardware[1][2][9]. Prior work by Human Security and others has shown that similar low-cost Android devices—including TV boxes, tablets and car infotainment systems—have been mass-produced with hidden backdoors, creating botnets used for ad fraud and residential proxy services on a global scale[9].

The Fuyao operation also fits into a wider pattern that has attracted law-enforcement attention, including an FBI warning about a massive cybercrime scheme dubbed “BADBOX 2.0” that quietly conscripted millions of smart devices—especially cheap third-party Android TV boxes—into residential proxy and ad-fraud networks[7][9]. Those alerts singled out no-name streaming products that encourage users to disable Google Play Protect, promise free access to paid channels or ship with unofficial Android builds, noting that families such as TV98 and X96 have been heavily abused as part of large-scale scam infrastructure[7][9]. Security firms have separately documented malware-laced Android TV boxes, including H96 variants, being used for distributed denial-of-service attacks and clickbots, reinforcing concerns that entire product lines are effectively prewired for criminal monetization before they reach consumers[3][9].

Defenders and consumers have limited visibility into what these opaque streaming devices are doing once plugged into home networks, but investigators and government agencies offer concrete steps to reduce exposure[1][7][8]. They advise avoiding generic Android TV boxes from unfamiliar brands—especially those marketed as “unlocked” or offering lifetime access to premium content—and instead choosing certified devices from well-known vendors that retain Google Play Protect and receive regular firmware updates[7][8]. Users are urged to place streaming hardware and other smart home gadgets on a separate guest or IoT Wi‑Fi network, monitor routers for unexplained outbound traffic, and promptly disconnect any device that shows sustained high-bandwidth activity when idle or triggers abuse complaints from their internet provider[1][8]. If a streaming box appears suspicious, experts recommend removing it from the network entirely and reporting potential compromise through channels such as the FBI’s Internet Crime Complaint Center, both to protect household systems and to help investigators map the expanding web of Android TV box-based fraud operations[7][8].

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply