Trojan Televisions: How Cheap Streaming Boxes Secretly Orchestrate a Massive Global Ad Fraud Empire

By Global Cybersecurity Desk
Published: July 2026
For years, cybersecurity professionals and federal law enforcement agencies have issued urgent warnings regarding the hidden dangers of generic, unbranded Android TV boxes. Frequently marketed across mainstream e-commerce platforms and social media channels as a "too good to be true" solution for free, unlimited entertainment, these inexpensive devices have long been suspected of hijacking home internet connections to route traffic for strangers.
However, a groundbreaking investigation by threat researchers has uncovered a far more insidious reality. Beyond merely acting as silent conduits for residential proxy networks, millions of these streaming sticks are hardcoded with sophisticated payloads designed to spoof mobile hardware, manipulate artificial intelligence-generated websites, and execute a sprawling, highly lucrative digital advertising fraud scheme.
Main Facts: The Anatomy of an IoT Connoisseur’s Trap
The latest research, spearheaded by Pedro Falé, a threat intelligence researcher at security firm Bitsight, has exposed how a popular brand of generic streaming devices known as H96 operates a dual-purpose malicious architecture. When plugged into a home network, these devices utilize pre-installed software to either rent out the owner’s bandwidth as a residential proxy or function as automated click-bots on sham web pages.

According to Bitsight’s analysis, the H96 boxes routinely falsify their device telemetry. When communicating with factory command-and-control servers, the television peripherals systematically spoof mobile operating systems, masquerading as popular smartphone models manufactured by tech giants such as Samsung, Vivo, Huawei, and Xiaomi.
The primary beneficiary—and orchestrator—of this ad-fraud pipeline has been traced back to mainland China. Bitsight’s investigation points directly to Zhejiang Fengwo IoT Technology Ltd., a company founded in 2019 that operates a massive portfolio under the moniker Fengwo Group.
Operating from the shadows of a network of shell entities registered in Hong Kong and Singapore, Fengwo utilizes specialized applications embedded directly into the H96 firmware. These applications coordinate automated browser sessions, forcing the compromised TV boxes to visit AI-generated websites, navigate pages, and simulate human interaction by clicking on targeted digital advertisements.
Chronology: Unraveling the H96 and Fengwo Conspiracy
The unmasking of the Fengwo Group ad fraud operation is a masterclass in modern threat hunting. The timeline of discovery highlights the methodical approach security researchers take when peeling back layers of obfuscated infrastructure.

- 2019–2023 (Establishment and Proliferation): Zhejiang Fengwo IoT Technology Ltd. is established in mainland China, quietly building out a network of app portfolios and registering multiple intellectual property patents related to automated mobile interaction and data collection. Concurrently, cheap H96 Android TV boxes flood global markets, aggressively marketed via online influencers on Amazon, Newegg, and Best Buy as budget-friendly cable-cutters.
- January 2026 (Botnet Escalation): Proxy tracking and threat intelligence service Synthient documents a massive security event wherein multiple botnets—such as the infamous Kimwolf botnet—rapidly enslave millions of unbranded streaming boxes by exploiting vulnerabilities in both their firmware and pre-installed residential proxy software.
- Mid-2026 (The Breakthrough Discovery): Pedro Falé of Bitsight registers an expired domain name that had historically been used for telemetry by H96 streaming sticks. The domain had been responsible for periodically harvesting hardware telemetry and app inventory lists from tens of thousands of active devices globally.
- Analysis and Deconstruction: Upon inspecting the incoming traffic routed to the newly acquired domain, Falé discovers an alarming anomaly: thousands of television-connected streaming boxes are reporting device profiles identical to high-end mobile smartphones.
- Identification of the Culprit: Bitsight links the apps communicating with the infrastructure directly to the Fengwo Group, mapping out their use of AI-generated content, automated visual programming interfaces, and revenue-generation shell companies. The findings are publicly released in a comprehensive research report.
Supporting Data: Numbers Behind the Multi-Million Dollar Fraud
The scale of the H96 ad fraud operation is vast, relying on distributed architecture, automated code generation, and specialized software routines to minimize overhead while maximizing monetization.
Financial and Network Metrics
- 38,000+ Active Sensors Tracked: Bitsight’s telemetry analysis focused on just one older, core domain associated with the Fengwo Group, identifying roughly 38,000 active H96 boxes phoning home globally.
- $50,000 Daily Revenue Estimate: Conservative financial estimations indicate that this single slice of the Fengwo ad fraud network generates close to $50,000 per day in fraudulent ad revenue, a figure that excludes secondary income derived from residential proxy leasing.
- 120,000 "Digital Humans": The primary public-facing portal for the Fengwo Group (
fwgcloud.com) markets the enterprise as a developer of "AI digital humans" for customer service and companionship—a facade that security experts believe is designed to mask the true botnet and proxy infrastructure underneath.
Operational Efficiency: The Blockly Framework
To minimize technical development costs, the Fengwo Group utilized an internal wiki platform tied directly to Blockly, an open-source visual programming language originally created by Google to teach children how to code.
By employing Blockly editors, low-skilled operators within the organization could drag and drop pre-coded visual blocks to define specific fraud routines. Once saved, these blocks automatically exported as JavaScript modules, which were then pushed via Amazon S3 buckets directly to target devices.
According to internal communications uncovered by Bitsight, this modular approach allowed a tiny team of elite developers to build core execution templates, while lesser-skilled workers managed the daily operations. This dramatically reduced overhead and maximized the speed at which new ad-fraud routines could be deployed.

The Behavioral Switch: TV On vs. TV Off
One of the most revealing technical discoveries made by Bitsight is the operational dichotomy built into the H96 boxes:
- TV Is On (HDMI Signal Active): When a user turns on their television and the streaming stick detects an active HDMI handshake, the device ceases ad fraud operations and dedicates its resources to functioning as a residential proxy, routing external traffic through the owner’s home network.
- TV Is Off (No HDMI Signal): As soon as the television is powered down, the device immediately pivots to execute ad fraud tasks, launching headless web browsers, navigating AI-generated blog posts, and clicking on monetization links.
Researchers concluded that this resource management strategy was necessary because the CPU-intensive demands of automated ad fraud and web rendering would severely degrade the streaming performance expected by the user.
Official Responses and Industry Warnings
Regulatory bodies and security agencies have grown increasingly vocal about the systemic threats posed by unvetted consumer IoT devices.
In late 2025 and early 2026, the Federal Bureau of Investigation (FBI) issued formal public safety alerts warning that inexpensive home internet-connected devices—particularly streaming sticks and digital photo frames—routinely ship pre-infected with malicious code. The FBI emphasized that these gadgets expose residential networks to criminal syndicates seeking endpoints for cyberattacks, credential stuffing, and data exfiltration.

Major e-commerce platforms have faced mounting pressure to remove unverified streaming devices from their digital shelves. However, thousands of generic variations continue to circulate on platforms like Amazon, Best Buy, and Newegg, often evading automated moderation by constantly shifting brand names (such as H96, T95, and various unbranded alternatives).
When approached for comment regarding these findings, the Fengwo Group failed to provide a statement. An email inquiry sent to [email protected] bounced back immediately with an automated failure notice:
"Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now."
Google has reiterated that consumers must verify whether their hardware runs an officially certified version of the Android TV operating system backed by Google Play Protect. Users can check device authenticity via official Google support guidelines. Furthermore, threat intelligence groups like Synthient maintain public repositories—including CSV logs of known compromised product names—to help consumers identify dangerous hardware.

Implications: The Future of IoT Security and Ad Fraud
The exposure of the Fengwo Group operation marks a watershed moment in the intersection of artificial intelligence, IoT botnets, and digital advertising fraud. The implications of this research extend far beyond mere copyright infringement or data privacy concerns.
1. The Weaponization of AI in Cybercrime
The integration of machine-generated content (news articles, finance blogs, gaming portals) combined with multi-modal vision and reasoning systems allows modern ad-fraud networks to pass modern bot-detection algorithms. By utilizing AI to mimic human reading patterns and visual confirmation steps, criminal networks can continually harvest ad revenue from legitimate marketing networks with near-impunity.
2. The Erosion of Consumer Trust in Smart Hardware
The "dirt cheap" business model of unbranded electronics relies on subsidizing hardware manufacturing costs through illicit back-end monetization—namely, selling user bandwidth and executing click fraud. Until major global marketplaces enforce stringent supply chain verification and hardware certification, consumers remain the unwitting accomplices in multi-million-dollar criminal enterprises.
3. Recommended Defensive Measures
Security experts universally advise consumers to take immediate steps to secure their home environments:
- Stick to Reputable Brands: Purchase streaming hardware exclusively from established, trusted manufacturers (such as Google, Roku, Apple, and Amazon Fire TV lines).
- Isolate IoT Networks: Place all Internet of Things (IoT) devices on a segregated guest or VLAN network to prevent lateral movement in the event that a peripheral is compromised.
- Audit Installed Applications: Periodically review applications installed on smart TVs and media boxes, removing unverified sideloaded apps or tools promising free access to premium subscription content.
