$47,500 a day is Bitsight's estimated ad-fraud yield from the operation it calls Fuyao Enterprise. In a single 24-hour sample, 65,957 reports resolved to roughly 38,000 unique MAC addresses carrying the Fuyao apps; $47,500 divided across 38,000 devices runs to about $1.25 per device per day. Fengwo Group's website advertised more than 120,000 "AI digital humans," a count Bitsight could not confirm; at that scale, the firm estimates the daily take could reach $150,000, before proxy revenue.
How the operation ran
Bitsight threat researcher Pedro Falé found an expired domain that had previously managed factory backdoors on certain Android TV boxes, registered it, and monitored the traffic sent in. The domain returned hardware profiles and installed-app inventories from connected devices. The anomaly was immediate: boxes identified themselves as Samsung, Vivo, Huawei, and Xiaomi smartphones even though their software pointed to TV hardware. Falé wrote that researchers noticed "something was wildly wrong."
The Fuyao apps appeared most often preinstalled on older H96 Max V11 devices. Bitsight said it could not determine from available evidence where in the supply chain the software was added; an original equipment distributor, reseller, or custom firmware provider each remain possible insertion points. Google said the affected devices are Android Open Source Project devices, not Android TV OS or Play Protect certified devices, and that it holds no security or compatibility test results for uncertified hardware.
Revenue mechanics and attribution
The boxes ran two jobs, switching on the HDMI signal. While a television was active, the device functioned as a residential proxy, routing outside traffic through the household connection so outside users appeared to originate from the home IP. When the TV went off, the box shifted to ad fraud: visiting 144 operator-controlled websites built with AI-generated content and clicking ads while appearing to advertising networks as a mobile phone. Computer vision let the bots locate ads when page layouts changed. A customized version of Google's Blockly programming tool let operators push tasks to the fleet remotely. Advertisers and ad networks were the direct victims, Bitsight said.
Bitsight attributed Fuyao to Zhejiang Fengwo IoT Technology Co., Ltd., operating under the Fengwo Group name. Evidence cited includes shared digital certificates, internal files, advertising-revenue entities, and company patents that researchers say matched components of the system. No court has ruled on the findings. Zhejiang Fengwo IoT Technology, Fengwo Group, and H96 Max did not respond before deadline.
The Fuyao operation is separate from the FBI's BADBOX 2.0 investigation; the FBI has warned that more than a million Android devices were hijacked in that campaign. Bitsight cautioned that MAC address spoofing could place the observed 38,000 device count above the true number of physical units in the network.