Researchers at Bitsight have uncovered a large-scale fraud scheme operating through cheap Android TV boxes sold globally. The devices ship with malicious apps that rewrite their hardware identifiers to pose as Samsung, Huawei, Xiaomi, or Vivo smartphones, then generate fraudulent ad clicks on websites operated by the same actors.
The operation, named Fuyao, traces back to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China-based company founded in 2019. The scheme operates on two fronts. First, the spoofed devices click ads while disguised as premium phones, inflating advertiser costs and generating revenue for the operators through click fraud. Second, the same malicious apps conscript owners' broadband connections into a proxy network, allowing the attackers to route traffic through compromised home internet connections.
This dual-purpose approach targets both advertising networks and internet infrastructure. Device owners remain largely unaware their broadband serves as a relay point for the attackers' activities. The proxy functionality potentially enables the actors to conduct credential stuffing attacks, bypass geographic restrictions, or obscure their own network footprints while engaging in other malicious activities.
The affected devices typically cost between $20 and $40, making them attractive to budget-conscious consumers in developing regions. However, the low price carries hidden costs. Owners experience degraded broadband performance as their connections handle the attackers' traffic. Internet service providers face increased strain from the proxy traffic, and advertisers lose money to artificially inflated click counts.
Bitsight's attribution to Fengwo suggests an organized operation rather than opportunistic malware distribution. The company's founding in 2019 aligns with the scheme's apparent emergence. The rebranding capability indicates sophisticated knowledge of Android's system architecture and permission models.
Users who purchased cheap Android TV boxes from
