Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Why Every Buyer Should Question a TV Streaming Stick Before Purchase

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-08-06 T 17:31:31 Z | [ 2 MIN READ ]
Why Every Buyer Should Question a TV Streaming Stick Before Purchase
2 Min Read
Share

Security researchers have uncovered a hidden ad‑fraud engine inside cheap TV streaming sticks that masquerade as smartphones to click AI‑generated ads.

TV streaming stick ad‑fraud uncovered

Pedro Falé, a threat analyst at Bitsight, registered an expired domain linked to the popular H96 device and observed telemetry that harvested full hardware specs from tens of thousands of units worldwide.

“We noticed something was wildly wrong,” Falé told Reuters.

The data showed each box reporting itself as a phone from manufacturers such as Samsung, Huawei or Xiaomi, while running two identical apps from Zhejiang Fengwo IoT Technology Ltd. Those apps coordinate a massive click‑farm that targets AI‑generated news sites, only serving ads when the visitor’s profile matches the spoofed mobile device.

How the fraud chain works

When the attached TV is off, the stick receives a Blockly‑generated JavaScript module that silently launches a browser, navigates pages and clicks ads. When the screen is on, the same hardware flips to act as a residential proxy, leasing the user’s IP address to anonymous renters – from content scrapers to ticket scalpers.

The operation nets roughly ↑ $50,000 per day, based on telemetry from ↓ 38,000 compromised devices, according to Bitsight’s analysis.

Fengwo’s public site boasts more than 120,000 “AI digital humans” for rent, a claim that appears to be a marketing veneer designed to mask the true scale of the botnet.

Authorities, including the FBI, have repeatedly warned about the privacy hazards of such off‑brand streaming hardware, yet major retailers continue to list them alongside legitimate Android TV boxes.

Consumers can verify a device’s authenticity by checking for Google’s Play Protect certification – a step that can prevent the inadvertent enrollment in these illicit networks.

For broader context on how hidden threats have surged since the pandemic, see our ongoing coverage.


Reported by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026
Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.