H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
ID: aeebb7be-f95e-5e23-bd1a-35f7e0cd387b
STIX ID: report--aeebb7be-f95e-5e23-bd1a-35f7e0cd387b
Feed Name: HackRead
Threat Score
Bitsight researchers identified a preinstalled operation named “Fuyao” on inexpensive Android TV boxes that rewrites device identities, automates ad-clicking using accessibility APIs, OCR and a YOLO vision model, and exposes devices as SOCKS5 residential proxies; the activity was observed across tens of thousands of device reports and linked to Zhejiang Fengwo IoT, with persistence likely via firmware or customized ROMs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
