Back to Feed
MalwareAug 3, 2026

H96 Android TV Boxes Used for Ad Fraud and Residential Proxies

H96 Android TV boxes found with Fuyao software for ad fraud and residential proxies.

Summary

Security researchers discovered that some inexpensive H96 Android TV boxes come pre-installed with Fuyao software. This software can disguise the devices as smartphones, generate fraudulent ad clicks, and route other users' internet traffic through the owners' home connections, effectively turning them into residential proxies.

Full text

Security AndroidH96 Android TV Boxes Used for Ad Fraud and Residential Proxies Bitsight found Fuyao software on H96 Android TV boxes, letting operators fake ad clicks and route proxy traffic through their owners’ home internet connections. byWaqasAugust 3, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Some inexpensive Android TV boxes were shipped with preinstalled software capable of disguising the devices as smartphones, clicking online advertisements, and routing other people’s internet traffic through owners’ home connections, according to new research from Bitsight. Bitsight researcher Pedro Falé identified the operation while examining factory backdoors left active on consumer streaming boxes. After registering an expired domain previously used for device management and telemetry, researchers began receiving hardware details and lists of installed applications from connected boxes. Among those reports, many devices reported themselves as smartphones from Samsung, Huawei, Xiaomi, Vivo, and other manufacturers. Their installed packages, hardware properties, and television launchers showed they were Android TV boxes whose identities had been rewritten. Bitsight named the operation Fuyao and found its applications mostly on devices reporting the model H96_MAX_V11. However, the company warned that its visibility was concentrated on older boxes from one brand, meaning the findings do not provide a complete list of affected products. During one 24-hour observation period, researchers received 65,957 reports associated with about 38,000 unique MAC addresses running Fuyao applications. Bitsight noted that identity rotation could cause the MAC address count to exceed the number of physical devices. (Credit: Bitsight) Evidence from installation paths and application privileges indicated that Fuyao was preinstalled on some devices or embedded in modified firmware. Bitsight said distribution may have involved device customisation, reseller firmware, or unofficial ROM images offered for download. Once connected, Fuyao could rewrite device properties and present a television box as a higher-value smartphone. The software then opened websites controlled by the operators, viewed advertisements and clicked them to generate payments from advertising networks. To make the activity resemble human browsing, Fuyao used Android accessibility data, optical character recognition and a YOLO computer vision model trained to identify page elements, including advertisements and Taboola recommendation widgets. Its tasks could scroll through pages, simulate reading time, select different browsers, close tabs and clear browser caches. Furthermore, operators built those routines using a customised version of Blockly, a visual programming system commonly used to teach children how to code. Dragging blocks together allowed workers with limited technical knowledge to prepare new advertising campaigns without writing each routine from the beginning. While a television was in use, the software could operate the box as a SOCKS5 residential proxy. Traffic from customers of a proxy service would then leave through the device owner’s home internet address, making it appear to originate from an ordinary residential connection. When the HDMI connection was inactive, the box could return to advertising tasks. Bitsight’s research also found that one in six observed Fuyao boxes overlapped with its residential proxy data during 24 hours. Over seven days, the overlap increased to one in four devices. The applications could also send logs and screenshots to command servers and livestream their virtual screen through WebRTC. Researchers linked Fuyao to Zhejiang Fengwo IoT Technology Co., Ltd., part of the mainland China-based Fengwo Group. Their evidence included shared certificates, exposed internal files, reused email addresses and company patents that matched functions found in the Fuyao applications. Fengwo advertised a network of more than 120,000 “AI digital humans,” but Bitsight did not independently confirm that figure. Its verified sample covered about 38,000 unique MAC addresses, with the company cautioning that this was not a reliable count of individual boxes. Ad clicks and impressions are generated by a globally distributed device fleet operating through registered publisher accounts (Credit: Bitsight) Anyone using an affected H96 device should consider disconnecting it and replacing it with hardware receiving authenticated firmware updates from its manufacturer. A factory reset may reinstall the same unwanted applications when they are embedded in the device firmware. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts AndroidAndroid TVBackdoorsBitSightCybersecurityFuyaoH96MalwareProxyResidential Proxy Leave a Reply Cancel reply View Comments (0) Related Posts Read More Hacking News Anonymous Security Anonymous & its affiliates hacked 90% of Russian misconfigured databases A new report reveals that since the Russian attack on Ukraine, Anonymous and its affiliate groups have compromised… byWaqas Read More Android Malware Security New RadzaRat Spyware Poses as File Manager to Hijack Android Devices Certo Software found RadzaRat, an Android RAT disguised as a file manager that has a 0/66 detection rate on VirusTotal. It keylogs passwords and steals files. byDeeba Ahmed Read More Security “Dirty COW”, the most dangerous Linux Bug for the last 9 years For the Past 9 Years, Linux Kernel has been Plagued with Dirty Cow – A Privilege-Escalation Bug Red… byUzair Amir Read More News Security Technology List of Proxy IPs Exposed to Block Killnet’s DDoS Bots Kallnet is a pro-Russian group known for targeting hospitals and other critical infrastructure in countries unfriendly to Russia byWaqas

Entities

H96 Android TV Boxes (product)Fuyao (product)Bitsight (vendor)Zhejiang Fengwo IoT Technology Co., Ltd. (vendor)Fengwo Group (vendor)Android TV boxes (technology)