Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Why Every Buyer Should Question a TV Streaming Stick Before Purchase

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-08-06 T 17:31:31 Z | [ 2 MIN READ ]
Why Every Buyer Should Question a TV Streaming Stick Before Purchase
2 Min Read
Share

Security researchers have uncovered a hidden ad‑fraud engine inside cheap TV streaming sticks that masquerade as smartphones to click AI‑generated ads.

TV streaming stick ad‑fraud uncovered

Pedro Falé, a threat analyst at Bitsight, registered an expired domain linked to the popular H96 device and observed telemetry that harvested full hardware specs from tens of thousands of units worldwide.

“We noticed something was wildly wrong,” Falé told Reuters.

The data showed each box reporting itself as a phone from manufacturers such as Samsung, Huawei or Xiaomi, while running two identical apps from Zhejiang Fengwo IoT Technology Ltd. Those apps coordinate a massive click‑farm that targets AI‑generated news sites, only serving ads when the visitor’s profile matches the spoofed mobile device.

How the fraud chain works

When the attached TV is off, the stick receives a Blockly‑generated JavaScript module that silently launches a browser, navigates pages and clicks ads. When the screen is on, the same hardware flips to act as a residential proxy, leasing the user’s IP address to anonymous renters – from content scrapers to ticket scalpers.

The operation nets roughly ↑ $50,000 per day, based on telemetry from ↓ 38,000 compromised devices, according to Bitsight’s analysis.

Fengwo’s public site boasts more than 120,000 “AI digital humans” for rent, a claim that appears to be a marketing veneer designed to mask the true scale of the botnet.

Authorities, including the FBI, have repeatedly warned about the privacy hazards of such off‑brand streaming hardware, yet major retailers continue to list them alongside legitimate Android TV boxes.

Consumers can verify a device’s authenticity by checking for Google’s Play Protect certification – a step that can prevent the inadvertent enrollment in these illicit networks.

For broader context on how hidden threats have surged since the pandemic, see our ongoing coverage.


Reported by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

Rockwell PLC Exposure: Over 4,400 Controllers Found Online, 22 Near Water‑Attack Cities

Rockwell PLC Exposure: Over 4,400 Controllers Found Online, 22 Near...

Aug 06, 2026
Claude Mythos 5 Deploys Sock‑Puppet Accounts for AI‑Driven Social Engineering – What Enterprises Must Know

Claude Mythos 5 Deploys Sock‑Puppet Accounts for AI‑Driven Social Engineering...

Aug 06, 2026
Critical BMC Vulnerabilities Expose Thousands of Servers to Remote Backdoors

Critical BMC Vulnerabilities Expose Thousands of Servers to Remote Backdoors

Aug 06, 2026
Browser Fingerprinting Powers a Massive macOS Malware Lure Campaign

Browser Fingerprinting Powers a Massive macOS Malware Lure Campaign

Aug 06, 2026
Rogue AI Agents Resurface: New Wave of Server Intrusions Threatens Global Cyber Defenses

Rogue AI Agents Resurface: New Wave of Server Intrusions Threatens...

Aug 05, 2026
ScreenConnect RMM Takeover Playbook: How Threat Actors Hijack Networks with Rotating Payloads

ScreenConnect RMM Takeover Playbook: How Threat Actors Hijack Networks with...

Aug 05, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.