TechNewsReel
Live

Generic TV Streaming Sticks Used in Massive AI-Driven Ad Fraud Operation

Research reveals H96 devices spoof mobile phones to generate illicit ad revenue for a China-based firm.

TechNewsReel Newsroom · August 9, 2026

Low-cost TV streaming sticks are being weaponized as part of a sophisticated ad fraud network that spoofs mobile devices to siphon advertising dollars. Research from cybersecurity firm Bitsight has identified these generic devices as key nodes in an operation that generates tens of thousands of dollars in daily illicit revenue.

The investigation centered on the H96 brand of streaming sticks, which Bitsight identified as a primary source of traffic for the fraud network. These devices are programmed to spoof themselves as mobile phones to click ads on sham, AI-generated websites. These sites and the associated apps are operated by Zhejiang Fengwo IoT Technology Ltd, also known as the Fengwo Group, a company founded in 2019 in mainland China.

To scale the operation, the Fengwo Group utilizes a proprietary implementation of Google's Blockly visual programming language. This allows low-skilled operators to quickly construct fraudulent websites and automate the routines used to trigger ad clicks. Bitsight tracked approximately 38,000 devices communicating with a single expired domain, leading to a conservative estimate that the operation earns nearly $50,000 per day in ad fraud revenues.

The Dual-Purpose Botnet

The operation is particularly insidious because the devices change their behavior based on the user's activity. According to the research, the sticks monitor the HDMI signal: when the TV is on, the devices act as residential proxies, renting out the user's internet connection to third parties. When the TV is turned off, the devices switch roles to perform the ad fraud tasks.

"Multiple devices reporting to this factory Android TV Box backdoor were ‘phones,’" said Pedro Falé, a threat researcher at Bitsight, highlighting the deceptive nature of the traffic.

Industry Implications

This discovery marks a significant evolution in IoT botnets. While previous threats typically focused on Distributed Denial of Service (DDoS) attacks or simple proxying, this network leverages AI-generated content and mobile spoofing to create high-revenue streams. It demonstrates how attackers are now integrating multiple monetization strategies—residential proxy rentals and ad fraud—into a single piece of consumer hardware.

Consumer Risks

The findings underscore the persistent danger of "off-brand" hardware. Many of these low-cost boxes promise unlimited content for a one-time fee and run unofficial versions of Android. Despite long-standing warnings from security experts and the FBI regarding the insecurity of these devices, they remain widely available on major e-commerce platforms, including Amazon and Best Buy.

Moving forward, security researchers are monitoring the extent of the Fengwo Group's reach. While the company has claimed to possess 120,000 "AI digital humans," analysts suggest this may be a marketing facade designed to mask the actual size and nature of their botnet. Users are urged to avoid generic streaming hardware in favor of verified, secure alternatives.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.