H96 Streaming Sticks Found Fueling Global Ad Fraud Network
Security researchers have uncovered that popular H96 TV streaming devices are part of a massive ad fraud scheme, spoofing themselves as mobile phones to generate fake ad clicks on AI-generated websites.
Security researchers have uncovered a sophisticated global ad fraud network that leverages a popular brand of TV streaming devices, H96, to generate fraudulent ad clicks. The operation, detailed by Bitsight TRACE researcher Pedro Falé, involves these devices spoofing themselves as mobile phones to interact with AI-generated websites operated by the Fengwo Group.
Falé gained insight into the network by registering an expired domain previously used for telemetry by H96 devices. This allowed him to observe the traffic, revealing that tens of thousands of these streaming sticks were reporting their hardware information and installed applications. Surprisingly, the majority of these devices claimed to be various mobile phone models, including Samsung, Vivo, Huawei, and Xiaomi, a stark contrast to their actual function as TV streaming boxes.
Further investigation traced the malicious activity to Zhejiang Fengwo IoT Technology Ltd, a Chinese company operating under the Fengwo Group. This entity holds patents that align with the functionality of the apps found on the compromised H96 devices. The Fengwo Group utilizes shell identities in Hong Kong and Singapore to collect revenue generated from these fraudulent activities.
The core of the operation involves H96 devices acting as a captive traffic source for ad fraud. The Fengwo Group employs these devices to silently click on ads displayed on websites they control. These websites are populated with machine-generated news articles and graphics across various categories, designed to appear legitimate but primarily serving as a platform for ad fraud.
Notably, the Fengwo Group's domain, fwgcloud[.]com, advertises services related to "AI digital humans" for companionship, customer service, and creative design. This domain shares SSL certificate data with the malicious apps found on the H96 devices, further linking the entities. The group also uses a proprietary implementation of Google's Blockly, a visual programming language, to construct these fraudulent websites.
Blockly's drag-and-drop interface allows low-skilled operators to easily define fraud routines without deep technical knowledge. Once configured, these routines are exported as JavaScript and deployed. This ease of use significantly reduces the Fengwo Group's operational costs by minimizing the need for highly skilled developers.
When an H96 device is tasked with ad fraud, it receives the appropriate Blockly module, which can direct it to visit websites, manage tabs, and click on ads. To ensure these clicks appear human-like, the system integrates vision and reasoning capabilities, allowing the bots to identify and interact with ads effectively.
An interesting observation by Bitsight is the dual nature of these H96 devices: they either act as residential proxies or participate in ad fraud, but not simultaneously. When an HDMI signal is detected, indicating user activity for streaming, the device typically functions as a proxy. When the TV is off, it reverts to its role in the ad fraud network, highlighting a dynamic switching mechanism to avoid detection and maximize its utility for malicious purposes.