DEALSTreasury's $6bn buyback fails to halt 30-year yield at 5.2%Sep 10, 2026
WORLDChina regulators warn banks against flooding IPO market with low-quality listingsSep 10, 2026
EARNINGSJ.J. McCarthy demoted to third string as Vikings name Wentz backup ahead of Green Bay openerSep 10, 2026
KALAKALA BIO sets November 3 annual meeting; stockholder nomination window closes September 19Sep 9, 2026
MACROTwenty-nine health systems plan to exit Medicare AdvantageSep 9, 2026
MACROCopper hits record $14,858.50 a ton as tariff stockpiling and global supply crunch convergeSep 9, 2026
CRYPTOIran relaxes foreign currency controls in quiet pivot toward cryptoSep 9, 2026
AMZNAmazon routes 360,000 annual scam inquiries through a new Alexa verification toolSep 9, 2026
DEALSTreasury's $6bn buyback fails to halt 30-year yield at 5.2%Sep 10, 2026
WORLDChina regulators warn banks against flooding IPO market with low-quality listingsSep 10, 2026
EARNINGSJ.J. McCarthy demoted to third string as Vikings name Wentz backup ahead of Green Bay openerSep 10, 2026
KALAKALA BIO sets November 3 annual meeting; stockholder nomination window closes September 19Sep 9, 2026
MACROTwenty-nine health systems plan to exit Medicare AdvantageSep 9, 2026
MACROCopper hits record $14,858.50 a ton as tariff stockpiling and global supply crunch convergeSep 9, 2026
CRYPTOIran relaxes foreign currency controls in quiet pivot toward cryptoSep 9, 2026
AMZNAmazon routes 360,000 annual scam inquiries through a new Alexa verification toolSep 9, 2026

Cheap Android TV boxes tied to $47,500-a-day ad fraud scheme, Bitsight finds

$47,500 a day is Bitsight's estimated ad-fraud yield from the operation it calls Fuyao Enterprise. In a single 24-hour sample, 65,957 reports resolved to roughly 38,000 unique MAC addresses carrying the Fuyao apps; $47,500 divided across…

By Warren Ashby·Aug 15, 2026·2 min read·regulatory·GOOGL

Key takeaways

  • Bitsight estimates the ad-fraud operation it calls Fuyao Enterprise yields about $47,500 a day, roughly $1.25 per device across the ~38,000 unique MAC addresses seen in a single 24-hour sample.
  • The Fuyao apps appeared most often preinstalled on older H96 Max V11 Android TV boxes, which falsely identified themselves as Samsung, Vivo, Huawei, and Xiaomi smartphones.
  • The boxes ran two jobs based on the HDMI signal: acting as a residential proxy while the TV was on, and committing ad fraud on 144 operator-controlled AI-generated websites while the TV was off.
  • Bitsight attributed Fuyao to Zhejiang Fengwo IoT Technology Co., Ltd. (operating as Fengwo Group), citing shared digital certificates, internal files, advertising-revenue entities, and company patents, though no court has ruled on the findings.
  • The Fuyao operation is separate from the FBI's BADBOX 2.0 campaign, which the FBI says hijacked more than a million Android devices.

$47,500 a day is Bitsight's estimated ad-fraud yield from the operation it calls Fuyao Enterprise. In a single 24-hour sample, 65,957 reports resolved to roughly 38,000 unique MAC addresses carrying the Fuyao apps; $47,500 divided across 38,000 devices runs to about $1.25 per device per day. Fengwo Group's website advertised more than 120,000 "AI digital humans," a count Bitsight could not confirm; at that scale, the firm estimates the daily take could reach $150,000, before proxy revenue.

How the operation ran

Bitsight threat researcher Pedro Falé found an expired domain that had previously managed factory backdoors on certain Android TV boxes, registered it, and monitored the traffic sent in. The domain returned hardware profiles and installed-app inventories from connected devices. The anomaly was immediate: boxes identified themselves as Samsung, Vivo, Huawei, and Xiaomi smartphones even though their software pointed to TV hardware. Falé wrote that researchers noticed "something was wildly wrong."

The Fuyao apps appeared most often preinstalled on older H96 Max V11 devices. Bitsight said it could not determine from available evidence where in the supply chain the software was added; an original equipment distributor, reseller, or custom firmware provider each remain possible insertion points. Google said the affected devices are Android Open Source Project devices, not Android TV OS or Play Protect certified devices, and that it holds no security or compatibility test results for uncertified hardware.

Revenue mechanics and attribution

The boxes ran two jobs, switching on the HDMI signal. While a television was active, the device functioned as a residential proxy, routing outside traffic through the household connection so outside users appeared to originate from the home IP. When the TV went off, the box shifted to ad fraud: visiting 144 operator-controlled websites built with AI-generated content and clicking ads while appearing to advertising networks as a mobile phone. Computer vision let the bots locate ads when page layouts changed. A customized version of Google's Blockly programming tool let operators push tasks to the fleet remotely. Advertisers and ad networks were the direct victims, Bitsight said.

Bitsight attributed Fuyao to Zhejiang Fengwo IoT Technology Co., Ltd., operating under the Fengwo Group name. Evidence cited includes shared digital certificates, internal files, advertising-revenue entities, and company patents that researchers say matched components of the system. No court has ruled on the findings. Zhejiang Fengwo IoT Technology, Fengwo Group, and H96 Max did not respond before deadline.

The Fuyao operation is separate from the FBI's BADBOX 2.0 investigation; the FBI has warned that more than a million Android devices were hijacked in that campaign. Bitsight cautioned that MAC address spoofing could place the observed 38,000 device count above the true number of physical units in the network.

Share
Source: foxnews.com
© 2026 NewsMeter

Frequently asked

How did Bitsight discover the operation?

Bitsight threat researcher Pedro Falé registered an expired domain that had previously managed factory backdoors on certain Android TV boxes and monitored the incoming traffic, which returned hardware profiles and installed-app inventories from connected devices.

Who were the direct victims of the scheme?

Bitsight said advertisers and ad networks were the direct victims, since the boxes clicked ads on operator-controlled sites while appearing to advertising networks as mobile phones.

Could the daily fraud figure be higher than $47,500?

Yes; Fengwo Group's website advertised more than 120,000 'AI digital humans,' and at that unconfirmed scale Bitsight estimates the daily take could reach $150,000 before proxy revenue.

Is the estimated device count reliable?

Bitsight cautioned that MAC address spoofing could place the observed 38,000 device count above the true number of physical units in the network.

What did Google say about the affected devices?

Google said the affected devices are Android Open Source Project devices, not Android TV OS or Play Protect certified, and that it holds no security or compatibility test results for the uncertified hardware.