Cybersecurity experts have been warning about the risks of generic TV boxes for years. These devices promise unlimited content streaming for a one-time fee, but secretly rent out users’ Internet connections to strangers. Now, a groundbreaking new analysis has uncovered another alarming threat. Not only do these devices rent out your connection, but they also spoof themselves as mobile phones clicking ads on AI-generated websites. This sprawling operation is designed to defraud online merchants and advertising networks.
Pedro Falé, a threat researcher with the security firm Bitsight, discovered this complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across one popular brand of streaming devices known as H96. The domain he registered had previously been used for telemetry, collecting information from tens of thousands of H96 sticks around the globe. But when Falé inspected the traffic being funneled to this domain, he found something disturbing: nearly all of the TV boxes transmitting data claimed to be mobile phone models.
Falé’s investigation revealed that these devices reported having the same two apps installed – both made by a Chinese company called Zhejiang Fengwo IoT Technology Ltd. Further research into this entity showed it has registered multiple patents matching the inner workings of these apps. Bitsight discovered that the operation is complex, using Hong Kong and Singapore shell identities to collect profits before tracing the money back to mainland China.
The H96 devices help coordinate an ad fraud network, clicking ads at AI-generated websites operated by the Fengwo Group. These websites contain machine-generated news articles and graphics across various categories, but only display ads when a device with the spoofed mobile profile of these H96 devices visits the page. This is not just about fake clicks – it’s also about generating real revenue through AI-powered websites that appear to be legitimate.
The Fengwo Group claims to “redefine the boundaries of human-AI interaction” on its domain fwgcloud.com, boasting over 120,000 “AI digital humans” available for rent. But Falé notes that this domain shares SSL certificate data with other domains associated with the H96 devices’ apps and phone spoofing mechanism. The domain also features an internal wiki platform directly tying the Fengwo Group to Blockly, a visual programming language originally designed to help kids learn software development.
The Blockly editor allows low-skilled operators to build the sham websites by dragging blocks of code together without understanding what they do or how they work. This system makes it easy for anyone to create these fake sites and participate in the ad fraud network. Bitsight’s report highlights that only a small number of highly-skilled developers are needed to set up this operation, making it accessible to those who wouldn’t normally have the technical expertise.
The takeaway from this investigation is clear: if you’re considering buying one of these generic TV streaming devices, be aware of the risks involved. Not only do they secretly rent out your connection, but they also participate in ad fraud networks that deceive online merchants and advertising networks. Always research a device’s security features and manufacturer before making a purchase to avoid falling victim to these complex operations.
Source: Krebs on Security — 2026-07-30