NEWYou can now listen to Fox News articles!
You plug a streaming box into your television, connect it to Wi-Fi and settle in for a movie. Meanwhile, that little device may have a completely different job running in the background. Security researchers say some cheap Android TV boxes can secretly route outside traffic through a household’s internet connection. New research from Bitsight shows that some boxes may also pretend to be smartphones, visit AI-generated websites and click online ads.
The hidden activity can generate advertising revenue or turn the box into a residential proxy that lets strangers use your home internet connection. Bitsight’s latest findings reveal how organized and technically advanced one such operation may have become. That inexpensive streaming box could cost you far more than its purchase price.
New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats
Join us Saturday, August 29, at 10 AM ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt “CyberGuy” Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
BRINKS HOME DATA BREACH PUTS 1M CUSTOMERS ON ALERT
Bitsight uncovers a hidden TV box operation
Bitsight threat researcher Pedro Falé uncovered the operation while studying security risks involving cheap Android TV boxes. His team found an expired domain that had previously managed factory backdoors on certain devices. Bitsight registered the domain and began observing the information sent to it.
The domain collected hardware information and lists of installed apps from connected boxes. Researchers quickly noticed something unusual: many of the devices identified themselves as phones from brands including Samsung, Vivo, Huawei and Xiaomi even though their software revealed signs of TV boxes. Falé wrote that researchers noticed “something was wildly wrong.” Bitsight eventually named the operation the Fuyao Enterprise.
Some H96 devices appeared to include the apps
Bitsight says the Fuyao apps appeared to arrive preinstalled on some Android TV boxes sold under the H96 name. Researchers found the apps most often on older H96 Max V11 devices. However, the available data covered only certain older models that reported to the expired domain. The findings do not establish that every H96 device contains the software. Bitsight also raised the possibility that an original equipment distributor, reseller or custom firmware provider added the apps before the boxes reached consumers. That means researchers cannot say from the available evidence exactly where in the supply chain the software was added.
A Google spokesperson told CyberGuy: “The infected devices are Android Open Source Project devices, not Android TV OS devices or Play Protect certified Android devices. If a device isn’t Play Protect certified, Google doesn’t have a record of its security and compatibility test results.” That distinction is important. These boxes may use Android’s open-source code, but they should not be confused with devices running Google’s official Android TV OS.
Is your Android TV box affected?
Bitsight has not published a complete list of every device connected to the Fuyao operation. Therefore, you cannot confirm that a box is affected based on its brand alone. Researchers found the Fuyao apps most often on older H96 Max V11 boxes. However, that does not mean every H96 Max V11 is affected or that other models are safe. Google says it does not have the H96 device name we asked about registered as a certified device. However, Google would need additional technical information about the specific device to confirm its certification status. Start by finding your box’s exact brand and model number. Check the label on the bottom or back of the device. You may also find it in your order history, purchase receipt or device settings under About or Device Preferences.
Pay closer attention if your box:
- Is an H96 Max V11 or another inexpensive H96 model
- Came from an unfamiliar manufacturer or third-party reseller
- Was advertised as unlocked or fully loaded
- Promised access to paid content without subscriptions
- Requires apps from an unofficial marketplace
- Asks you to disable Google Play Protect
- Shows that it is not Play Protect certified
- Produces unexplained internet traffic when nobody is streaming
These signs do not prove the device contains Fuyao software. However, an H96 Max V11 or an uncertified off-brand box with several warning signs should be treated cautiously. Because malicious software may be built into the firmware, a factory reset may not remove it. Disconnect a suspicious box from your network and consider replacing it with a certified device from a recognized manufacturer.
How the hidden ad fraud works
Bitsight says the Fuyao software could disguise a TV box as a smartphone, then quietly send it to operator-controlled websites containing AI-generated content. The box could view and click ads while appearing to advertising systems like a mobile user. Researchers mapped 144 websites tied to the operation and said the actual network could be larger. Bitsight says the operators also used computer vision to help the bots locate ads when webpage layouts changed. A customized version of Google’s Blockly programming tool made it easier for operators to build and send fraud tasks to the boxes. The result was an automated system that could generate fake advertising activity without showing anything unusual on the owner’s television. Bitsight says advertisers and ad networks were victims of the scheme.
SHARED VPN VS DEDICATED IP: WHICH ONE IS RIGHT FOR YOU?

TV on may mean proxy and TV off may mean ad fraud
One of Bitsight’s more unusual findings involved the television’s HDMI connection. Bitsight found that the boxes could switch between two money-making jobs. While an HDMI signal indicated that someone was watching TV, the box often acted as a residential proxy. When the TV was off, it could switch to ad fraud. Researchers believe this helped prevent the more resource-intensive ad activity from interfering with streaming. In practical terms, the box could route somebody else’s internet traffic while you watched television and start clicking ads after you turned the TV off.
Your internet address could hide a stranger’s activity
A residential proxy sends another person’s online traffic through a normal home internet connection. Websites then see the household’s public IP address instead of the stranger’s true location.
Residential proxies have legitimate uses, but criminals can also use them to disguise where their activity originates. A compromised-box owner may never realize that outside traffic is passing through the home connection. The FBI has warned that compromised streaming boxes and other connected devices can give criminals access to residential proxy networks. The agency says malware may arrive preinstalled or enter through unofficial apps.
The Fuyao operation is separate from the FBI’s BADBOX 2.0 investigation, which has also involved compromised streaming devices and other inexpensive electronics. CyberGuy previously covered the FBI’s warning that more than a million Android devices had been hijacked by BADBOX 2.0. Both cases show how an inexpensive connected gadget can quietly become part of a much larger network.
How big is the operation?
In a 24-hour sample, Bitsight observed 65,957 reports tied to roughly 38,000 unique MAC addresses that appeared to have the Fuyao apps installed. Researchers cautioned that spoofing could make that figure higher than the actual number of physical devices. Their visibility was also limited to some older models from one brand.
Using the roughly 38,000 observed device identities, Bitsight estimated potential ad fraud revenue of about $47,500 per day. Fengwo Group’s website claimed more than 120,000 “AI digital humans,” although researchers could not confirm that larger fleet. Bitsight estimated that a fleet of that size could potentially generate about $150,000 per day before accounting for possible proxy revenue.
Bitsight links the operation to Fengwo Group
Bitsight attributed the Fuyao operation to Zhejiang Fengwo IoT Technology Co., Ltd., which it says operates under the Fengwo Group name. Bitsight says its attribution is based on evidence including shared digital certificates, internal files, advertising-revenue entities and company patents that appeared to match parts of the Fuyao system. The company’s website also advertised more than 120,000 “AI digital humans.” Bitsight suggested that phrase could relate to the automated device network, although that remains the researchers’ interpretation. These conclusions are based on Bitsight’s technical research. A court has not ruled on the allegations.
CyberGuy reached out to Google, Zhejiang Fengwo IoT Technology, Fengwo Group and H96 Max for comment. Google responded with information about the distinction between AOSP and Android TV OS devices, Play Protect certification and consumer security protections. We did not hear back from Zhejiang Fengwo IoT Technology, Fengwo Group or H96 Max before our deadline.
Tips to avoid risky Android TV boxes
A few checks can help you decide whether that bargain streaming box belongs on your home network.
1) Choose a recognizable manufacturer
Buy streaming devices from companies that provide security updates and customer support. Be cautious with unfamiliar brands that promise free access to paid content. Also avoid products advertised as “fully loaded” or “unlocked.” Established manufacturers generally provide a clearer path for updates, security information and customer support.
2) Check Play Protect certification
Google recommends checking whether your device is Play Protect certified. On your streaming device, open the Google Play Store. Select your profile icon, then go to Settings > About. Look for Play Protect certification. Google says uncertified devices do not have security and compatibility test results on record with the company. Play Protect can also warn you about or block known malicious apps on certified devices with Google Play Services. This protection can apply to apps installed outside Google Play. Do not assume the Google Play Store means your device is certified. Check the status yourself. You can also review Google’s list of official Android TV OS partners to see whether the manufacturer uses the official platform.
HOTEL WI-FI PHISHING ATTACK TARGETS MICROSOFT LOGINS

3) Avoid unofficial app stores
Do not install apps from a marketplace you do not recognize. Stop if setup instructions ask you to disable Google Play Protect. You should also be cautious if a seller tells you to remove Google’s official app store. Those instructions bypass safeguards designed to detect harmful apps. An unofficial streaming app may appear to work normally while proxy software runs in the background.
4) Disconnect a suspicious box
Unplug the streaming box from your television. Then disconnect its Wi-Fi or Ethernet connection. Open your router’s app or administration page and review the connected-device list. Remove devices you do not recognize. Change your Wi-Fi password if the suspicious box continues to appear. Use a password manager to create and save a strong, unique password. You will need to reconnect your trusted devices with the new password. This is also a good time to review CyberGuy’s guide to fixing common home Wi-Fi security risks.
5) Consider replacing the device
A factory reset may remove apps that were installed after purchase. However, a reset may not eliminate malicious software built into the original firmware. Replacing a suspicious box may be safer than continuing to use it. Do not sell it or give it to someone else. Take the device to a reputable electronics recycling program.
6) Put smart devices on a separate network
Connect streaming boxes and other smart devices to a guest or IoT network when your router supports one. That separation can make it harder for a compromised box to communicate with computers or other sensitive devices on your primary network. Look for Guest Network, IoT Network or Device Isolation in your router’s settings.
7) Watch for unexplained internet activity
A compromised box may use bandwidth when nobody is streaming. Review your router or internet provider’s app for unfamiliar devices and unusual overnight traffic. Slow internet alone does not prove that malware is present. However, unexplained activity from an uncertified device deserves attention.
8) Keep strong security software on your other devices
A streaming box may sit on the same network as your phone or computer. Use strong antivirus software on devices that support it. Security software can alert you to malicious downloads, suspicious websites and other threats that try to spread beyond the streaming box. Also keep your operating system, browser and security apps updated. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
9) Report suspected criminal activity
The FBI asks consumers to report suspected compromised devices through the Internet Crime Complaint Center at IC3.gov. Include the device’s brand and model. Add the seller’s information along with any suspicious apps or network activity you observed. Save your receipt and take screenshots of anything unusual before disconnecting the device.
Kurt’s key takeaways
I love a good bargain, but I would be careful with any streaming box that connects to your home Wi-Fi. Bitsight found that some H96 devices may have quietly clicked ads or routed outside traffic through a household’s internet connection. Google also clarified that the infected devices in this case are AOSP devices, not official Android TV OS or Play Protect certified devices. Before using a bargain streaming box, check its model number and Play Protect certification. If you see several warning signs, disconnect it and consider replacing it.
Do you have a low-cost Android TV box at home, and what did you find when you checked its model and Play Protect certification? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Copyright 2026 CyberGuy.com. All rights reserved.
Read the full article here


