Security Researchers Warn of Hidden Fraud Schemes in Cheap Android TV Boxes

💛 A quick favor, if you've got a second.

We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.

It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Share this story:


✉️ Email


💬 Text

Security researchers have identified a sophisticated scheme in which inexpensive Android TV boxes operate hidden background processes designed to generate fraudulent advertising revenue and route household internet traffic through external networks. Bitsight, a security firm, discovered that some devices sold under the H96 brand name contained preinstalled malicious software capable of disguising the boxes as smartphones to visit operator-controlled websites and automatically click online advertisements without the owner’s knowledge.

The operation, which Bitsight has named Fuyao Enterprise and attributed to Zhejiang Fengwo IoT Technology Co., Ltd., demonstrates a technically advanced approach to digital fraud. In a 24-hour observation period, researchers documented approximately 38,000 unique devices potentially containing the malicious software, with estimated daily ad fraud revenue reaching $47,500. The company’s website claims to operate more than 120,000 “AI digital humans,” which researchers suggest may refer to the automated device network.

Threat researcher Pedro Falé uncovered the operation while investigating security vulnerabilities in budget-priced Android TV boxes. His team discovered an expired domain previously used to manage factory backdoors and observed that many devices identified themselves as smartphones from manufacturers including Samsung, Vivo, Huawei and Xiaomi, despite software indicators revealing they were television devices.

The malicious apps employed sophisticated techniques to avoid detection, including the ability to switch operational modes based on whether the television was powered on or off. When an HDMI signal indicated active viewing, the box typically functioned as a residential proxy, routing outside traffic through the household’s internet connection. After the television was turned off, the device would shift to ad-clicking activities, preventing resource-intensive fraudulent activity from interfering with legitimate streaming.

Bitsight researchers mapped 144 websites connected to the operation and discovered that operators used computer vision technology to locate advertisements when webpage layouts changed. A customized version of Google’s Blockly programming tool enabled operators to build and distribute fraud tasks to compromised devices, creating an automated system that generated fake advertising activity without displaying any unusual content on the television screen.

A residential proxy enables third parties to route internet traffic through a normal home connection, causing websites to display the household’s public IP address rather than the visitor’s actual location. While legitimate applications exist for this technology, criminals exploit it to conceal the origins of their online activities. The FBI has previously warned that compromised streaming devices and connected electronics can provide criminals with access to residential proxy networks, with malware arriving either preinstalled or through unofficial applications.

Google clarified that the affected devices are based on Android Open Source Project code rather than Google’s official Android TV OS or Play Protect certified devices. The technology giant stated that uncertified devices lack recorded security and compatibility test results in its systems and do not receive the same protective measures as certified products.

Bitsight acknowledged that the available data covers only certain older models reporting to the expired domain, and researchers could not definitively determine at which point in the supply chain the malicious software was introduced. The findings do not establish that every H96 device contains the fraudulent applications, as an original equipment manufacturer, reseller or custom firmware provider may have added the software before distribution to consumers.

Consumers should verify their streaming device’s exact brand and model number by checking labels on the device or reviewing purchase receipts and order history. Users can determine Play Protect certification status by opening the Google Play Store on the device, selecting the profile icon, and navigating to Settings followed by About to check for certification documentation.

Security experts recommend purchasing streaming devices from established manufacturers that provide regular security updates and customer support. Consumers should avoid unfamiliar brands promising free access to paid content and products advertised as “fully loaded” or “unlocked,” which may indicate unauthorized software modifications. Installation instructions requesting that users disable Google Play Protect or remove Google’s official app store should be treated as warning signs, as these steps bypass critical security safeguards.

If a streaming box is suspected of containing malicious software, users should unplug the device and disconnect its internet connection immediately. A factory reset may remove apps installed after purchase but typically cannot eliminate malware built into the original firmware. Experts recommend replacing suspicious devices with certified alternatives rather than attempting repairs, and advise against selling or donating potentially compromised equipment.

Router administration pages should be checked to review connected devices and remove unfamiliar entries. Users should change their Wi-Fi password using a password manager to generate a strong, unique credential, then reconnect trusted devices with the new authentication details. When routers support the feature, connecting streaming boxes and smart devices to a separate guest or IoT network creates additional isolation from computers and sensitive personal devices on the primary network.

Users can monitor for suspicious activity by reviewing bandwidth usage patterns through their router or internet provider’s application for unexpected overnight traffic or unfamiliar devices. Strong antivirus software on connected computers and phones, along with current operating systems and security applications, can detect malicious downloads and suspicious network communications originating from compromised devices.

The FBI requests that consumers report suspected compromised devices through the Internet Crime Complaint Center at IC3.gov, providing the device’s brand, model, seller information, and documentation of any suspicious applications or network activity. Users should preserve purchase receipts and capture screenshots of unusual behavior before disconnecting potentially infected equipment.

Share this story:


✉️ Email


💬 Text