Skip to content
Beveiligingsnieuws

Cheap Android TV boxes can turn your broadband proxy

fraude met Android TV-boxen

Cheap Android TV boxes are often marketed as affordable ways to stream movies and apps. But recent research describes a far more troubling use: some devices can alter their identity to look like popular phone models, run ad-fraud tasks, and even relay other users’ traffic through the owner’s internet connection.

According to Bitsight, an operation dubbed Fuyao used compromised boxes that carried apps designed for both deception and misuse. While the exact number of affected models remains incomplete, the technical details show a coordinated workflow: fingerprint spoofing, visual ad detection, remote command delivery, and network behavior changes triggered by HDMI activity.

What the operation did to the devices

Bitsight reports that certain low-cost Android TV boxes shipped with applications that rewrite the device’s hardware identity. Instead of presenting as a streaming box, the apps mimic well-known smartphone models from brands such as Samsung, Huawei, Xiaomi, or Vivo.

From the outside, the apps also appear to help the device behave like a phone during web activity. In practice, researchers observed that devices could click or trigger ads on websites operated by the same campaign operators.

However, the identity spoofing is only part of the story. The same applications also take on a second role tied directly to how the box behaves when connected to a display.

When HDMI is on, the box can become a proxy

One of the most concerning findings is how the devices respond to HDMI signals. Bitsight states that when an HDMI connection is detected, the box typically switches into a mode that relays traffic over the owner’s broadband connection.

In this relaying mode, the box acts as a SOCKS5 exit node, meaning other traffic can be routed through the connection provided by the device owner. Once HDMI is off, the device returns to waiting for ad-fraud tasks.

This behavior implies a direct link between everyday usage—plugging in and powering a display—and the opportunity for the box to be used as part of a broader proxy and fraud infrastructure.

How researchers found the campaign

Bitsight says it identified Fuyao by registering an expired domain used as a kind of factory backdoor and telemetry collector. Researchers then used their “sinkhole” approach to observe what devices reported when they connected to the system.

Bitsight notes that many devices reported a model name H96_MAX_V11. At the same time, the researchers caution that their sinkhole view was biased toward older models from one brand, so it didn’t produce a complete list of affected hardware.

In a single day, after filtering for devices running Fuyao apps, the sinkhole reportedly received 65,957 reports from around 38,000 unique MAC addresses. Importantly, researchers explain that identifiers could be spoofed or rotated, so the report count does not automatically translate into the true fleet size.

Phone masquerading: why the reports often looked like phones

Most of the observed reports described the devices as phones rather than streaming boxes. Bitsight emphasizes that this is not a confirmed inventory of physical devices, since the system can rotate identifiers to appear as different clients.

So while the telemetry is useful for understanding behavior, it doesn’t give a definitive “how many boxes are out there” answer. It does, however, align with the described identity rewriting: the device wants to be treated like a phone by the operators’ systems.

How remote control and profiles were delivered

Bitsight describes a command-and-control approach where a server pushes complete phone profiles to each device. The mechanism blends a base configuration with a per-model “diff,” while also deleting properties that could reveal the underlying chipset platform.

Specifically, the researchers mention that the system removes indicators that could expose board families associated with chips such as Rockchip, Amlogic, or Allwinner. The goal is to make the device look consistent with a particular phone target profile.

This kind of per-model tailoring suggests the operators were not relying on a single generic configuration. Instead, they appear to have built a system intended to scale across different hardware variants.

Ad fraud automation: machine vision and app permissions

Fuyao includes a workflow for detecting where ads appear on the screen. Bitsight says the operation uses machine vision internally to locate ad placements.

The Script app contains a YOLOv8s object-detection model named lourui_2. The model was trained using 12 screen elements, including generic banner regions and specific ad widgets associated with Taboola.

To improve detection, the app combines visual detection with Android accessibility data and also uses optical character recognition through Google ML Kit. Bitsight’s researcher describes this as fusing multiple vision and reasoning components into a single interface.

Building and scaling campaigns with a visual editor

Instead of requiring operators to code everything from scratch, Bitsight says campaign logic was assembled in a custom editor built on Blockly, Google’s drag-and-drop framework.

After creation, the operators export each fraud routine as JavaScript, upload it to S3, and then send it to the box for execution. This design would allow a smaller group of skilled engineers to provide templates, while other operators focus on routine campaign tasks.

In testing of a limited set of devices, Bitsight captured about 40 fraud tasks, 21 unique campaigns, and 166 unique modules. Even with a small sample size, the variety of modules indicates a modular framework rather than a single-purpose script.

Revenue chain and related networks

Bitsight reports that payout and tracking appear to flow through a publishing network. Researchers mapped 144 operator-owned domains across seven beneficiary clusters. At least 84 of those domains loaded a Taboola tag on the homepage.

The report also states that the team used Taboola’s public sellers.json file to connect domains to revenue-collecting entities based in Hong Kong and Singapore. This is presented as a linkage method, not direct proof of a single operator’s internal accounting.

Bitsight modeled gross returns at about $1.25 per device per day. Under a scenario where roughly 38,000 devices were active, the model suggests about $47,500 daily. The researchers also estimated annual revenue could be as high as $40 million at an advertised fleet size, citing assumptions about fraud flagging and ad-fill rates.

Crucially, Bitsight frames these as estimates, not observed confirmed earnings.

Attribution: where the research points, and what’s not proven

Bitsight attributes the operation to Zhejiang Fengwo IoT Technology Co., Ltd., citing shared TLS certificate data, exposed wiki files, reused email addresses, revenue links, and patents.

The reporting also references Chinese patent records that independently identify Zhejiang Fengwo as the assignee of related technologies involving “digital human” execution and monitoring. However, those filings reportedly do not describe advertising, and they do not establish that the company personally operated Fuyao or participated in ad fraud.

Additionally, the sources checked do not confirm who installed the apps, or at what point in the device supply chain those apps appeared. In other words, attribution supports a likely connection, but it does not complete every missing step in how devices reached end users.

What Google and the FBI advise owners to do

Google states that these off-brand devices were not Play Protect certified Android devices. According to Google, Play Protect certification means Google has records of security and compatibility testing results, and that without certification Google doesn’t have comparable test records for the device.

Google points users to its Android TV partner list and suggests using available steps to verify whether a device is Play Protect certified and intended for Android TV OS.

In parallel, the FBI advised in June 2025 that owners should assess connected devices, disconnect suspicious ones, keep firmware up to date, and treat generic streaming boxes sold on promises of free content as suspect.

Practical checklist before you buy or keep one

If you’re considering an inexpensive streaming box, or you already own one, these steps can reduce risk:

  • Verify Play Protect certification and check whether the device is meant for Android TV OS.
  • Keep firmware current and avoid devices that do not provide updates.
  • Be cautious with “too good to be true” content claims, especially when the product is marketed as free entertainment.
  • Watch for suspicious behavior such as unexpected network activity, unusual advertisements, or repeated prompts.
  • Disconnect immediately if you suspect compromise, then re-check settings and software sources.

Because Fuyao-style behavior can switch modes based on HDMI signals, everyday viewing may coincide with risky network activity in the background.

Conclusion: cheap Android TV boxes can expose your network

The Fuyao investigation highlights how some cheap Android TV boxes can go beyond simple streaming: they can spoof phone identities, execute ad-fraud routines using machine vision, and—when an HDMI signal is present—relay traffic through the owner’s broadband connection as a SOCKS5 exit node.

Even though the affected model list is not fully complete, the described techniques show a sophisticated operation. For buyers and owners alike, verifying Play Protect certification, keeping devices updated, and treating low-cost “free content” claims with skepticism are practical steps to protect both your viewing experience and your internet connection.

Source: https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html