logo

H96 Android TV Boxes Used for Ad Fraud and Residential Proxies

ID: aeebb7be-f95e-5e23-bd1a-35f7e0cd387b

STIX ID: report--aeebb7be-f95e-5e23-bd1a-35f7e0cd387b

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Waqas

...
...

Bitsight researchers identified a preinstalled operation named “Fuyao” on inexpensive Android TV boxes that rewrites device identities, automates ad-clicking using accessibility APIs, OCR and a YOLO vision model, and exposes devices as SOCKS5 residential proxies; the activity was observed across tens of thousands of device reports and linked to Zhejiang Fengwo IoT, with persistence likely via firmware or customized ROMs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.