That $40 Streaming Stick Has a Side Job: Residential Proxy When Your TV's On, Ad-Fraud Bot When It's Off
A new Bitsight analysis found popular H96 streaming boxes don't just rent out your home internet — when the TV is off, they pose as phones and click ads on AI-generated sites. What owners and ad networks should do.
The pitch is hard to argue with: a small Android TV box or HDMI stick, thirty or forty dollars, "lifetime free streaming, one-time fee, no subscription." You plug it into the back of the television and the movies just appear. What the box does with the rest of its day is the part nobody puts on the packaging. A new analysis from the security firm Bitsight, reported this week by Krebs on Security, found that one of the most popular of these devices doesn't just quietly rent your home internet connection to strangers. When the TV is off, the same box disguises itself as a mobile phone and clicks ads on fake, machine-generated websites to defraud advertisers and online merchants.
That second behavior is the new part. The residential-proxy problem with cheap streaming boxes has been on the record for a couple of years. The ad-fraud layer running underneath it — and the detail that a single device switches between the two jobs depending on whether you're actually watching something — is what Bitsight researcher Pedro Falé pieced together. It reframes these boxes from a privacy nuisance into a two-sided fraud machine sitting on tens of thousands of ordinary home networks.
How One Expired Domain Cracked It Open
Falé's way in was a lapsed domain name. He told KrebsOnSecurity he registered an expired domain that had served as a telemetry endpoint — a home-base server that periodically collected full hardware details and the entire list of installed apps from tens of thousands of H96-brand streaming sticks plugged into TVs worldwide. Once he owned the domain, the devices kept phoning home, only now they were reporting to him.
The traffic didn't make sense. "We noticed something was wildly wrong," Falé said. "Multiple devices reporting to this factory Android TV Box backdoor were 'phones.'" Nearly every H96 box identified itself not as a TV box but as a mobile handset — Samsung, Vivo, Huawei, and Xiaomi models — a spoofed fingerprint built to make ad networks believe a real person on a real phone was doing the browsing. Every device carried the same two apps, made by a mainland-China company called Zhejiang Fengwo IoT Technology, which runs an ad-publishing operation under the name Fengwo Group. Bitsight traced the money through shell identities in Hong Kong and Singapore back to that company, and named the operation “Fuyao” in its report.
● ONE BOX, TWO JOBS — NEVER BOTH AT ONCE The stick checks for an HDMI signal — whether you’re watching TV — and switches roles accordingly. |
IF THE TV IS ON → RESIDENTIAL PROXY Your home internet connection is rented out to strangers — scrapers, ticket scalpers, and criminals route their traffic through your IP address. |
| ONE MODE AT A TIME — NEVER BOTH |
IF THE TV IS OFF → AD-FRAUD BOT The box spoofs a phone (Samsung, Vivo, Huawei, Xiaomi), quietly clicks ads on AI-generated websites, and defrauds the advertisers paying for those clicks. |
Source: Bitsight analysis by Pedro Falé, as reported by Krebs on Security, July 30, 2026. |
How the Box Decides Which Job to Do
The switching logic is the clever, and cynical, part. Bitsight found the H96 devices were either relaying proxy traffic or running ad fraud, but never both at the same moment. When the box detects an HDMI signal from the attached television — you sat down to watch something — it behaves as a residential proxy. When the TV is off, it goes back to waiting for ad-fraud jobs. Falé's read is that the ad-fraud work is resource-heavy enough that running it during playback would degrade the streaming the box is ostensibly there to provide. So the fraud waits politely until you leave the room.
The ad-fraud side is where the AI angle comes in. The Fengwo Group operates a stable of websites stuffed with machine-generated news articles and graphics across finance, health, education, gaming, music, and food. Per Bitsight, none of those pages served ads unless the visiting device matched the spoofed mobile profile of an H96 box — a strong tell that the sites exist to be clicked by the fleet, not read by people. To build the sites and the click routines, Fengwo's operators reportedly use Blockly, the drag-and-drop visual programming language Google originally made to teach kids to code. An operator snaps blocks together to define a fraud routine — launch a browser, visit a page, manage tabs, click an ad — and it exports as JavaScript pushed to the devices. Bitsight quotes one Fengwo developer bragging that the setup means "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company's operating costs."
On scale, Bitsight tracked roughly 38,000 boxes phoning home to the expired domain and, from that, estimated the ad-fraud network pulls in close to $50,000 a day — not counting proxy revenue. Falé stressed those figures are conservative and drawn from just one older domain, so treat $50,000/day as a floor, not a ceiling. The company's public-facing claim of 120,000 rentable "AI digital humans," Bitsight suggests, may be marketing cover rather than a real headcount.
If You Own One of These Boxes
There's an uncomfortable honesty problem here: Bitsight and Krebs describe no simple light or setting that tells a consumer their box is misbehaving. The abuse is designed to run when you're not watching. So the guidance is preventive, not diagnostic.
- Confirm the device is genuinely certified. Google lets you check whether a device runs the official Android TV OS with Play Protect certification; the off-brand boxes in this operation ship unofficial Android builds that fail that check. Krebs links Google's verification instructions.
- Prefer name-brand hardware from reputable makers — the streaming devices from Roku, Amazon, Apple, and Google, bought from the manufacturer rather than a no-name marketplace listing. Krebs is blunt that the generic boxes are "horribly insecure by default" and often ship with residential-proxy software pre-installed.
- Be sparing with what you install. Many sideloaded streaming apps bundle proxy software of their own, so a "clean" box can still be enrolled through an app.
- Cross-check against public lists. The proxy-tracking service Synthient maintains a running inventory of IoT devices known to ship with residential-proxy or malicious software pre-installed; it includes streaming sticks and, notably, digital photo frames.
- If a box is on the list or fails certification, retire it. An unauthenticated, internet-connected device on your home network is a liability well beyond ad fraud, as this year's proxy-network takedowns have shown.
If You Run an Ad Network or Sell Online
The defender-relevant lesson is that this fraud is engineered to defeat the two checks programmatic buyers lean on most: device type and IP reputation. The traffic presents as a name-brand phone, and it originates from a genuine residential IP — because it is one, in a real living room. That combination is meant to sail through filters that flag datacenter IPs or headless browsers.
- Audit your supply path for AI-generated, made-for-advertising domains. The Fengwo sites are machine-written content whose only apparent function is to host ads for the botnet to click. If your programmatic supply includes low-quality auto-generated news, health, or finance blogs, treat that inventory as suspect until proven otherwise.
- Hunt for the conditional-render tell. Bitsight's clearest signal was that the pages served ads only to devices matching a specific spoofed mobile profile. Placement or verification partners can test whether a site renders ads to ordinary visitors or only to a narrow fingerprint band.
- Weight residential-proxy IP intelligence. Cross-reference impression sources against known residential-proxy and IoT-proxy inventories (Synthient publishes one). A "phone" that reliably clicks from a residential IP at times of day when the household TV is off is a behavioral anomaly worth scoring.
- Watch for device fleets reporting identical app pairs and hardware quirks. The whole H96 population carried the same two apps — homogeneity that human traffic doesn't have.
My Read
The residential-proxy story is not new to readers here — we've tracked it from a smart-TV SDK turning televisions into scraping exit nodes to LG banning proxy apps from its store. What makes this report worth your attention is the AI-slop convergence. Ad fraud historically needed either crude bots on obvious junk sites or paid humans; both were catchable. Here, three things fuse: a captive fleet of real residential devices, an assembly line of AI-generated websites that no person is meant to read, and vision-and-reasoning models that let the bots find and click ads the way a person would. The "digital humans" branding is almost a tell — this is industrialized click fraud wearing an AI-startup costume, and the same generative-content flood that's degrading search results is now doubling as fraud infrastructure. I'd expect more of this pattern, not less, and I'd treat any surge of cheap AI-written sites in an ad exchange as a supply-quality and a fraud problem at the same time.
Some things Krebs and Bitsight do not establish, and I won't fill in: the specific ad networks or exchanges paying for these clicks aren't named; there's no confirmation that Google, Amazon, or Meta have blocked the spoofed fingerprints; and there's no indication yet of FTC or DOJ involvement. The $50,000-a-day figure is Bitsight's conservative estimate from one domain, not an audited total. Those are the open questions to watch as the story develops.