Low-cost Android TV boxes are at the center of a cybersecurity concern, as highlighted by a recent study conducted by Bitsight. These devices are reportedly equipped with applications that modify their hardware identity to impersonate well-known smartphone brands like Samsung, Huawei, and Xiaomi. This manipulation allows them to engage in ad-click fraud, benefiting operators running these fraudulent sites.
Key Findings of the Fuyao Operation
The fraudulent activities, dubbed the Fuyao operation, have been linked to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. The applications embedded in these TV boxes perform a dual function. When they detect an HDMI signal, they transform the device into a SOCKS5 proxy, channeling external traffic through the owner’s internet connection. Once the HDMI signal ceases, the devices revert to executing ad-related tasks.
Bitsight unearthed this operation by acquiring an expired domain used as a backdoor by the factory. The domain collected telemetry data, revealing that most devices identified were the model H96_MAX_V11. However, this view was limited to older models from a single brand, indicating that the full range of affected models remains unknown.
Technical Insights and Revenue Implications
In a single day, the sinkhole set up by researchers logged 65,957 reports from approximately 38,000 unique MAC addresses, although the actual number of devices remains uncertain due to the ability to change spoofed identifiers. In addition, Zhejiang Fengwo’s marketing of over 120,000 ‘AI digital humans’ complicates the understanding of the operation’s scale. Nevertheless, these figures are not directly comparable and do not clarify the physical size of the device fleet.
The command-and-control server associated with the operation sends complete smartphone profiles to each device, customizing configurations and concealing hardware identifiers. Machine vision technology is employed within the operation to pinpoint advertisements, using a YOLOv8s object-detection model trained on various screen elements.
Attribution and Broader Implications
Bitsight’s analysis connected the operation to Zhejiang Fengwo through shared TLS certificates, wiki files, email addresses, and revenue pathways. Chinese patent documents further identify Zhejiang Fengwo as the holder of patents related to digital-human execution and monitoring technologies, although these do not directly link the company to the Fuyao operation or ad fraud activities.
Current guidance for device owners remains general, advising verification of Play Protect certification and disconnection of suspicious devices. The FBI has also issued recommendations to assess connected devices and maintain updated firmware. With Bitsight’s ongoing investigation, there is a clear need for greater transparency and detailed identification guidance to address the risks posed by these budget Android TV boxes.
