Android TV Boxes Pose as Phones for Ad Fraud

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Bitsight discovered the Fuyao operation by registering an expired domain used as a factory backdoor, finding apps that rewrite hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones and click ads on operator-run websites.
- Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China IoT company founded in 2019, was attributed as the operator based on shared TLS certificates, exposed wiki files, reused email addresses, revenue links, and patents.
- Fuyao boxes double as SOCKS5 exit nodes: when an HDMI signal is detected they relay other people's traffic through the owner's broadband, and they return to ad-fraud tasks when HDMI is off.
- The fraud uses a YOLOv8s object-detection model named "lourui_2" trained on 12 screen elements including Taboola widgets, combined with Android accessibility data and Google ML Kit OCR.
- Operators build fraud routines in a custom Blockly-based drag-and-drop editor, exporting them as JavaScript to S3; Bitsight captured ~40 fraud tasks, 21 campaigns, and 166 modules across four test devices.
- Bitsight mapped 144 operator-owned domains across seven beneficiary clusters (84+ loading Taboola tags) and modeled $1.25/device/day — about $47,500 daily at 38,000 devices, with annual revenue estimates up to $40 million at the advertised fleet size.
- Google confirmed the off-brand devices were not Play Protect certified Android devices; the FBI advised in June 2025 that owners treat generic streaming boxes sold on promises of free content as suspect.
Why it matters: Cheap uncertified streaming boxes turn each buyer's broadband into both an ad-fraud click farm and a relay for strangers' traffic, exposing owners to ISP scrutiny while funneling an estimated $40 million annually to one Zhejiang company with no Play Protect certification to fall back on.


