Cheap TV Streaming Sticks Found Running Massive Ad Fraud Network

Original: Read this before you buy that TV streaming stick

Why This Matters

Reveals how low-cost consumer streaming hardware can serve as covert nodes in large-scale ad fraud operations.

Security firm Bitsight revealed that generic Android TV streaming sticks, specifically the H96 brand, are secretly spoofing mobile devices to commit ad fraud on AI-generated websites, traced back to China-based Zhejiang Fengwo IoT Technology Co., Ltd.

Bitsight threat researcher Pedro Falé uncovered a large-scale ad fraud operation by registering an expired domain previously used to collect telemetry from H96 Android TV streaming boxes sold globally, including on Amazon. The domain was receiving data from tens of thousands of devices, but nearly all reported themselves as mobile phones from brands like Samsung, Vivo, Huawei, and Xiaomi — despite being TV boxes. All devices shared two identical apps, both linked to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019 operating under the name Fengwo Group. These apps coordinate fake ad clicks on a network of AI-generated websites containing machine-generated articles across finance, health, gaming, and other categories. Critically, those websites only displayed ads when visited by devices matching the spoofed mobile profile of H96 units. Bitsight traced the monetization infrastructure through Hong Kong and Singapore shell entities back to Fengwo Group, whose domain fwgcloud[.]com promotes over 120,000 "AI digital humans" for rent. SSL certificate data and an internal Blockly-based wiki further tied the apps directly to the Fengwo Group.

Source

krebsonsecurity.com — Read original →