Interestana
Home/News/Android TV Boxes Hijacked to Click Ads and Proxy Traffic
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Android TV Boxes Hijacked to Click Ads and Proxy Traffic

Android TV Boxes Hijacked to Click Ads and Proxy Traffic

Security researchers at Bitsight have identified a widespread operation, dubbed Fuyao, where inexpensive Android TV boxes are being compromised with malicious applications. These applications are designed to alter the device's hardware identity, making it appear as a legitimate smartphone from manufacturers such as Samsung, Huawei, Xiaomi, or Vivo. This impersonation is part of a scheme to generate fraudulent advertising revenue by automatically clicking on ads hosted on websites controlled by the same operators. The operation has been attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a company established in mainland China in 2019. The Fuyao malware performs a dual function, with its second capability involving the repurposing of the compromised TV box's internet connection. Once the device's identity is masked, the malware leverages the user's broadband connection to act as a proxy server. This allows the operators to route other internet traffic through the compromised devices, potentially masking the origin of illicit online activities or facilitating access to geo-restricted content for other clients. The implications of this operation extend beyond simple ad fraud, as the use of user devices as proxies can expose individuals to risks associated with the traffic being routed through their network. This includes potential involvement in activities that could be traced back to their IP address. The widespread distribution of these cheap Android TV boxes, often found in consumer electronics markets, means that a significant number of users could be unknowingly participating in this malicious network. The researchers have not yet disclosed the exact number of devices affected or the specific models of Android TV boxes that are vulnerable, but the nature of the operation suggests a broad reach. The tactic of disguising the hardware identity is a sophisticated method to evade detection by ad networks and security software that might otherwise flag unusual device behavior. By mimicking popular smartphone brands, the compromised devices are more likely to pass initial checks and continue their fraudulent activities undetected for extended periods. The dual-use nature of the malware, combining ad fraud with proxy services, highlights the evolving tactics of cybercriminals targeting Internet of Things (IoT) devices. The low cost and widespread availability of such devices make them an attractive target for botnet creation and other malicious operations.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next