Security firm Bitsight has identified a large-scale ad fraud operation, dubbed Fuyao, which utilizes generic H96 TV streaming sticks. These devices are configured to mimic mobile phones, such as Samsung, Huawei, Xiaomi, or Vivo models, to generate fraudulent ad clicks on AI-generated websites. The operation is attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a company founded in mainland China in 2019.
Beyond ad fraud, the H96 devices serve a second purpose. When an HDMI signal is detected, the devices switch to relaying other users' internet traffic, functioning as SOCKS5 proxy exit nodes. When the HDMI signal is off, they revert to ad-fraud tasks. This dual functionality allows the operators to monetize the devices through both fraudulent advertising revenue and by selling access to the users' broadband connections.
Bitsight threat researcher Pedro Falé discovered the operation by registering an expired domain name previously used for telemetry. This domain collected full hardware information and lists of installed applications from tens of thousands of H96 streaming sticks globally. The sinkhole received 65,957 reports from approximately 38,000 unique MAC addresses in one day, with most devices reporting themselves as mobile phones.
The operation exposes users of these generic streaming devices to significant security risks, including unauthorized data collection and the misuse of their internet bandwidth. For online advertising networks and merchants, it represents a form of ad fraud that can distort advertising metrics and lead to financial losses. The most identifiable devices reported the model name H96_MAX_V11, though Bitsight noted its view was skewed towards older models from one brand.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Bitsight researchers identified an operation named Fuyao, attributed to Zhejiang Fengwo IoT Technology Co., Ltd., where cheap Android TV boxes are shipped with software that rewrites their hardware identity to mimic phones. These devices then engage in ad fraud and turn owners' broadband into SOCKS5 proxy exit nodes when an HDMI signal is detected. This activity highlights a new method of ad fraud and network abuse leveraging consumer hardware.
A Bitsight analysis revealed that H96 TV streaming sticks are part of a widespread ad fraud operation, spoofing mobile phones to click ads on AI-generated websites and secretly collecting user hardware information and installed app lists. This matters because it exposes a significant security vulnerability and fraudulent activity within generic streaming devices, impacting online advertising networks and user privacy.