By Interestana AI Editorial — AI-drafted, human-overseen. How we report
TV Streaming Sticks Exploit Users for Ad Fraud

Security experts have long warned about the risks associated with generic TV boxes that offer unlimited content streaming for a one-time fee, citing concerns that these devices secretly rent out users' internet connections to unauthorized third parties. A recent, groundbreaking analysis has revealed an additional, significant threat: these devices routinely impersonate mobile phones to generate fraudulent ad clicks on AI-generated websites. This activity is part of a large-scale operation designed to defraud online merchants and advertising networks.
Pedro Falé, a threat researcher at the security firm Bitsight, detailed his findings to KrebsOnSecurity. Falé gained insight into a vast and complex ad fraud network by registering an expired domain name. This domain had been previously used to coordinate fake ad clicks originating from a popular brand of these streaming devices, specifically identified as H96. The H96 TV streaming device is currently advertised for sale on platforms like Amazon. Falé explained that the domain he acquired was formerly utilized for telemetry purposes, which involved periodically collecting comprehensive hardware information and a complete list of installed applications from tens of thousands of H96 streaming sticks connected to televisions worldwide.
Upon examining the data transmitted to the domain, Falé discovered that nearly all of the TV boxes were reporting themselves as mobile phone models from various manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was wildly wrong," Falé stated, observing that "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’" Further investigation revealed that all of the compromised devices reported having the same two applications installed. These applications were developed by Zhejiang Fengwo IoT Technology Ltd, a company established in mainland China in 2019. Zhejiang Fengwo IoT Technology Ltd operates an ad-publishing portfolio under the name Fengwo Group. The researcher's deeper dive into the Fengwo Group uncovered that the company has registered multiple patents that align with the internal functionalities of these suspicious applications. Bitsight TRACE identified several entities registered in Hong Kong and Singapore, along with a single-person entity, described as a "legal" entity, which were involved in this operation.
Original source — read the full reporting at the publisher:
Read on Krebs on SecurityGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.