HackMyIP
← Back to News
2026-07-31 The Hacker News

Fuyao Botnet Hides in Cheap Android TV Boxes, Steals Bandwidth for Ad Fraud

MalwareSupply ChainAI Threats

Bitsight researchers have uncovered a supply-chain operation called "Fuyao" that ships pre-installed on low-cost Android TV boxes, transforming consumer hardware into a dual-purpose ad-fraud and proxy botnet. Researchers, including threat investigator Pedro Falé, traced the activity to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China IoT vendor founded in 2019. The discovery began after Bitsight registered an expired domain once used as a factory backdoor and telemetry collector, allowing the team to sinkhole reports from compromised devices—most commonly identifying as the H96_MAX_V11 model—while stripping away identifying names like Samsung, Huawei, Xiaomi, and Vivo to mask their Rockchip, Amlogic, or Allwinner SoCs.

The malware fuses three vision systems into one fraud pipeline. A YOLOv8s object-detection model dubbed "lourui_2" combines with Android accessibility services and Google ML Kit optical character recognition to locate banner ads and Taboola widgets on screen, then clicks them automatically. Operators build each fraud routine in a custom Blockly-based editor, export it as JavaScript to Amazon S3, and push complete phone profiles from the C2 to every box—merging a base config with a per-model diff. Across four test devices, Bitsight captured roughly 40 fraud tasks, 21 distinct campaigns, and 166 unique modules. The payout chain routes through 144 operator-owned domains spread across seven beneficiary clusters, at least 84 of which loaded a Taboola tag on their homepage.

Fuyao has a second, quieter job. When one of these boxes detects an active HDMI signal, it switches into SOCKS5 relay mode and pipes arbitrary third-party traffic through the owner's broadband line. With HDMI off, it returns to ad-clicking duties. In a single filtered day, the Bitsight sinkhole logged 65,957 reports from about 38,000 spoofed MAC addresses, though the figure is inflated by rotating identifiers. Network owners worried about unauthorized relays can validate their egress path with a VPN/proxy detector and audit exposed services with a port scanner.

Buyers of off-brand Android boxes get the same generic guidance experts have repeated for years: confirm Play Protect certification before purchase, isolate unfamiliar IoT devices on a guest VLAN, and watch for unexplained bandwidth spikes. Bitsight noted that Fengwo also advertises more than 120,000 "AI digital humans" in its marketing—a number that does not map cleanly onto the infected-device count and cannot be cross-referenced. For households that suspect their network has already been conscripted, running a DNS leak test can reveal whether DNS queries are being routed through unexpected resolvers, a common side effect of malware-driven proxy relays.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →