Back to feed

Bitsight Uncovers Fuyao: Cheap Android TV Boxes Pose as Phones for Fraud

2 min
Bitsight Uncovers Fuyao: Cheap Android TV Boxes Pose as Phones for Fraud

This digest was compiled by AI from multiple sources — links to the originals are below.

Bitsight has uncovered an operation, dubbed Fuyao, in which cheap Android TV boxes shipped with apps that spoof their hardware to appear as popular smartphones and automatically click ads on operator-owned websites, the security firm reported. The same devices also relay proxy traffic through owners’ broadband as SOCKS5 exit nodes when an HDMI signal is detected. Researchers linked the operation to Zhejiang Fengwo IoT Technology, a company in mainland China.

Device Impersonation

The Fuyao operation uses apps pre-installed on cheap Android TV boxes that rewrite their hardware identity to mimic popular phone models like Samsung, Huawei, Xiaomi, and Vivo. These apps delete chipset properties that would reveal the underlying Rockchip, Amlogic, or Allwinner boards. A command-and-control server pushes complete phone profiles to each device, merging a base configuration with per-model adjustments.

Dual-Purpose Malware

When the TV box detects an HDMI signal, it switches to relaying other people's traffic through the owner's broadband as a SOCKS5 exit node. When HDMI is off, the device awaits ad-fraud tasks. The fraud automation uses machine vision: a YOLOv8s object-detection model named lourui_2, trained on 12 screen elements including banner ads and Taboola widgets, combines with Android accessibility data and Google ML Kit OCR to locate and click ads. Across four test devices, Bitsight captured about 40 fraud tasks, 21 unique campaigns, and 166 unique modules. Operators build campaigns using a custom Blockly-based editor and deploy them via Amazon S3.

Botnet Scale and Attribution

Bitsight sinkholed a factory backdoor domain and received 65,957 reports from 38,000 unique MAC addresses in one day, though the devices rotated spoofed identifiers so the true count is uncertain. Most reports described the devices as phones. The security firm attributed the operation to Zhejiang Fengwo IoT Technology, a mainland Chinese company founded in 2019, which advertised over 120,000 "AI digital humans" — a marketing figure not directly tied to the physical fleet. The payout chain ran through 144 operator-owned domains across seven beneficiary clusters, 84 of which loaded a Taboola tag, using Taboola’s public sellers.

1 source

Time · lag behind first