Bitsight reveals H96 streaming sticks fuel $50,000 daily ad fraud
Security firm Bitsight discovered a large-scale ad fraud network orchestrated by China-based Fengwo Group using compromised H96 Android-based streaming devices. The infected devices, which also feature residential proxy software, spoof mobile user identities to click on ads hosted on AI-generated websites, generating an estimated $50,000 in daily fraudulent revenue.
Key Takeaways
- Compromised H96 Android-based streaming boxes spoof identities of Samsung, Huawei, and Vivo phones to bypass ad-network detection.
- The operation generates an estimated $50,000 in daily revenue from faked ad clicks on a network of websites built using AI and Google’s Blockly programming language.
- Infected devices act as residential proxy exit nodes when an HDMI signal is detected and switch to ad fraud when the TV is off to maximize resource efficiency.
- Security firm Bitsight identified the mainland China-based Zhejiang Fengwo IoT Technology Ltd as the orchestrator of the 'Fuyao' fraud enterprise.
Why It Matters
This discovery highlights a critical supply-chain vulnerability where off-brand streaming hardware enters major e-commerce channels pre-loaded with malware. For advertisers, it underscores the persistent risk of 'Sophisticated Invalid Traffic' as fraud networks now use computer vision and AI to mimic human browsing behavior on fake sites. The automated nature of these attacks means detection tools must evolve beyond simple script identification. Stakeholders should monitor for increased regulatory pressure on e-commerce platforms like Amazon and Best Buy to vet third-party hardware vendors more rigorously as fraud losses are projected to climb through 2026.
Additional Context
The Bitsight report on the H96 streaming boxes coincides with a broader surge in sophisticated invalid traffic (IVT) targeting the connected TV (CTV) and mobile ecosystems. According to 2026 projections from Juniper Research, global ad fraud losses are expected to reach between $150 billion and $220 billion annually, with programmatic CTV spend being a primary target. Industry data from Fraudlogix in Q1 2026 indicated that fraud rates across desktop, mobile, and tablet have converged at roughly 18%, suggesting that fraud syndicates have matured to the point where they can exploit all screen types with equal effectiveness. This convergence is partly driven by the rise of 'Agentic AI,' which simulates human traits like scrolling and hesitation to bypass legacy defensive filters. Simultaneously, law enforcement has escalated its warnings regarding low-cost IoT devices. In early 2026, the FBI issued a public service announcement (I-031226-PSA) specifically targeting residential proxy misuse and 'Badbox 2.0' malware. Per the FBI, more than one million Android-based streaming boxes have been compromised globally to route illicit traffic through home networks. The FBI advisory specifically flagged brands like VSeeBox and SuperBox for often lacking Google Play Protect certification and shipping with firmware-level backdoors. Similar research by Synthient highlighted how these botnets frequently target affordable, off-brand hardware often marketed by online influencers as 'unlocked' for free access to premium content. In response to these persistent threats, hardware manufacturers are beginning to take more aggressive defensive stances. Per Forbes, July 2026, LG recently moved to ban residential proxy software from its smart TV app ecosystem to prevent its hardware from being enlisted in such networks. This trend mirrors broader industry efforts, where approximately 84% of advertisers now maintain expanded brand safety blocklists to avoid AI-generated 'Made-for-Advertising' (MFA) sites, which according to Spider AF data from 2025, saw a 1,409% year-over-year increase in inventory.
Read full article at krebsonsecurity.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source