negativeSYS.SOURCE: The Hacker News• 2026-07-31T20:15:01+05:30
Malicious Android TV Boxes Exploit Network Traffic by Mimicking Phones and Acting as Proxies
Malicious Android TV boxes spoof phone identities to engage in ad fraud and exploit user broadband as proxies, part of the Fuyao operation linked to Zhejiang Fengwo IoT Technology. The campaign uses machine vision and custom scripting to automate ad clicks, with estimated daily revenues of $47,500 from 38,000 devices.
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.
Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.
The same apps have a second job. When a box
*** END OF TRANSMISSION ***