Cheap TV Boxes Linked to Secret Ad Click Fraud

Featured & Cover Cheap TV Boxes Linked to Secret Ad Click Fraud

Researchers warn that some inexpensive H96 Android TV boxes may be engaging in ad fraud and routing external internet traffic through users’ home Wi-Fi connections.

In a troubling revelation, security researchers from Bitsight have discovered that certain low-cost H96 Android TV boxes could be secretly clicking ads and routing external internet traffic through users’ home Wi-Fi networks. This hidden activity raises significant security and privacy concerns for consumers who may unknowingly be facilitating ad fraud.

When you plug a streaming box into your television and connect it to Wi-Fi, you might expect it to serve as a simple device for watching movies and shows. However, researchers have found that some of these inexpensive Android TV boxes are capable of much more nefarious activities. According to Bitsight, these devices can masquerade as smartphones, visit AI-generated websites, and engage in ad-clicking schemes that generate revenue for unknown operators.

Pedro Falé, a threat researcher at Bitsight, uncovered this operation while investigating security risks associated with cheap Android TV boxes. His team identified an expired domain that had previously managed factory backdoors on specific devices. By registering the domain, Bitsight began monitoring the information sent to it, revealing alarming findings.

Researchers noted that many of the devices identified themselves as smartphones from well-known brands such as Samsung, Vivo, Huawei, and Xiaomi, despite their software indicating they were TV boxes. Falé remarked that the situation was “wildly wrong,” leading to the operation being dubbed the Fuyao Enterprise.

Bitsight’s investigation revealed that the Fuyao apps appeared preinstalled on some Android TV boxes sold under the H96 brand, particularly older H96 Max V11 models. However, the data collected only pertained to specific older models that reported to the expired domain, meaning not every H96 device is necessarily compromised. The researchers also suggested that the malicious software could have been added by an original equipment distributor or reseller before the boxes reached consumers.

A spokesperson for Google clarified that the infected devices are Android Open Source Project (AOSP) devices, not certified Android TV OS devices. This distinction is crucial, as AOSP devices lack the security and compatibility test results that certified devices possess. Therefore, consumers should exercise caution when purchasing these low-cost streaming boxes.

While Bitsight has not released a comprehensive list of all devices connected to the Fuyao operation, they found the apps most frequently on older H96 Max V11 boxes. However, this does not guarantee that all such devices are affected. Google has indicated that it does not have the H96 device name registered as a certified device, but additional technical information would be needed to confirm its certification status.

Consumers are advised to be vigilant if their streaming box exhibits certain warning signs. Although these indicators do not definitively prove the presence of Fuyao software, they warrant caution. Malicious software may be embedded in the firmware, making a factory reset ineffective in removing it. If you suspect your device is compromised, disconnect it from your network and consider replacing it with a certified device from a reputable manufacturer.

Bitsight’s research indicates that the Fuyao software can disguise a TV box as a smartphone, allowing it to interact with operator-controlled websites that contain AI-generated content. This enables the box to view and click on ads, appearing to ad networks as if a mobile user is engaging with the content. The researchers mapped 144 websites associated with the operation, suggesting that the network could be even larger.

One of the more unusual findings from Bitsight involved the HDMI connection of the TV boxes. The researchers discovered that the devices could alternate between two revenue-generating roles. When the HDMI signal indicated that someone was watching TV, the box would often function as a residential proxy. Conversely, when the TV was turned off, it could switch to ad fraud activities. This dual functionality helps prevent the ad activity from interfering with streaming services.

A residential proxy allows external internet traffic to be routed through a home connection, masking the true location of the user. While residential proxies can serve legitimate purposes, they can also be exploited by criminals to obscure their activities. Owners of compromised boxes may remain unaware that their home internet connection is being used for external traffic.

The FBI has previously warned that compromised streaming boxes and other connected devices can provide criminals access to residential proxy networks. Malware may be preinstalled or introduced through unofficial apps, highlighting the risks associated with inexpensive electronics.

In a recent 24-hour analysis, Bitsight observed nearly 66,000 reports linked to approximately 38,000 unique MAC addresses that appeared to have the Fuyao apps installed. However, researchers cautioned that spoofing could inflate these numbers. Their visibility was limited to older models from one brand, making it difficult to ascertain the full extent of the operation.

Based on their findings, Bitsight estimated that the potential ad fraud revenue from the observed devices could reach about $47,500 per day. The researchers also noted that the Fengwo Group, which operates under the name Zhejiang Fengwo IoT Technology Co., Ltd., is likely behind the Fuyao operation. This attribution is based on shared digital certificates, internal files, and company patents that align with parts of the Fuyao system.

As consumers navigate the world of streaming devices, it is essential to prioritize security. When purchasing streaming devices, opt for brands that offer regular security updates and customer support. Be wary of unfamiliar brands that promise free access to paid content, and avoid products marketed as “fully loaded” or “unlocked.”

Google recommends checking whether your device is Play Protect certified. To do this, open the Google Play Store on your streaming device, select your profile icon, and navigate to Settings > About. Look for Play Protect certification status, as uncertified devices lack security and compatibility test results.

In conclusion, while low-cost streaming boxes may seem like a bargain, they can pose significant risks to your home network and personal data. If you suspect your device is compromised, disconnect it and consider replacing it with a certified alternative. Always stay informed about the potential threats associated with connected devices.

For more information on this issue, refer to Bitsight.

Leave a Reply

Your email address will not be published. Required fields are marked *

More Related Stories

-+=