« All posts

Cheap H96 TV Streaming Boxes Caught Spoofing Phones for Ad Fraud

Bitsight found cheap H96 TV streaming boxes spoofing as phones to run large-scale ad fraud and residential proxy schemes tied to China's Fengwo Group.

Bitsight researcher Pedro Falé uncovered a sprawling ad fraud operation by registering an expired domain once used to coordinate telemetry from tens of thousands of H96-branded Android TV streaming sticks. The captured traffic revealed nearly all devices were falsely identifying themselves as mobile phones from brands like Samsung, Vivo, Huawei and Xiaomi, all running the same two apps built by China-based Zhejiang Fengwo IoT Technology, operating as the Fengwo Group.

The investigation found Fengwo Group employees use a proprietary version of Google's Blockly — a visual programming language originally designed to teach kids coding — to let low-skilled operators assemble fraud routines by dragging code blocks together. These routines drive the spoofed devices to visit AI-generated news and blog sites and click ads that only render for traffic matching the fake mobile phone profile, using a system that fuses multiple vision and reasoning models to mimic human browsing behavior.

Crucially, the boxes never run ad fraud and proxy relaying simultaneously: when an HDMI signal indicates an attached TV is streaming video, the device switches to renting out the user's internet connection as a residential proxy; when idle, it resumes clicking ads. Bitsight tracked roughly 38,000 devices connected to the exposed domain and estimates the fraud network alone generates close to $50,000 daily, calling this a conservative figure based on just one older domain.

The case is a stark reminder for engineers and security teams of the risks embedded in unofficial IoT hardware supply chains, where default insecurity and undisclosed monetization schemes can quietly turn consumer devices into dual-purpose fraud and proxy infrastructure.