
H96 TV Boxes Run Hidden Ad Fraud and Proxy Scheme
Bitsight researchers found H96 streaming sticks pose as phones to click ads on AI-generated sites and rent out home internet addresses as proxies.
A new analysis from security firm Bitsight shows that H96 TV boxes and similar no-name streaming sticks are being used as a hidden ad fraud and residential proxy network. Security researchers have warned for years that cheap generic TV boxes, sold as a way to watch unlimited content for a one-time fee, secretly rent out the owner's internet connection to strangers. The new report, released on July 30, 2026, adds that these devices also impersonate mobile phones to click ads on AI-generated websites, defrauding online merchants and advertising networks. Pedro Falé, a threat researcher at Bitsight, told KrebsOnSecurity that he peered inside the operation by registering an expired domain name that had been used to coordinate fake ad clicks for the popular H96 brand.
The expired domain had been used for telemetry, meaning it periodically collected full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into televisions around the globe. When Falé inspected the traffic being sent to the domain, he found that nearly all of the TV boxes transmitting data claimed to be mobile phone models from Samsung, Vivo, Huawei, and Xiaomi. He said multiple devices reporting to this backdoor were phones, which was wildly wrong. All of the devices reported having the same two apps installed, and those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China that operates an ad-publishing portfolio under the name Fengwo Group. Bitsight TRACE identified several Hong Kong, Singapore, and single person legal shell identities used to collect the monetization and traced the operation back to Zhejiang Fengwo. The company has registered multiple patents that match the inner workings of these apps.
The apps help coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group. Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music, and food blogs. They also found that none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices. The domain for the Fengwo Group, fwgcloud.com, claims the company is redefining the boundaries of human-AI interaction and that it has created more than 120,000 AI digital humans available to rent for everything from emotional companionship to 24/7 customer service and creative design. Bitsight found that the domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. The domain also hosts an internal wiki platform that ties the Fengwo Group to a proprietary implementation of Google Blockly, a visual programming language originally designed to help children learn software. Fengwo employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in an editor without needing to understand what the code does. An operator can drag blocks together to define each fraud routine for a given task type, and once saved it is exported as JavaScript and uploaded to cloud storage buckets.
When an H96 streaming stick is selected for a specific fraud task, it receives the appropriate Blockly module according to the task desired. These tasks can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads. To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group fuses three vision and reasoning systems into a single interface, allowing the bots to correctly identify an ad on a webpage and navigate the site much like a human would. Bitsight also found that the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. When the TV boxes detect an HDMI signal from an attached television, indicating the user intends to stream video content, the box usually functions as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs. Falé believes the boxes are set up this way because ad fraud activities are far more resource intensive and could interfere with the device's stated purpose of streaming video.
Despite repeated warnings from the FBI and security industry leaders, major e-commerce providers like Amazon, Best Buy, and Newegg continue to sell hundreds of different models and brands that bundle unofficial versions of Google's Android operating system. These devices are frequently marketed, often via online influencers, as a way to access a broad array of streaming services and live broadcasts without a subscription. In addition to enlisting the user's TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user's internet address out to anonymous paying customers, who range from aggressive content scraping firms to ticket scalpers and outright cybercriminals. These generic and generally dirt cheap TV boxes are also horribly insecure by default and lack any kind of authentication, so installing one on a home or office network invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.
Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain. Based on that number, the report estimates this ad fraud network brings in revenues of close to 50,000 dollars a day, not counting substantial revenue from the residential proxy side of the business. Falé emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group's core but older domains. As for the Fengwo Group's claim to have 120,000 digital humans at their disposal, Bitsight's report concludes it could be a marketing scheme, a way to avoid drawing suspicion to the company's operations. Historically, when dealing with proxy services or DDoS, websites sometimes present inconspicuous facades so as not to advertise their botnet size or DDoS capability, and this could be the case here. The company did not respond to a request for comment from KrebsOnSecurity; an email to the contact address listed on its homepage bounced back saying the inbox was full or getting too much mail.
For consumers, the practical advice is to avoid generic TV boxes that promise too much. Stick to name brands from reputable manufacturers, and then be sparing with any apps you install, since many of those can bundle resid
How to Protect Yourself
- Before buying any streaming stick, check the manufacturer and model against Synthient's public list of devices known to ship with hidden proxy or malicious software, and stick to well-known brands with official Android TV OS and Play Protec
- Avoid ultra-cheap or generic TV boxes that promise free access to many streaming services without a subscription, even when they appear on major online stores.
- If you already own an H96 or similar no-name streaming box, unplug it from power and HDMI when you are not watching, and consider replacing it, because it can run ad fraud or proxy tasks whenever it is turned on.
- Review the apps installed on your streaming device and remove any you do not recognize or use, since many third-party apps quietly include residential proxy software.
- Use a secure DNS service on your home network and keep smart devices on a separate guest network if your router supports it, so suspicious internet lookups are easier to spot and contain.
Terms Explained
- residential proxy Software that rents out a person's home internet address to strangers, so those strangers' online activities appear to come from that home.
- telemetry The automatic collection and sending of technical data from a device back to a remote server.
- ad fraud The use of fake clicks or fake visitors to trick advertisers into paying for ads that no real person actually sees.
- Blockly A visual programming tool from Google that lets people build software by dragging blocks together instead of writing code.
- Play Protect Google's built-in security check for Android devices and apps that verifies they have not been tampered with.
- botnet A network of hijacked devices controlled remotely to carry out tasks like clicking ads or sending spam.