# You Bought a $40 TV Box. Someone in Zhejiang Bought Your Internet Connection.


The box probably came in a plain package with a name you've already forgotten. It streams 4K, runs Android, maybe came with a free IPTV trial. You plugged it in, it worked, and you moved on. What you didn't see was the firmware doing something else entirely — rewriting the device's hardware identity to look like a Samsung Galaxy, joining an ad-click network, and quietly leasing your home broadband to whoever would pay for it.


Bitsight researchers have documented exactly this scheme, which they've named Fuyao, and traced it back to Zhejiang Fengwo IoT Technology Co., Ltd., a company registered in mainland China in 2019. The operation combines two distinct revenue streams into one compromised device: ad fraud at scale and residential proxy infrastructure — and it does both without the consumer ever noticing a thing.


## The Identity Swap


The technical core of Fuyao is surprisingly elegant. Apps embedded in the firmware rewrite what Android reports as the device's hardware identity — spoofing the model name, manufacturer strings, and device fingerprints to present as a Samsung, Huawei, Xiaomi, or Vivo handset. From the perspective of any ad network or website, the traffic looks like it's coming from a legitimate consumer smartphone, not a $40 box sitting behind someone's router.


Those fake identities are then used to click ads on websites that Fuyao's operators control. The loop is closed: Fengwo manufactures or supplies the boxes, embeds the apps, runs the destination ad inventory, and collects from the ad networks in the middle. The consumer's broadband connection provides the cover; the device's fake identity provides the click-through plausibility.


The second job the firmware handles is residential proxy enrollment. Once a box is active on a home network, it registers that IP address with proxy infrastructure — the same model used by services that sell "residential" proxy access to clients who want traffic that looks like it's coming from real households. Depending on how aggressively the proxy is used, a consumer might see unexplained bandwidth consumption, slower speeds during peak hours, or nothing at all.


## Why Cheap Android Boxes Keep Shipping Malware


This is not a new problem, and that's the point.


In late 2023, Human Security's Satori team documented BADBOX, a nearly identical operation affecting off-brand Android TV boxes and tablets — devices that shipped with a backdoor called Triada baked into the firmware before they ever left the factory. BADBOX enrolled compromised devices into residential proxy networks and ad fraud schemes, and the researchers estimated it had touched over 74,000 devices at the time of disclosure. Then came BADBOX 2.0, documented in early 2024, which expanded the scope dramatically — more device types, more operators, and a modular backend that made attribution harder.


Fuyao appears to be a parallel operation or successor in this same ecosystem. The technical patterns are consistent: firmware-level persistence, hardware identity spoofing, dual-use ad fraud and proxy infrastructure, and a Chinese IoT manufacturer sitting at the center of the supply chain.


The reason these operations keep appearing isn't that defenders haven't noticed. It's that the economics are nearly impossible to interrupt at scale. Fengwo-branded or Fengwo-supplied devices move through gray-market channels, Amazon third-party sellers, AliExpress storefronts, and wholesale distributors. By the time a researcher traces the firmware to a specific factory, hundreds of thousands of units may already be in homes. Takedowns at the software layer don't reach the hardware already in circulation.


## Who's Actually Exposed


The immediate victims are split into two groups who have no idea they're in the same story.


Consumers are running proxy infrastructure for someone else, burning bandwidth and potentially exposing their home IP addresses to whatever activity that proxy infrastructure supports downstream. That's a legal exposure most people don't think about — if a residential proxy registered to your IP is used for credential stuffing, scraping, or worse, your address is in the log.


Advertisers are the other victim class. Ad fraud at the scale these operations achieve — spoofed device identities, geographically distributed residential IPs, realistic click patterns from what appears to be organic mobile traffic — costs the digital advertising industry an estimated $100 billion annually across all schemes combined. Fuyao is one node in that ecosystem, but it's a well-designed one: controlling both the click source and the destination inventory is about as clean a fraud loop as you can build.


Enterprise security teams generally don't buy $40 Android TV boxes for their SOC. But employees bring them home, put them on the same network as work laptops, VPN clients, and cloud sync services. The proxy infrastructure that routes through a compromised home network doesn't stop at the TV.


## What Defenders and Buyers Can Do


The honest answer is that supply-chain firmware compromise is hard to defend against after the fact. But there are practical steps that reduce exposure:


  • Avoid no-name Android TV boxes from unverifiable manufacturers. Brand names you've never seen before, shipping from generic warehouses, priced well below comparable hardware — the margin has to come from somewhere.
  • Segment IoT devices onto a guest VLAN. A compromised TV box on an isolated network can't reach your NAS, your work laptop, or your router's admin interface.
  • Monitor for unexpected outbound traffic. Residential proxy enrollment and ad-click activity generate outbound connections that differ from normal streaming patterns. Most home routers won't catch this, but a basic Pi-hole or a managed router with traffic logging will show anomalies.
  • Check firmware sources before purchase. Devices running verified builds from the Android Open Source Project, with named firmware maintainers and update histories, are meaningfully safer than boxes with anonymous firmware versions.

  • There is no patch coming for Fuyao. The manufacturer isn't going to push a remediation update.


    ---


    ## HackWire Analysis


    The Fuyao disclosure lands at an interesting moment in the residential proxy market. Law enforcement and ad fraud researchers have spent the last two years building cases against proxy-as-a-service operations — several have been seized or shut down — which creates pressure on the supply side. Operations like Fuyao represent the supply side's answer: don't buy residential IP access on the open market, build your own by shipping compromised hardware directly into consumers' homes.


    What's missing from most coverage of this operation is the downstream liability question. When a residential IP address enrolled in proxy infrastructure appears in an incident log — a credential stuffing attack on a bank, a scraping operation against a competitor, a fraud probe — the person who owns that IP address is the first call that investigators make. Consumers running Fuyao-compromised boxes are, without their knowledge, becoming potential subjects of cybercrime investigations they have nothing to do with. That's a meaningful harm that "you might see slower streaming speeds" doesn't capture.


    The BADBOX lineage also deserves more attention. Fuyao, BADBOX, BADBOX 2.0, and half a dozen smaller operations documented over the past three years share the same fundamental architecture: firmware-level persistence on cheap Android hardware, residential proxy enrollment, and ad fraud as a revenue layer. This is not a series of independent discoveries — it's an ecosystem. The same factories, the same firmware developers, possibly the same backend infrastructure, iterating after each disclosure. Treating each new named operation as a separate story misses the continuity. Until the supply chain itself faces meaningful consequences — customs enforcement, manufacturer blacklists, liability for distributors — expect Fuyao 2.0 within eighteen months.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)