Skip to main content

Android TV Boxes Hijack Broadband for Proxy Networks

Cluttered electronics room with Android TV box at center, surrounded by router, modem, and cables in dim, ambient light.

Bitsight's sinkhole recorded 65,957 reports from about 38,000 unique MAC addresses in a single day after filtering for devices carrying the Fuyao apps — and most of those devices described themselves as phones.

What Bitsight calls "Fuyao" and the Zhejiang Fengwo link

Bitsight named the operation "Fuyao" and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. That attribution, the company wrote, rests on shared TLS certificate data, exposed wiki files, reused email addresses, revenue links, and patents. Public Chinese patent records independently list Zhejiang Fengwo as the assignee of two related filings: CN117421142B (granted November 2024) covering execution-flow tracking for digital‑human behavior modules, and CN117478834A describing monitoring remote screens through cloud‑hosted thumbnails and keyframe comparison. Neither patent describes advertising, and the records do not establish that the company operated Fuyao or engaged in ad fraud.

How the boxes spoof phones and run ad‑fraud routines

Bitsight found that some cheap Android TV boxes shipped with apps that rewrite the device's hardware identity to mimic phones from Samsung, Huawei, Xiaomi, or Vivo. The command‑and‑control server pushes complete phone profiles to each box, merging a base configuration with a per‑model diff and deleting chipset properties that would expose an underlying Rockchip, Amlogic, or Allwinner board.

Fuyao's automation uses machine vision to locate ads. Bitsight describes a Script app that carries a YOLOv8s object‑detection model named lourui_2, trained on 12 screen elements — including generic banner regions and Taboola widgets — and combined with Android accessibility data and Google ML Kit optical character recognition. "Fuyao fuses three vision and reasoning systems into a single interface," Pedro Falé, a Bitsight threat researcher, wrote.

Campaign logic is assembled in a custom editor built on Blockly; operators export fraud routines as JavaScript, upload them to S3, and send them to the boxes for execution. Across four test devices, Bitsight captured roughly 40 fraud tasks, 21 unique campaigns, and 166 unique modules. A recovered developer comment said the template system let a small group of skilled engineers support less‑skilled campaign operators, lowering costs.

When HDMI is on: owners' broadband becomes a SOCKS5 exit node

Bitsight found the apps also switch behavior based on an HDMI signal. When a box detects HDMI activity, it usually switches to relaying other people's traffic through the owner's broadband line as a SOCKS5 exit node; when HDMI is off, the device reverts to waiting for ad‑fraud tasks. That dual function means devices acting as innocuous TV boxes can also carry third‑party network traffic without the owner's knowledge.

The payout chain: publisher domains, Taboola tags, and estimated revenue

Bitsight mapped 144 operator‑owned domains across seven beneficiary clusters and identified at least 84 of them loading a Taboola tag on the homepage. Using Taboola's public sellers.json file, researchers connected those domains to revenue‑collecting entities in Hong Kong and Singapore. Bitsight modeled gross returns at $1.25 per device per day — which would equal about $47,500 daily if 38,000 devices were active — and separately estimated annual revenue could reach $40 million at the advertised fleet size, citing 30–40% fraud flagging and a 70% ad‑fill rate. Bitsight noted those figures are estimates and did not show the full calculations; they are not observed revenue.

What this means for end users, security teams, and publishers

  • End users: Owners of low‑cost Android TV boxes should verify Play Protect certification and disconnect suspicious devices from their networks; the FBI previously advised assessing connected devices, disconnecting suspect ones, keeping firmware current, and treating generic streaming boxes sold as promising free content as suspect.
  • Security teams and network operators: Devices that report phone‑like identities or that suddenly begin presenting SOCKS5 exit endpoints merit investigation; the sinkhole evidence shows spoofed identifiers can inflate counts, so teams should rely on multiple indicators rather than simple device tallies.
  • Publishers and ad networks: At least 84 domains in Bitsight's mapping loaded Taboola tags; the connection to public sellers.json entries shows how ad supply chains and third‑party tags may be linked to monetization endpoints in Hong Kong and Singapore that collect revenue from fraudulent impressions.

Bitsight found the operation by registering an expired domain used as a factory backdoor and telemetry collector, but researchers and the checked sources did not establish who installed the apps or at what point in the device supply chain they appeared. As of 7:48 p.m. IST on July 31, 2026, Bitsight's blog index still listed only the July 30 overview, and promised technical follow‑ups were not discoverable on the site searched. That leaves concrete identification guidance incomplete, even as the single‑day sinkhole data points to a large, distributed phenomenon.

Original story