Cheap TV streaming sticks are secretly clicking ads and pretending to be phones
Researchers say around 38,000 H96 Android TV boxes are pulling double duty as ad-fraud bots and residential proxies, funnelling roughly $50,000 a day to a mainland China outfit called the Fengwo Group.

Key points
- Bitsight TRACE tied roughly 38,000 H96 brand Android TV streaming sticks worldwide to an ad-fraud network run by Zhejiang Fengwo IoT Technology Co., Ltd.
- The infected sticks pretend to be Samsung, Vivo, Huawei and Xiaomi phones so they can click ads on AI-generated websites the same operator runs.
- Bitsight estimates the ad-fraud side alone brings in about $50,000 a day, on top of separate revenue from renting out users' home internet connections.
- The devices switch roles: when the TV is on they act as a residential proxy for paying customers; when it is off, they run ad-fraud jobs.
- The FBI and independent researchers have warned for years against buying these no-name streaming boxes, yet Amazon, Best Buy and Newegg still list hundreds of models.
A cheap streaming stick that promises free TV for a one-off payment is not really cheap. It is working a second job in your living room, and the pay cheque goes to someone else.
That is the finding of a new investigation by security firm Bitsight TRACE, whose researcher Pedro Falé got a rare look inside the operation after registering an expired web address the criminals had forgotten to renew. The domain was used by the devices to phone home. Once Falé owned it, tens of thousands of streaming sticks around the world started reporting to him.
The brand at the centre of the story is H96, a family of Android TV boxes sold widely online, including on Amazon. They plug into a television and promise unlimited streaming for a single payment.
What are these sticks actually doing?
Two things, and they take turns. When the television is switched on and someone is watching, the box acts as a residential proxy, meaning it quietly rents out the household's internet connection to anonymous paying customers. When the television is off, the same box loads a hidden web browser and clicks on adverts, generating fake traffic for the operator's own websites.
Falé told KrebsOnSecurity the devices never do both jobs at once because ad-fraud work is heavy and would interrupt the streaming the buyer actually wanted.
Who is behind it?
Bitsight traced the network to Zhejiang Fengwo IoT Technology Co., Ltd, a company founded in 2019 in mainland China and trading as the Fengwo Group. The money moves through shell entities in Hong Kong and Singapore. Fengwo has even filed patents that describe the same techniques the apps use.
The group's public website advertises "AI digital humans" for hire, more than 120,000 of them, for tasks from customer service to "emotional companionship".
How does the fraud work?
The infected sticks tell the internet they are Samsung, Vivo, Huawei or Xiaomi mobile phones. That matters because the fake news sites the operator runs, machine-generated blogs about finance, health, food and gaming, only show ads to visitors that look like phones. A stick pretending to be a Xiaomi handset walks straight past that filter.
To make the clicks look human, the software "fuses three vision and reasoning systems into a single interface" so the bots can spot an ad on a page and move around the site the way a person would, according to Bitsight's report.
Internally, Fengwo staff build the fraud routines using Blockly, a drag-and-drop coding tool Google originally made for children learning to program. One Fengwo developer wrote that this lets low-skilled staff assemble campaigns without understanding the code, which "greatly reduces the company's operating costs".
| Detail | Figure |
|---|---|
| H96 devices phoning home | ~38,000 globally |
| Estimated daily ad-fraud revenue | ~$50,000 |
| Fengwo company founded | 2019, mainland China |
| Advertised "AI digital humans" | 120,000+ |
Should ordinary buyers be worried?
Yes, and the fix is simple: do not plug an unbranded Android streaming box into your home network. The FBI has warned about these devices for years. They ship with the proxy software already installed, they have no meaningful security, and, as Bitsight shows, they can be pulled into criminal jobs without the owner ever noticing.
If you already own one, unplug it. Use a streaming device from a known maker, or a smart TV app, instead. Watch your home broadband for unusual slowdowns, and check with your bank if you see charges you do not recognise on a card used to buy the box.



