# The $30 TV Box That's Quietly Committing Ad Fraud on Your Internet Connection
You bought it because it promised free movies, unlimited streaming, no monthly fees. Someone on YouTube swore it was a cheat code for cutting the cord. What you actually bought was a node in a sprawling Chinese-operated ad fraud network — and your home internet connection has been doing the dirty work ever since.
That's the conclusion of a detailed investigation by Bitsight threat researcher Pedro Falé, who stumbled into one of the more intricate fraud operations in recent memory by doing something deceptively simple: registering a domain nobody else was watching.
## A Dead Domain Opens a Live Fraud Network
The H96 is a cheap Android TV stick sold openly on Amazon, one of dozens of generic streaming devices that flood the market under various brand names. Security researchers have warned for years that these boxes ship with pre-installed malware that presses consumer broadband connections into service as residential proxies — renting your IP address to strangers without your knowledge. That was already bad enough.
What Falé found goes considerably further.
The expired domain he acquired had been used as a telemetry endpoint — a check-in server for H96 devices deployed in homes around the world. Once he controlled it, the traffic started rolling in: hardware fingerprints, installed app lists, device identifiers from tens of thousands of sticks plugged into televisions across the globe. Standard botnet telemetry. Unremarkable, until he looked closer at what these TV boxes were claiming to be.
Nearly every device identifying itself to his server said it was a smartphone. Samsung. Vivo. Huawei. Xiaomi. Multiple devices, same location, all reporting as different phone models. "We noticed something was wildly wrong," Falé said. "Multiple devices reporting to this factory Android TV Box backdoor were 'phones.'"
## The Anatomy of the Scam
Every infected device had exactly two apps in common — both built by a company called Zhejiang Fengwo IoT Technology Ltd, a mainland China entity founded in 2019 that operates under the name Fengwo Group. Bitsight traced the monetization through a constellation of Hong Kong, Singapore, and single-person shell entities designed to diffuse legal exposure before the trail leads back to Fengwo.
The mechanics are elegant in a cynical way. The Fengwo Group runs a network of AI-generated websites across anodyne categories: finance, health, education, gaming, food blogs. These sites appear to contain real content — machine-generated articles, stock-ish graphics — but they have a trigger condition: the ads only render when the visiting device matches the spoofed mobile profile of an H96 stick pretending to be a phone.
Put plainly: the sites generate fake traffic from fake mobile visitors, click their own ads, collect the ad revenue, and show nothing to anyone else who might stumble across them. The H96 devices in living rooms around the world are the fake audience.
What makes this operationally scalable is Blockly, a visual programming language Google originally built to teach children how to code. Fengwo Group employees use a proprietary implementation of Blockly to drag code blocks together and build the sham websites — no software development knowledge required. Low-skilled operators can spin up new fraudulent surfaces without understanding what the underlying code actually does.
Fengwo Group's own website pitches the company as being in the business of "AI digital humans" — more than 120,000 of them available for rent, for everything from companionship to customer service. The SSL certificate data from that domain connects directly to the apps found on H96 devices and their phone-spoofing mechanism. The internal wiki ties the Blockly implementation to Fengwo employees. The patents match the app behavior. This isn't a loose correlation — Bitsight traced the whole stack back to a single organization.
## Who Gets Hurt
The obvious victims are the advertisers whose budgets are being siphoned by fake impressions on fake pages. Ad fraud costs the digital advertising industry tens of billions annually, and operations like this one explain a significant portion of that loss. Brands paying for mobile display ads are getting clicks from H96 sticks in someone's basement pretending to be a Galaxy S23.
But the homeowners with these devices are also victims — twice over. Their bandwidth is being used without consent, and their IP addresses are attached to fraudulent activity. If a downstream investigation ever focuses on click fraud originating from a residential IP, the person who bought the streaming stick is the first address in the log.
The retailers carrying these products — Amazon most visibly — face a harder question: at what point does stocking them constitute negligence? H96 devices remain available for purchase today.
## HackWire Analysis
The Fengwo operation isn't new in concept — cheap Android TV boxes with pre-installed malware have been documented since at least 2019, and researchers including those at Human Security (formerly WhiteOps) have mapped large-scale residential proxy botnets built on similar hardware. What Bitsight's investigation adds is the full picture of *how the money flows*, which prior reporting has largely missed.
The ad fraud angle matters because it creates a sustainable economic engine that pure proxy-for-hire operations lack. A residential proxy network has to find buyers for that bandwidth. An integrated fraud stack — TV box to fake mobile click to AI content farm to ad payout — is self-funding. Fengwo doesn't need external customers. The network generates its own revenue, which funds more device distribution, which grows the network.
This also reframes the threat model for brand safety teams and ad verification vendors. The conventional focus has been on bot traffic that looks like bots. A TV box spoofing a Xiaomi phone, clicking on ads that only appear to that spoofed device, on a site that otherwise serves clean-looking content to real crawlers — that's a significantly harder detection problem. Most ad fraud detection relies on user agent analysis, click patterns, and IP reputation. A residential IP that looks like a mobile device blows through several of those filters simultaneously.
Defenders in the ad tech space should be looking specifically at residential IPs that exhibit mobile user agents across inconsistent geographic patterns — a "Samsung Galaxy" browsing from an IP that also appears in IPTV abuse databases is a signal worth pulling on. For consumers, the guidance is blunt: if a streaming device costs $30 and promises unlimited content with no subscription, you are the product, and so is everyone downstream of your router.
— HackWire Editorial
## Related Coverage