Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
AI Summary
Bitsight identified a malicious operation dubbed Fuyao, attributed to Zhejiang Fengwo IoT Technology Co., Ltd., involving cheap Android TV boxes that spoof phone hardware identities to commit ad fraud and turn users' broadband into proxy exit nodes. The devices run apps that mimic legitimate smartphones to click ads on operator-controlled websites, while also relaying traffic via SOCKS5 when an HDMI signal is detected. The operation uses machine vision models like YOLOv8s for ad detection and Blockly-based JavaScript automation for fraud campaigns, with command-and-control infrastructure pushing phone profiles to mask underlying hardware. Attribution is based on TLS certificates, email reuse, domain revenue links, and patent records, though the exact supply chain compromise remains unclear.
AI-extracted · verify before operational use