Executive Overview
For years, cybersecurity professionals and federal law enforcement agencies have issued stark warnings about the hidden dangers lurking inside inexpensive, generic TV streaming boxes. Marketed aggressively across major e-commerce platforms like Amazon, Best Buy, and Newegg as a loophole for free, unlimited entertainment—bypassing traditional subscription models—these uncertified devices are sold dirt cheap for a reason. While security analysts have long known that these streaming sticks silently hijack users’ home internet connections to act as unauthorized residential proxies for anonymous third parties, a groundbreaking new threat intelligence analysis reveals a far more insidious and lucrative enterprise.
According to a comprehensive investigation by threat researchers at security firm Bitsight, popular generic streaming hardware lines—most notably the widespread H96 brand—are pre-infected with sophisticated malware. This malware does not merely rent out bandwidth. Instead, it operates as a dual-action botnet. When a television is actively in use, the streaming box functions as a residential proxy, funneling traffic for data scrapers, ticket scalpers, and cybercriminals. But the moment the television is turned off, the hardware switches roles, transforming into an aggressive, automated engine for digital advertising fraud.
This sprawling operation is masterminded by Zhejiang Fengwo IoT Technology Co., Ltd. (operating under the Fengwo Group), a mainland Chinese enterprise founded in 2019. By spoofing their hardware fingerprints to masquerade as mobile phones built by premier manufacturers like Samsung, Vivo, Huawei, and Xiaomi, tens of thousands of compromised H96 streaming devices systematically visit AI-generated scam websites and artificially inflate advertising metrics.
Generating an estimated $50,000 per day from ad fraud alone—not counting supplementary revenue from proxy monetization—the Fengwo Group represents a terrifying evolution in cybercrime. By combining low-code visual programming tools, advanced vision-and-reasoning automation systems, and a vast captive web of compromised consumer electronics, this operation demonstrates how cheap smart home hardware has been weaponized into industrial-scale fraud.
Detailed Chronology of an Investigation
The unraveling of the Fengwo Group’s ad-fraud infrastructure began not with an alert from a major antivirus vendor, but with a piece of digital forensics luck encountered by Pedro Falé, a threat researcher at Bitsight.

The Expired Domain Breakthrough
Falé was investigating the command-and-control infrastructure tied to the H96 brand of Android TV boxes when he discovered an expired domain name that had previously been used for telemetry. In its active days, this domain collected comprehensive hardware diagnostics and complete app inventories from tens of thousands of H96 streaming sticks plugged into television sets globally.
By strategically registering the expired domain, Bitsight gained an unprecedented window into the operational heartbeat of the botnet. What Falé expected to see was a telemetry stream originating from stationary Android television boxes. Instead, the incoming data revealed a profound discrepancy.
“We noticed something was wildly wrong,” Falé noted. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’”
Unmasking the Mobile Spoofing Routine
Upon closer inspection of the data packets, Bitsight discovered that nearly all of the TV streaming boxes were systematically spoofing their user-agent strings and hardware identifiers. Despite being plugged into stationary home theater setups, the devices were reporting themselves as high-end mobile phones from major global brands.
Embedded within every single one of these spoofed devices were two proprietary applications developed by Zhejiang Fengwo IoT Technology Ltd. Further technical correlation—including overlapping SSL certificate data, shared internal wiki platforms, and matched patent filings—definitively tied these applications to the Fengwo Group’s corporate infrastructure.

The investigation revealed that these pre-installed apps were responsible for orchestrating a multi-stage fraud routine. When triggered, the streaming boxes would silently launch background web browsers, load sprawling networks of AI-generated web pages across diverse categories—including finance, health, gaming, music, and food blogs—and meticulously simulate human browsing behavior to click on targeted advertisements.
Supporting Context & Metrics: Inside the Machine
To understand the sheer scale and efficiency of the Fengwo Group’s operation, security analysts had to dissect the technical mechanisms that allow low-skilled operators to command tens of thousands of captive devices.
Low-Code Malicious Development via Blockly
One of the most alarming discoveries detailed in the Bitsight report is the Fengwo Group’s utilization of Blockly, a Google-built visual programming language originally designed to teach school-aged children how to write basic software.
Rather than requiring complex, hand-written C++ or Python scripts to direct the botnet, the Fengwo Group adapted Blockly into an internal web development dashboard. Employees and affiliate operators can simply drag and drop visual blocks of code together to define specific ad-fraud routines. Once a routine is compiled in the visual editor, it is automatically exported as JavaScript and pushed out to Amazon S3 buckets, ready to be deployed to compromised hardware.
Internal developer communications captured by Bitsight highlighted the strategic brilliance—and chilling efficiency—of this setup. One developer remarked that the system required only a small cadre of highly skilled engineers to build the core template execution units. Meanwhile, lower-tier operators could manage the day-to-day fraud routines with minimal technical understanding, drastically cutting operational overhead while maximizing output.

Automated Vision and Reasoning
Simulating thousands of automated ad clicks on AI-generated websites presents a significant hurdle: modern advertising networks deploy sophisticated fraud-detection filters designed to spot and block basic clickbots. To bypass these defenses, the Fengwo Group integrated a sophisticated automation pipeline into its apps.
The system fuses three distinct vision and reasoning frameworks into a single interface. When an H96 device is selected for a fraud task, the embedded automation tool does not simply hammer a URL at random intervals. Instead, it visually scans the webpage, identifies the precise location of targeted ad banners using computer vision, and navigates the site naturally—scrolling, pausing, managing browser tabs, and executing human-like mouse or touch inputs before clicking the ad.
Crucially, Bitsight’s analysis revealed that these AI-generated landing pages were deliberately engineered to remain dormant and ad-free unless visited by a device matching the specific, spoofed mobile hardware profile transmitted by the compromised H96 sticks.
The Dual-State Operation: Proxy by Day, Fraud by Night
The hardware resource constraints of a generic, low-cost TV box mean that running heavy residential proxy traffic and intensive visual ad-fraud routines simultaneously would instantly crash the device or degrade performance so severely that the user would notice.
To circumvent this, the Fengwo Group engineered a clever switching mechanism into the malware:

- Television Active (HDMI Signal Detected): When a user turns on their television and the box detects an active HDMI signal—signaling an intent to stream video—the device temporarily halts its ad-fraud tasks and dedicates its bandwidth exclusively to acting as an unauthenticated residential proxy.
- Television Idle (Off State): The moment the television is turned off, the streaming box drops its proxy duties and immediately reconnects to the Fengwo command servers to await ad-fraud assignments.
Financial and Fleet Metrics
Tracking telemetry from just a single, older core domain associated with the Fengwo Group, Bitsight identified approximately 38,000 active TV boxes phoning home globally. Based on this conservative sample, researchers estimate that the ad-fraud network pulls in a staggering $50,000 per day in fraudulent ad revenue. This figure excludes the separate, highly lucrative monetization stream generated by renting out user bandwidth via residential proxy networks.
Furthermore, the Fengwo Group’s public-facing marketing portal (fwgcloud.com) boldly claims to have created and deployed over 120,000 "AI digital humans" available for rent for customer service, emotional companionship, and creative design. While threat researchers suggest this grandiose figure may be a clever semantic facade designed to obscure the true nature of their botnet infrastructure, it underscores the vast resources at the organization’s disposal.
Official Statements and Industry Response
The security community’s repeated alarms regarding generic streaming hardware have found increasing validation from international law enforcement agencies, though regulatory and corporate catch-up remains painfully slow.
The Federal Bureau of Investigation (FBI) Warning
In formal advisories issued through its Cyber Division, the FBI has explicitly warned consumers and enterprises about the severe security risks posed by unmanaged Internet of Things (IoT) devices, particularly cheap streaming media players and digital photo frames. The bureau highlighted that unauthenticated smart devices are routinely co-opted into criminal botnets, used to facilitate distributed denial-of-service (DDoS) attacks, credit card stuffing, and cyber espionage.
E-Commerce Complicity
Despite recurring exposés from cybersecurity journalists and researchers, major online retailers—including Amazon, Best Buy, and Newegg—continue to host hundreds of third-party storefronts selling unbranded and off-brand Android streaming sticks. These devices routinely bundle unofficial, uncertified forks of Google’s Android operating system, often advertised heavily by online influencers as magical "jailbroken" boxes offering free access to premium sports, movies, and live television broadcasts.

When KrebsOnSecurity reached out to the Fengwo Group for comment via the contact email listed on their corporate domain ([email protected]), the inquiry bounced back immediately with an automated failure notice:
"Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now."
Future Outlook & Recommendations
As threat actors continue to professionalize cybercrime through artificial intelligence, low-code automation, and hardware-level supply chain compromises, the threat surface extending into ordinary living rooms will only expand. The intersection of consumer IoT and automated ad fraud points toward a troubling future where personal home networks are routinely exploited as invisible economic engines for overseas criminal syndicates.
How Consumers Can Protect Themselves
Security experts emphasize that safeguarding home networks from pre-infected IoT devices requires strict adherence to procurement and configuration best practices:
- Stick to Reputable Brands: Consumers should strictly avoid unbranded or generic "free streaming" boxes purchased via third-party marketplace sellers. Major brand-name streaming devices—such as Apple TV, Roku, Google Chromecast, and official Amazon Fire TV sticks—maintain strict security controls, signed firmware updates, and verifiable app store compliance.
- Verify Android Certification: For users purchasing hardware running Google’s Android TV ecosystem, Google provides official verification instructions to ensure devices carry legitimate Play Protect certification and run uncorrupted operating systems.
- Audit Installed Applications: Many name-brand smart televisions and streaming boxes are also beginning to face scrutiny regarding secondary software inclusions. For instance, platforms like LG have actively moved to ban residential proxy applications from their smart TV app ecosystems. Users should audit their installed apps regularly and remove any utilities of unknown origin.
- Consult Public Threat Intelligence Feeds: Organizations like Synthient maintain public, open-source repositories (such as community-driven product name CSV lists on GitHub) cataloging IoT hardware models known to ship with pre-installed proxy malware and botnet backdoors. Enterprise and consumer network administrators can cross-reference these lists to identify and isolate compromised hardware before it compromises local network security.
Ultimately, as the Fengwo Group investigation makes abundantly clear, the adage holds truer than ever in the digital age: if a consumer-facing technology product promises unlimited premium content for a negligible, one-time fee, the true cost is ultimately paid by the user’s own network bandwidth, data privacy, and digital security.