Skip to main content
Emerging ThreatsMalware & Ransomware

Streaming Devices Expose Users to Ad Fraud, Proxy Schemes

Cluttered living room with streaming device on TV stand amidst scattered electronics and cables.

"We noticed something was wildly wrong," Pedro Falé told KrebsOnSecurity after peering into an ad‑fraud operation tied to inexpensive TV streaming sticks.

Pedro Falé and Bitsight trace a sprawling ad‑fraud network

Pedro Falé, a threat researcher with the security firm Bitsight, registered an expired domain that had been used for telemetry from tens of thousands of H96 streaming sticks. That action allowed him to inspect traffic and uncover an operation that, according to Bitsight, used those devices not only to relay residential proxy traffic but also to impersonate mobile phones and click ads on AI‑generated websites. Bitsight TRACE identified transfers of monetization through several Hong Kong, Singapore and single‑person legal entities and traced the operation back to Zhejiang Fengwo IoT Technology Co., Ltd., which operates under the name Fengwo Group, Falé wrote in the report released July 2026.

H96 streaming sticks spoof mobile phones to click ads

Bitsight's analysis found that nearly all of the TV boxes phoning home to the expired domain reported themselves as mobile phones — models from Samsung, Vivo, Huawei and Xiaomi — despite being Android TV boxes. All of the devices reported having the same two apps installed; those apps were published by Zhejiang Fengwo IoT Technology Ltd. Falé told KrebsOnSecurity he observed devices reporting themselves as "phones" while connecting to the coordination domain.

The apps pushed modules that could silently launch a web browser, visit websites, manage tabs and click on advertisements. To ensure the boxes could identify and activate ads on the generated pages, the operation "fuses three vision and reasoning systems into a single interface," Bitsight observed, allowing the bots to navigate pages much like a human would.

Fengwo Group, fwgcloud[.]com, and "AI digital humans"

The Fengwo Group’s domain, fwgcloud[.]com, claims the company is "redefining the boundaries of human‑AI interaction" and advertises more than 120,000 "AI digital humans" available for rent. Bitsight found the domain shared SSL certificate data with other domains tied to the phone‑spoofing mechanism and hosts an internal wiki linking the company to a proprietary use of Blockly — a Google‑built visual programming language.

Bitsight reported that employees use Blockly to assemble "fraud routines" by dragging blocks together and exporting the resulting code as JavaScript for upload to cloud S3 buckets. As one Fengwo Group developer put it in internal discussion quoted by Bitsight, "only a small number of highly‑skilled developers are needed to build the template execution‑unit images," and "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs."

Bitsight also found the group's AI‑style websites consisted largely of machine‑generated news articles and graphics spanning finance, health, education, gaming, music and food blogs — but those pages did not display ads unless the visitor matched the spoofed mobile profile of the H96 boxes.

TV ON? PROXY. TV OFF? AD FRAUD

Bitsight discovered the H96 devices operated in two mutually exclusive modes: they either relayed residential proxy traffic or took on ad‑fraud jobs, but not both simultaneously. When the device detected an HDMI signal from an attached television — indicating the user intended to stream video — it usually functioned as a residential proxy. When the TV was off, the device reverted to waiting for ad‑fraud tasks.

Bitsight estimated it recorded roughly 38,000 TV boxes globally phoning home to the expired Fengwo domain and used that telemetry to produce a conservative revenue estimate of close to $50,000 per day from the ad‑fraud activity alone. Falé cautioned those estimates are conservative and derived from data tied to one older domain. The report also noted substantial additional revenue likely derives from the residential proxy side of the business.

What this means for technologists, policymakers, and consumers

  • Technologists and security teams: monitor for devices presenting inconsistent device metadata (Android TV boxes advertising mobile phone profiles) and watch for coordinated telemetry to domains that share SSL certificates across multiple operational domains, as Bitsight documented.
  • Policymakers and procurement leaders: recognize that cheap, off‑brand devices can be dual‑use — simultaneously sold as streaming hardware while functioning as residential proxies or ad‑fraud nodes — and that apparent legal entities and shell companies may be used to collect monetization.
  • Consumers and procurement managers: stick to name brands from reputable manufacturers, be sparing with apps installed on streaming sticks, and verify whether a device has official Android TV OS and Play Protect certification using Google's published instructions, Bitsight advised. Synthient maintains a running list of IoT devices known to ship with residential proxy software and other malicious apps.

The record here is precise and narrow: Bitsight's telemetry, gathered after taking control of an expired domain, ties H96 streaming sticks to a coordinated ad‑fraud and proxy business that the report traces back to Zhejiang Fengwo IoT Technology and its Fengwo Group brand. Despite the company's public claims of renting tens of thousands of "AI digital humans," Bitsight notes that the public face of fwgcloud[.]com answered no outreach — an email to postmaster@fwgcloud[.]com bounced with an automatic reply that the inbox was full. Major retailers such as Amazon, Best Buy and Newegg continue to list hundreds of off‑brand Android‑based streaming devices, and the findings underscore why Bitsight's advice is blunt: prefer reputable manufacturers and scrutinize every app shipped or installed on these devices.

Read the original report on KrebsOnSecurity