Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones

Bitsight found generic TV streaming sticks spoofing as phones and clicking ads on AI-generated sites in a Fengwo Group ad-fraud network worth $50,000 a day.
Table of Contents
    Add a header to begin generating the table of contents

    Generic TV streaming sticks are routinely spoofing themselves as mobile phones and clicking ads on AI-generated websites as part of a sprawling ad-fraud operation, according to an analysis released this week by Bitsight threat researcher Pedro Falé. The researcher reclaimed an expired domain previously used for telemetry by H96 streaming sticks and documented roughly 38,000 devices reporting in, nearly all of them posing as phones from Samsung, Vivo, Huawei, and Xiaomi.

    Fengwo Group’s TV Sticks Spoof as Phones to Click Ads on AI-Generated Sites

    All the devices reported the same two apps, made by Zhejiang Fengwo IoT Technology Ltd, which was founded in 2019 and operates an ad-publishing portfolio under the Fengwo Group name. The apps coordinate an ad-fraud network that uses the H96 devices as a captive traffic source to click ads on AI-generated websites operated by the Fengwo Group. The sites contain machine-generated news and graphics across finance, health, education, gaming, music, and food categories, and they display ads only when the visiting device matches the spoofed mobile profile, which hides the fraud from advertisers serving real user traffic.

    38,000 Tracked Boxes Funnel Traffic Into the Fengwo Network

    The Fengwo Group’s domain claims it has created more than 120,000 “AI digital humans” available for rent, which Bitsight suggests may be a marketing facade to avoid drawing suspicion about the device fleet. Falé’s measurement of roughly 38,000 reporting boxes represents only the devices that phoned home to the reclaimed telemetry domain, meaning the full fleet could be larger. The boxes fuse three vision and reasoning systems into a single interface so the bots can identify an ad on a webpage and navigate like a human, a design aimed at passing ad-verification checks that look for realistic browsing behavior.

    Blockly-Built Fraud Sites and the HDMI Signal That Switches Roles

    Fengwo employees build the sham websites using Google’s Blockly visual programming language, dragging blocks of code together to define each fraud routine and exporting it as JavaScript uploaded to S3 buckets. That approach lowers the technical skill required to operate the network. The devices are either relaying residential proxy traffic or participating in ad fraud, never both: when the box detects an HDMI signal, meaning the TV is on, it typically functions as a residential proxy, and when the TV is off, it switches to ad-fraud jobs.

    The Residential Proxy Layer and the Insecure-By-Default Device Market

    Generic streaming devices also almost universally ship with residential proxy software pre-installed that rents the user’s internet address to paying customers. Bitsight described the devices as horribly insecure by default and bereft of any kind of authentication. The FBI and the security industry have repeatedly warned about these devices, and earlier this year the proxy-tracking service Synthient documented multiple botnets that enslaved millions of TV boxes. For the buyer, the box is a one-time purchase; for the operator, it is a permanently resident node on the buyer’s home network.

    Bitsight’s $50,000-a-Day Estimate and Prior Industry Warnings

    Bitsight estimates the ad-fraud network brings in close to $50,000 a day from roughly 38,000 tracked boxes, a figure it describes as conservative because it is based on one older Fengwo domain and does not count residential-proxy revenue. The estimate illustrates the scale of revenue a consumer device fleet can generate: a modest, semi-automated operation built on commodity streaming hardware can sustain that level of income while the hardware itself is sold as a one-time consumer purchase.

    How Consumers Become the Fraud Infrastructure

    The economics of cheap streaming sticks explain why the market keeps growing. Hardware is sold at a one-time cost while the device continuously generates ad-click revenue and proxy income for its operators, so every box sold is effectively a recruited node in a fraud and bandwidth-rental network. The buyers paying a few dollars for the stick are silently subsidizing ad fraud against merchants and advertising networks, and they are exposing their home connections to use as anonymous relay infrastructure. Because the devices also lack authentication, the same fleets can be repurposed by other attackers once the original operators lose control of them.

    Guidance for Buyers of Cheap Streaming Sticks

    Falé’s advice to consumers is to stick with name-brand devices from reputable manufacturers, confirm a device uses the official Android TV OS and Play Protect certification, be sparing with installed apps, and avoid generic one-time-fee streaming boxes. Synthient maintains a running list of IoT devices known to ship with residential proxy software and malicious apps pre-installed, giving buyers a way to check a device before purchase. For organizations, the findings show that personal networks feeding into corporate remote access are only as trustworthy as the devices attached to them.

    Related Posts