Bitsight disclosed the Fuyao ad-fraud operation on July 30 after tracing suspicious telemetry from low-cost H96 Android TV boxes. The security firm alleges that preinstalled apps spoofed the boxes as phones, automated clicks and views on AI-generated websites, and supported residential proxy traffic without owners' knowledge. Bitsight estimated the operation could generate up to $40 million annually.
Bitsight disclosed a previously unreported Android TV-box botnet that it calls Fuyao, alleging that preinstalled apps on some H96 devices spoofed the hardware as Android phones and generated fraudulent advertising traffic. In a July 30 report, the security firm linked the operation to Zhejiang Fengwo IoT Technology Co., Ltd. and its Fengwo Group advertising portfolio.
According to Bitsight, the operation combines device spoofing, automated browsing, AI-generated websites, and residential proxy capabilities. The firm reported that affected devices could forward traffic through consumers' home connections without their consent while also being used to generate advertising clicks and impressions.
An expired domain exposed the infrastructure
Bitsight threat researcher Pedro Fale found the operation while examining a factory-installed remote-management backdoor on consumer Android TV boxes, according to KrebsOnSecurity and Help Net Security. A domain used by that backdoor had expired, and Bitsight's TRACE team registered it. Devices that continued to contact the domain sent telemetry including hardware details and installed-application lists.
Rather than reporting as TV boxes, many devices identified themselves as phones from vendors including Samsung, Vivo, Huawei, Xiaomi, and others, KrebsOnSecurity reported. Bitsight found that the devices shared two applications attributed to Zhejiang Fengwo IoT Technology, and said patents registered by the company matched functions in the apps and supporting systems.
Bitsight reported observing nearly 38,000 unique MAC addresses over 24 hours through its sinkhole. The researchers cautioned that this is not a count of infected devices because identities can rotate. Separately, the operators advertised more than 120,000 "AI digital humans," according to Bitsight.
Automation designed for ad traffic
The Fuyao apps reportedly use a custom editor built on Blockly, the visual programming framework commonly used in educational coding tools. Bitsight described a system in which fraud tasks can be created and monitored per bot, with visual feedback on campaign execution.
The firm's report also describes apps that can livestream a device screen to command-and-control infrastructure and use computer-vision models to locate advertisements on pages. Bitsight said the bots interacted with ads across thousands of AI-generated websites while mimicking human behavior. That combination matters because ad-fraud defenses frequently use device fingerprints, behavioral signals, traffic provenance, and content-quality signals to identify invalid activity.
Help Net Security reported that Bitsight estimated daily revenue at $1 to $1.25 per device, yielding a potential annual total of as much as $40 million after accounting for clicks and impressions that ad platforms might detect as fraudulent. Bitsight also said it traced monetization identities to Hong Kong, Singapore, and single-person shell entities, with publisher accounts associated with Google AdSense and Taboola.
Supply-chain risk beyond the application layer
The findings extend the security risk of low-cost streaming hardware beyond malicious sideloaded apps. In this case, public reporting describes functionality embedded in the device software stack, including a remote-management backdoor that remained enabled after sale.
Companies investigating comparable fraud patterns typically need telemetry from several layers: device identity, network egress, ad-request behavior, publisher-account activity, and web-content provenance. The Fuyao case illustrates why mobile-device claims alone are an insufficient trust signal when hardware profiles, installed packages, and traffic behavior tell a conflicting story.
Bitsight's public report attributes the infrastructure and app ecosystem to Fengwo-linked entities.
Key Points #
- 1Bitsight linked preinstalled Android TV-box apps to spoofed mobile traffic, expanding ad-fraud risk from browser automation into consumer-device supply chains.
- 2The reported Blockly-based task system shows that visual automation tooling can orchestrate fraud workflows at botnet scale, not only educational projects.
- 3Comparable fraud investigations require correlating device fingerprints, network telemetry, publisher accounts, and behavioral signals rather than trusting claimed device identity.
Scoring Rationale #
The reported operation combines firmware-level exposure, device impersonation, residential proxies, computer vision, and ad-fraud automation. It is highly relevant to security teams, advertising platforms, and fraud engineers, although the findings concern a specific device ecosystem rather than a broadly deployed AI model or platform.
Sources #
Primary source and supporting public references used for this report.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
[Active Search Campaigns by BudgetEasy](/problems/sql/active-search-campaigns-by-budget)
[High CPC Clicks & Poor Landing PagesMedium](/problems/sql/high-cpc-clicks-poor-landing-page)
[Campaign ROAS by Attribution ModelHard](/problems/sql/campaign-roas-by-attribution-model)
250 free problems · No credit card