H96 TV Streaming Sticks Found Running Massive Mobile Ad Fraud Network
Cheap TV streaming sticks marketed as offering unlimited content for a one-time fee are secretly powering a sophisticated ad fraud operation that spoofs mobile devices to click on ads across AI-generated websites. Security researcher Pedro Falé of Bitsight uncovered the scheme after registering an expired domain previously used for telemetry by H96 streaming devices, which are widely sold on Amazon and other marketplaces. Once reactivated, the domain began receiving data from tens of thousands of H96 boxes worldwide—each falsely reporting itself as a smartphone from manufacturers including Samsung, Vivo, Huawei, and Xiaomi.
Further analysis revealed that every infected H96 device had two identical apps installed, both developed by Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China firm operating under the Fengwo Group brand since 2019. According to Bitsight's TRACE team, these apps transform compromised streaming sticks into a captive traffic source, automating fraudulent ad clicks on a network of machine-generated news sites spanning finance, health, education, gaming, music, and food. Crucially, none of those sites display ads unless the visitor matches a spoofed mobile profile—evidence that the operation is engineered specifically to monetize stolen device identities. Operators relied on shell entities registered in Hong Kong, Singapore, and through individual nominee holders to collect ad payouts before funneling funds back to the parent company. Users concerned about device-level exposure can validate their network's outbound behavior with a port scanner to spot unexpected connections.
Fengwo Group's corporate domain, fwgcloud[.]com, boasts of "redefining the boundaries of human-AI interaction" and claims to have built more than 120,000 "AI digital humans"—a marketing line that closely mirrors the automated content farms underpinning the fraud. Bitsight has also linked the company to multiple registered patents matching the internal mechanics of the offending apps, suggesting the fraudulent behavior is by design rather than the work of a rogue third party. Researchers urge buyers of low-cost Android TV boxes to inspect installed applications, audit outbound DNS queries with a DNS leak test, and reconsider the long-term risks of importing unverified IoT hardware into home or office networks.