Android TV Boxes Mimic Phones, Hijack Home Broadband

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Bitsight reported that some cheap Android TV boxes shipped with pre-installed apps that rewrite the devices' hardware identity to impersonate phones from Samsung, Huawei, Xiaomi, or Vivo.
- The spoofed devices then use their owner's residential broadband to click ads on websites operated by the same actors behind the boxes.
- Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., a Chinese IoT vendor.
- By routing ad-clicking traffic through the buyer's home internet connection, the operation effectively turns each customer's Wi-Fi into an unwitting proxy for click fraud.
- The impersonation of four major phone brands means ad-fraud defenses designed to spot phone-originated traffic will see these clicks as legitimate mobile sessions.
Why it matters: Every buyer of an affected Android TV box becomes an unwitting participant in click fraud, with their home IP generating ad revenue for the operator. Bitsight's attribution to a named Chinese IoT company (Zhejiang Fengwo) gives ISPs, ad networks, and brand-fraud teams a concrete vendor and operation to block — and the spoofing of four of the world's biggest phone brands defeats the mobile-traffic filters those defenders rely on most.


