Press play to start listening
Some inexpensive Android TV boxes were shipped with preinstalled software capable of disguising the devices as smartphones, clicking online advertisements, and routing other people’s internet traffic through owners’ home connections, according to new research from Bitsight.
Bitsight researcher Pedro Falé identified the operation while examining factory backdoors left active on consumer streaming boxes. After registering an expired domain previously used for device management and telemetry, researchers began receiving hardware details and lists of installed applications from connected boxes.
Among those reports, many devices reported themselves as smartphones from Samsung, Huawei, Xiaomi, Vivo, and other manufacturers. Their installed packages, hardware properties, and television launchers showed they were Android TV boxes whose identities had been rewritten.
Bitsight named the operation Fuyao and found its applications mostly on devices reporting the model H96_MAX_V11. However, the company warned that its visibility was concentrated on older boxes from one brand, meaning the findings do not provide a complete list of affected products.
During one 24-hour observation period, researchers received 65,957 reports associated with about 38,000 unique MAC addresses running Fuyao applications. Bitsight noted that identity rotation could cause the MAC address count to exceed the number of physical devices.
Evidence from installation paths and application privileges indicated that Fuyao was preinstalled on some devices or embedded in modified firmware. Bitsight said distribution may have involved device customisation, reseller firmware, or unofficial ROM images offered for download.
Once connected, Fuyao could rewrite device properties and present a television box as a higher-value smartphone. The software then opened websites controlled by the operators, viewed advertisements and clicked them to generate payments from advertising networks.
To make the activity resemble human browsing, Fuyao used Android accessibility data, optical character recognition and a YOLO computer vision model trained to identify page elements, including advertisements and Taboola recommendation widgets. Its tasks could scroll through pages, simulate reading time, select different browsers, close tabs and clear browser caches.
Furthermore, operators built those routines using a customised version of Blockly, a visual programming system commonly used to teach children how to code. Dragging blocks together allowed workers with limited technical knowledge to prepare new advertising campaigns without writing each routine from the beginning.
While a television was in use, the software could operate the box as a SOCKS5 residential proxy. Traffic from customers of a proxy service would then leave through the device owner’s home internet address, making it appear to originate from an ordinary residential connection. When the HDMI connection was inactive, the box could return to advertising tasks.
Bitsight’s research also found that one in six observed Fuyao boxes overlapped with its residential proxy data during 24 hours. Over seven days, the overlap increased to one in four devices. The applications could also send logs and screenshots to command servers and livestream their virtual screen through WebRTC.
Researchers linked Fuyao to Zhejiang Fengwo IoT Technology Co., Ltd., part of the mainland China-based Fengwo Group. Their evidence included shared certificates, exposed internal files, reused email addresses and company patents that matched functions found in the Fuyao applications.
Fengwo advertised a network of more than 120,000 “AI digital humans,” but Bitsight did not independently confirm that figure. Its verified sample covered about 38,000 unique MAC addresses, with the company cautioning that this was not a reliable count of individual boxes.

Anyone using an affected H96 device should consider disconnecting it and replacing it with hardware receiving authenticated firmware updates from its manufacturer. A factory reset may reinstall the same unwanted applications when they are embedded in the device firmware.
