Cheap Android TV boxes may be covertly clicking ads and routing traffic
Security researchers discovered that low-cost Android TV boxes can masquerade as smartphones, visit AI-generated sites and click ads, turning homes into residential proxies.
Bitsight threat analyst Pedro Falé uncovered a scheme in which cheap Android TV boxes, especially older H96 Max V11 models, install covert software that disguises the device as a smartphone and visits AI-generated websites to click ads. The operation, named Fuyao Enterprise, can also turn the box into a residential proxy, routing third-party traffic through the home’s internet connection when the TV is in use, and switching to ad-fraud activity when the screen is off.
The researchers linked the network to Zhejiang Fengwo IoT Technology Co., Ltd., operating under the Fengwo Group, based on shared digital certificates and internal files. Google explained that the affected devices are AOSP-based and lack Play Protect certification, meaning they are not covered by Google’s security checks. The FBI has warned that compromised streaming devices can be used for proxy networks, separate from its BADBOX 2.0 probe. Users should check device model numbers, confirm Play Protect status, avoid unofficial app stores, and consider replacing or isolating any suspect box.
Why it matters
Infected streaming boxes can hijack home internet for fraud, exposing users to hidden data usage and security risks.
In this story
