Cheap TV streaming sticks are secretly clicking ads and pretending to be phones
Researchers say around 38,000 H96 Android TV boxes are pulling double duty as ad-fraud bots and residential proxies, funnelling roughly $50,000 a day to a mainland China outfit called the Fengwo Group.

Key points
- Bitsight TRACE tied roughly 38,000 H96 brand Android TV streaming sticks worldwide to an ad-fraud network run by Zhejiang Fengwo IoT Technology Co., Ltd.
- The infected sticks pretend to be Samsung or Xiaomi phones so they can click ads on AI-generated websites the same operator runs.
- Bitsight estimates the ad-fraud side alone brings in about $50,000 a day, on top of separate revenue from renting out users' home internet connections.
- Devices split their workload by TV signal: proxying when the screen is on, running ad-fraud jobs when it's off.
- Amazon, Best Buy and Newegg still list hundreds of models despite years of FBI warnings against no-name streaming boxes.
A cheap streaming stick that promises free TV for a one-off payment isn't really cheap. It's working a second job in your living room, and the pay cheque goes to someone else.
That's the finding of a new investigation by security firm Bitsight TRACE, whose researcher Pedro Falé got a rare look inside the operation after registering an expired web address the criminals had forgotten to renew. The domain was used by the devices to phone home. Once Falé owned it, tens of thousands of streaming sticks around the world started reporting to him.
The brand at the centre of the story is H96, a family of Android TV boxes sold widely online, including on Amazon. They plug into a television and promise unlimited streaming for a single payment.
What are these sticks actually doing?
Two things, taken in turns. When the television detects an HDMI signal and someone is watching, the box acts as a residential proxy, quietly renting out the household's internet connection to anonymous paying customers. Switch the TV off and the same box loads a hidden web browser and clicks on adverts, generating fake traffic for the operator's own websites.
Falé told KrebsOnSecurity he believes the two roles never overlap because ad-fraud work is resource-intensive and would interrupt the streaming the buyer actually paid for.
Who is behind it?
Bitsight traced the network to Zhejiang Fengwo IoT Technology Co., Ltd, a company founded in 2019 in mainland China and trading as the Fengwo Group. Money moves through shell entities in Hong Kong and Singapore. Fengwo has even filed patents describing the same techniques the apps use.
Its public website advertises more than 120,000 "AI digital humans" available to rent for tasks ranging from customer service to "emotional companionship".
How does the fraud work?
The infected sticks tell the internet they are Samsung, Vivo, Huawei or Xiaomi mobile phones. That matters because Fengwo's machine-generated blogs, covering finance, health and gaming, only serve ads to visitors that look like phones. A stick spoofing a Xiaomi handset walks straight past that filter.
To make the clicks look human, the software "fuses three vision and reasoning systems into a single interface" so bots can spot an ad and navigate a page the way a person would, according to Bitsight's report.
Fengwo staff build the fraud routines using Blockly, a drag-and-drop coding tool Google originally made for children learning to program. One Fengwo developer noted that "developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company's operating costs."
| Detail | Figure |
|---|---|
| H96 devices phoning home | ~38,000 globally |
| Estimated daily ad-fraud revenue | ~$50,000 |
| Fengwo company founded | 2019, mainland China |
| Advertised "AI digital humans" | 120,000+ |
Should ordinary buyers be worried?
Yes, and the fix isn't complicated. These boxes ship with proxy software already installed, carry no meaningful security, and can be conscripted into criminal jobs without the owner noticing. When we covered the NetNut botnet disruption on 3 July 2026, the same pattern held: ordinary home devices turned into anonymous relay points for criminal traffic, with owners none the wiser.
If you own one of these boxes, unplug it. Switch to a streaming device from a named manufacturer, or a smart TV's built-in app. Watch your home broadband for unusual slowdowns.



