Android TV Boxes Run Ad Fraud, Hijack Home Broadband

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Bitsight uncovered Fuyao, finding cheap Android TV boxes ship with apps that spoof hardware identities to mimic Samsung, Huawei, Xiaomi, or Vivo phones and click ads on operator-run websites.
- Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019, is attributed as the operator based on shared TLS certificates, exposed wiki files, reused email addresses, revenue links, and related patents.
- The boxes also function as SOCKS5 proxy exit nodes whenever an HDMI signal is active, relaying outside traffic through the owner's broadband, then reverting to ad-fraud tasks when HDMI is off.
- In a single day, Fuyao's sinkhole received 65,957 reports from roughly 38,000 unique MAC addresses, with most identifiable devices reporting the model name H96_MAX_V11.
- The automation pipeline runs a YOLOv8s object-detection model called lourui_2, trained on 12 screen elements including Taboola widgets and combined with Google ML Kit OCR and Android accessibility data.
- Researchers mapped 144 operator-owned domains across seven beneficiary clusters, with at least 84 loading Taboola tags; modeled gross returns at $1.25 per device per day, estimating roughly $47,500 daily at 38,000 active devices.
Why it matters: Cheap streaming hardware sold to consumers doubles as a residential proxy network and ad-fraud botnet, with Bitsight estimating operators could pull roughly $47,500 daily across ~38,000 observed devices — meaning buyers of generic Android boxes may unknowingly host criminal infrastructure that triggers ISP scrutiny over suspicious outbound traffic.


