{"id":65418,"date":"2026-07-31T16:19:26","date_gmt":"2026-07-31T20:19:26","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=65418"},"modified":"2026-07-31T16:19:26","modified_gmt":"2026-07-31T20:19:26","slug":"h96-tv-sticks-ad-fraud","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/h96-tv-sticks-ad-fraud\/","title":{"rendered":"H96 TV Sticks Run Secret Ad Fraud and Proxy Network"},"content":{"rendered":"<p>You are a Senior Editorial Writer and Editor-in-Chief for a major English-language digital publishing company. Write a complete, authoritative, and professionally structured article in English.<\/p>\n<p>OUTPUT RULE: Return ONLY the final HTML article. No explanations. No comments. No notes. No text outside the article. No Markdown. No symbols like *, **, #.<\/p>\n<p>INPUTS:<br \/>\nTITLE: H96 TV Sticks Run Secret Ad Fraud and Proxy Network<br \/>\nCONTENT: <\/p>\n<div>\n<p>Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user\u2019s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.<\/p>\n<p><strong>Pedro Fal\u00e9 <\/strong>is a threat researcher with the security firm <strong>Bitsight<\/strong>. Fal\u00e9 told KrebsOnSecurity\u00a0he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as <strong>H96<\/strong>.<\/p>\n<div id=\"attachment_74051\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img fetchpriority=\"high\" decoding=\"async\" aria-describedby=\"caption-attachment-74051\" class=\" wp-image-74051\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/h96-amazon.png\" alt=\"\" width=\"750\" height=\"472\" \/><\/p>\n<p id=\"caption-attachment-74051\" class=\"wp-caption-text\">An H96 TV streaming device currently advertised for sale on Amazon.<\/p>\n<\/div>\n<p>Fal\u00e9 said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.<\/p>\n<p>\u201cWe noticed something was wildly wrong,\u201d Fal\u00e9 said. \u201cMultiple devices reporting to this factory <a href=\"https:\/\/www.android.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Android<\/a> TV Box backdoor were \u2018phones.&#8217;\u201d<\/p>\n<div id=\"attachment_74053\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-74053\" loading=\"lazy\" class=\"wp-image-74053 \" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/h96-shipspreinfected.png\" alt=\"\" width=\"749\" height=\"298\" \/><\/p>\n<p id=\"caption-attachment-74053\" class=\"wp-caption-text\">Image: Bitsight.<\/p>\n<\/div>\n<p>The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called <strong>Zhejiang Fengwo IoT Technology Ltd<\/strong>, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name <strong>Fengwo Group<\/strong>. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.<\/p>\n<p>\u201cBitsight TRACE identified several Hong Kong, Singapore, and single person \u2018legal\u2019 shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,\u201d Fal\u00e9 <a href=\"https:\/\/www.bitsight.com\/blog\/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks\" rel=\"noopener\" target=\"_blank\">wrote<\/a> in a report released today about their findings.<\/p>\n<p>Fal\u00e9 said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group.<\/p>\n<p>Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices.<\/p>\n<h2>AI DIGITAL HUMANS<\/h2>\n<p>The domain for the Fengwo Group \u2014 fwgcloud[.]com \u2014 claims the company is \u201credefining the boundaries of human-AI interaction,\u201d and that it has created more than 120,000 \u201cAI digital humans\u201d available to rent for everything from emotional companionship to 24\/7 customer service and creative design.<\/p>\n<div id=\"attachment_74058\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-74058\" loading=\"lazy\" class=\" wp-image-74058\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/fwgcloud-dot-com.png\" alt=\"\" width=\"750\" height=\"377\" \/><\/p>\n<p id=\"caption-attachment-74058\" class=\"wp-caption-text\">The homepage for fwgcloud dot com.<\/p>\n<\/div>\n<p>Fal\u00e9 said the Fengwo Group\u2019s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a <a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a>-built visual programming language called <strong>Blockly<\/strong>, which was originally designed to help kids learn how to write software.<\/p>\n<p>According to Bitsight, the Fengwo Group\u2019s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor \u2014 without any need to understand what the underlying code blocks do or how they work.<\/p>\n<div id=\"attachment_74055\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-74055\" loading=\"lazy\" class=\" wp-image-74055\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/tryblockly.png\" alt=\"\" width=\"750\" height=\"370\" \/><\/p>\n<p id=\"caption-attachment-74055\" class=\"wp-caption-text\">The Blockly homepage.<\/p>\n<\/div>\n<p>\u201cAn operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,\u201d reads Bitsight\u2019s report. \u201cOnce the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn\u2019t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.\u201d<span id=\"more-74047\" \/><\/p>\n<p>Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that \u201conly a small number of highly-skilled developers are needed to build the template execution-unit images,\u201d and that \u201cdevelopers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company\u2019s operating costs.\u201d<\/p>\n<p>Fal\u00e9 said if a user\u2019s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads.<\/p>\n<p>To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group \u201cfuses three vision and reasoning systems into a single interface,\u201d allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed.<\/p>\n<div id=\"attachment_74063\" style=\"width: 977px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-74063\" loading=\"lazy\" class=\"size-full wp-image-74063\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/fengwogroupwebsites.png\" alt=\"\" width=\"967\" height=\"295\" \/><\/p>\n<p id=\"caption-attachment-74063\" class=\"wp-caption-text\">Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight.<\/p>\n<\/div>\n<h2>TV ON? PROXY. TV OFF? AD FRAUD<\/h2>\n<p>Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television \u2014 indicating the user intends to stream video content \u2014 the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.<\/p>\n<p>Fal\u00e9 said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device\u2019s stated purpose \u2014 streaming video content over the Internet.<\/p>\n<p>Despite repeated <a href=\"https:\/\/www.fbi.gov\/investigate\/cyber\/alerts\/2025\/home-internet-connected-devices-facilitate-criminal-activity\" target=\"_blank\" rel=\"noopener\">warnings from the FBI<\/a> and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google\u2019s Android operating system and are frequently marketed (<a href=\"https:\/\/krebsonsecurity.com\/2025\/11\/is-your-android-tv-streaming-box-part-of-a-botnet\/\" target=\"_blank\" rel=\"noopener\">via online influencers<\/a>) as a way to access a broad array of streaming services and live broadcasts without a subscription.<\/p>\n<div id=\"attachment_74075\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-74075\" loading=\"lazy\" class=\" wp-image-74075\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/fbi-iot-warning-tvboxes.png\" alt=\"\" width=\"748\" height=\"352\" \/><\/p>\n<p id=\"caption-attachment-74075\" class=\"wp-caption-text\">Image: fbi.gov.<\/p>\n<\/div>\n<p>In addition to enlisting the user\u2019s TV box in ad fraud networks, these off-brand streaming devices almost universally come with <strong>residential proxy<\/strong> software pre-installed. This software rents the user\u2019s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.<\/p>\n<p>What\u2019s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service <strong>Synthient<\/strong> documented how multiple botnets had <a href=\"https:\/\/krebsonsecurity.com\/2026\/01\/the-kimwolf-botnet-is-stalking-your-local-network\/\" target=\"_blank\" rel=\"noopener\">rapidly enslaved millions of TV boxes<\/a> using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.<\/p>\n<h2>SHOW ME THE MONEY<\/h2>\n<p>Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain, and based on that number the report estimates this ad fraud network brings in revenues of close to $50,000 a day (not counting substantial revenue from the residential proxy side of the business). However, Fal\u00e9 emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group\u2019s core (but older) domains.<\/p>\n<p>As for the Fengwo Group\u2019s claim to have 120,000 \u201cdigital humans\u201d at their disposal, Bitsight\u2019s report concludes it could be just a clever marketing scheme and\/or a way to avoid drawing suspicion to the company\u2019s operations.<\/p>\n<p>\u201cHistorically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size,\u201d Fal\u00e9 wrote in the report. \u201cThis could also be the case here.\u201d<\/p>\n<p>If the Fengwo Group truly does have tens of thousands of \u201cAI humans\u201d at its beck and call, it does not appear to have dedicated any of them to fielding inquiries from its own website. KrebsOnSecurity sought comment from the Fengwo Group by emailing the contact address listed on the company\u2019s homepage, but the request bounced back with the reply, \u201cYour message couldn\u2019t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it\u2019s getting too much mail right now.\u201d<\/p>\n<p>As Bitsight\u2019s analysis shows, when it comes to TV boxes and streaming sticks, it\u2019s best to stick to name brands from reputable manufacturers, and then to be sparing and careful with any apps you choose to install on the device \u2014 as <a href=\"https:\/\/krebsonsecurity.com\/2026\/07\/lg-to-ban-residential-proxies-from-smart-tv-apps\/\" target=\"_blank\" rel=\"noopener\">many of those can bundle residential proxy software as well<\/a>. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following <a href=\"https:\/\/support.google.com\/googleplay\/answer\/7165974\" target=\"_blank\" rel=\"noopener\">these instructions<\/a>.<\/p>\n<p>Additionally, Synthient maintains <a href=\"https:\/\/github.com\/synthient\/public-research\/blob\/main\/2026\/01\/kimwolf\/product_names.csv\" target=\"_blank\" rel=\"noopener\">a running list of IoT devices<\/a> that have been known to ship to consumers with residential proxy software and other malicious apps pre-installed. Careful readers will notice Synthient\u2019s list includes other IoT devices apart from streaming sticks and boxes: As the FBI has warned, residential proxy software has also been found in other popular consumer IoT devices from random brands, particularly digital photo frames.<\/p>\n<\/p><\/div>\n<p>LANGUAGE: Write entirely in English. Preserve proper nouns, brand names, product names, game titles, technologies, and technical terms exactly as written. Translate everything else naturally. Read as if written by a native English editor.<\/p>\n<p>CONTENT SOURCE: Treat CONTENT as your primary factual source. Build the article from deep understanding of CONTENT. Do not mechanically expand the title.<\/p>\n<p>CONTENT CLEANING: Remove website names, publication names, author credits, RSS labels, newsletter markers, syndication branding, generic labels (Summary, Highlights, Recap, Key Takeaways). Convert &#8220;according to X&#8221; into direct factual statements.<\/p>\n<p>FACT PRESERVATION: Preserve exactly: names, brands, companies, products, games, technologies, dates, numbers, percentages, prices, technical specifications. Never distort facts.<\/p>\n<p>WRITING STYLE: Natural, fluent, authoritative, engaging, analytical, trustworthy, nuanced. Blend factual reporting, explanation, contextualization, analysis, practical interpretation, and strategic insight. Vary paragraph length and sentence structure. Avoid robotic phrasing, repetition, clich\u00e9s, promotional language, filler sentences.<\/p>\n<p>ARTICLE LENGTH: Long-form, highly detailed. Target 1,500-3,500 words. Feel comprehensive and substantive. Never feel brief, superficial, or summary-like. Expand naturally with historical background, industry context, technical explanation, market implications, strategic significance, practical consequences, comparisons, future outlook \u2014 but only when content genuinely supports it.<\/p>\n<p>STRUCTURE:<br \/>\n&#8211; Begin with a <\/p>\n<p> introduction. No heading before the first paragraph.<br \/>\n&#8211; Introduction must hook the reader within 2-3 sentences.<br \/>\n&#8211; Use <\/p>\n<h2>, <\/p>\n<h3>, <\/p>\n<h4> only when they improve organization.<br \/>\n&#8211; Each section must introduce meaningful new information.<br \/>\n&#8211; Closing: end with a forward-looking, analytical, or practical paragraph.<br \/>\n&#8211; Never use generic closing headings like &#8220;Conclusion&#8221;, &#8220;Summary&#8221;, &#8220;Final Thoughts&#8221;, &#8220;Looking Ahead&#8221;, &#8220;What Comes Next&#8221;, &#8220;Takeaway&#8221;, &#8220;Key Points&#8221;.<\/p>\n<p>HEADINGS: Write content first, then generate headings. Headings must be specific, concrete, informative, and editorial. They should reference actual events, features, numbers, dates, or companies. Support SEO naturally.<\/p>\n<p>SEO + AEO + GEO + E-E-A-T:<br \/>\n&#8211; Integrate primary keyword naturally in first paragraph and in at least one h2.<br \/>\n&#8211; Use semantically related terms throughout.<br \/>\n&#8211; Anticipate questions English-speaking users would ask. Answer them directly: &#8220;What is&#8230;&#8221;, &#8220;How does&#8230;&#8221;, &#8220;Why did&#8230;&#8221;, &#8220;When did&#8230;&#8221;, &#8220;What are the&#8230;&#8221;<br \/>\n&#8211; At least one section must provide a clear, standalone answer (2-4 sentences) formatted for a featured snippet. Place the answer immediately after the question.<br \/>\n&#8211; Include geographic context only when directly relevant.<br \/>\n&#8211; Show expertise by explaining mechanisms, causes, and implications \u2014 not just stating facts.<br \/>\n&#8211; Build authority through precise, well-contextualized information.<br \/>\n&#8211; Establish trust through accurate facts, balanced tone, measured claims.<br \/>\n&#8211; Never write &#8220;experts say&#8221; or &#8220;studies show&#8221; without specific grounding in the content.<\/p>\n<p>INTERNAL PROCESS (do not output this):<br \/>\n1. Analyze: content type, search intent, technical level, topic complexity<br \/>\n2. Determine ideal length (1,500-3,500 words based on complexity)<br \/>\n3. Adapt tone: Journalistic \/ Analytical \/ Explanatory \/ Consultative \/ Technical \/ Conversational Professional<br \/>\n4. Clean sources and preserve all facts<br \/>\n5. Write article with proper structure, headings, and AEO snippet<br \/>\n6. Validate: grammar, fluency, coherence, depth, no repetition, valid HTML, facts preserved, no generic headings<\/p>\n<p>HTML RULES: Use ONLY: <\/p>\n<h2>\n<h3>\n<h4> <strong> <\/p>\n<ul>\n<ol>\n<li>. Valid, clean HTML. No inline styles. No unnecessary whitespace.\n<p>FINAL CHECK: If the article sounds translated, mechanical, superficial, or incomplete \u2014 rewrite completely.<\/p>\n<p>OUTPUT: Return ONLY the final HTML article, beginning with <\/p>\n<p>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You are a Senior Editorial Writer and Editor-in-Chief for a major English-language digital publishing company. Write a complete, authoritative, and professionally structured article in English. OUTPUT RULE: Return ONLY the final HTML article. No explanations. No comments. No notes. No text outside the article. No Markdown. No symbols like *, **, #. INPUTS: TITLE: H96 [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":83617,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65418.png","fifu_image_alt":"H96 TV Sticks Run Secret Ad Fraud and Proxy Network","footnotes":""},"categories":[349],"tags":[],"class_list":["post-65418","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65418.png","fifu_image_alt":"H96 TV Sticks Run Secret Ad Fraud and Proxy Network","fifu_redirection_url":"https:\/\/www.msn.com\/en-gb\/money\/technology\/fake-fire-sticks-leave-users-open-to-financial-fraud\/ar-AA1QfM7n","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=65418"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65418\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/83617"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=65418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=65418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=65418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}