A company specializing in ad fraud generates $40 million a year with infected Android TV boxes

An investigation into the security of cheap Android TV boxes has uncovered a large-scale ad fraud operation that has remained hidden for years. The operation, dubbed Fuyao, exploits pre-installed apps, device identity spoofing, AI-generated websites, and residential proxy services to generate ad revenue without user consent. According to Bitsight, the operators manage a network of over 120,000 devices, with an estimated annual profit of between $30 and $40 million.

An investigation that started by chance

Researcher Pedro Falé discovered the operation while investigating remote management backdoors left active on Android TV boxes sold to consumers. When a domain used by the backdoor expired, Bitsight's TRACE team registered it, starting to receive telemetry data from devices still in contact with it. Unexpectedly, the devices identified themselves as smartphones from brands like Xiaomi, Samsung, and Huawei, despite containing software typical of TV boxes.

Analysis of the installed applications revealed two recurring apps on both smartphones and TV boxes, suggesting a link to a larger operation. The discovery exposed a complex ecosystem of ad fraud that exploits advanced technologies to evade detection systems.

Computer vision and artificial intelligence at the service of fraud

The Fuyao Enterprise relies on a multi-level structure of command and control (C2) servers, each with specific functions. Once active, an infected TV box can operate in two modes: ad fraud or residential proxy. In fraud mode, the device visits websites controlled by the attackers, filled with AI-generated articles on topics such as finance, health, and food.

The ads on these sites only appear to visitors who seem to come from mobile devices. The infected bots then present false phone properties to pass this check and click on the ads. To find and interact with ads as a person would, the apps combine Android's accessibility services with a YOLO computer vision model and OCR text recognition. This allows the bots to identify and click on banners or content recommendation widgets, rather than relying solely on scripts that might stop working if the site structure changes.

A company dedicated to ad fraud

What sets Fuyao apart from traditional ad fraud operations is its well-organized corporate structure. The operators use Blockly, a visual, block-based programming language designed by Google to teach children the fundamentals of coding, to build the fraud logic. Developers assemble the campaign logic by dragging blocks together in a custom editor, then export the result as JavaScript and upload it to cloud storage for the infected boxes.

A comment left by a Fuyao developer, translated by Bitsight, explains the advantage of this approach: "Only a small number of highly qualified developers are needed to build the execution module template images; developers who create execution modules from these templates have significantly lower technical requirements (...) thus greatly reducing the company's operating costs".

A sophisticated business model

By registering test devices in the botnet and recording the activity pushes sent to them in two different executions, Bitsight captured approximately 166 fraud modules, divided into groups covering browser launch, cache and tab cleaning, page navigation, ad detection, telemetry, and logic specific to a target website.

Bitsight concluded that "Fuyao deviates from the traditional low-effort modus operandi of ad fraud. In fact, an entire company has been created and dedicated exclusively to building a product that conducts these fraudulent activities".

Implications for security and business

The Fuyao operation represents an emblematic case of how advanced technologies can be used for fraudulent purposes. Its discovery raises important questions about the security of IoT devices and the need for greater vigilance by advertising platforms. Furthermore, Fuyao's sophisticated business model suggests that ad fraud operations are becoming increasingly organized and professional.

Next steps for the security community

The discovery of Fuyao underscores the importance of continuing to investigate and monitor suspicious activities in IoT devices. Security companies and advertising platforms must collaborate to develop more effective solutions against these emerging threats. Additionally, end users should be aware of the risks associated with using cheap, non-certified devices.

The investigation into Fuyao is a clear example of how cybersecurity can uncover large-scale criminal operations that exploit the most advanced technologies. The security community must remain vigilant and ready to respond to these continuously evolving threats.

A growing criminal ecosystem

The Fuyao operation represents only the tip of the iceberg of a rapidly growing phenomenon: the use of advanced technologies for large-scale criminal activities. According to security experts, similar operations are proliferating worldwide, exploiting the increasing connectivity of IoT devices and the complexity of global supply chains.

A concerning aspect is the use of legitimate cloud services like Azure to host AI models. This creates unique challenges for tech companies, forced to balance the accessibility of their platforms with the need to prevent abuse.

The economic impact of ad fraud

The global advertising industry loses billions of dollars every year due to fraud like that orchestrated by Fuyao. According to recent estimates, ad fraud could cost the digital economy over $100 billion annually, a problem that threatens the very sustainability of the digital advertising model.

Platforms like Google AdSense and Taboola are implementing advanced technical solutions, including machine learning and behavioral analysis, to detect and block these fraudulent activities. However, the continuous evolution of fraud techniques requires a proactive and collaborative approach among all stakeholders.

The challenge of regulation

The discovery of Fuyao raises important regulatory questions. Authorities in Hong Kong and Singapore, where the front companies associated with the operation are registered, are investigating violations of local laws.

Consumer associations are working to raise awareness of these risks, while IoT device manufacturers are encouraged to adopt more stringent security standards.

Protecting consumers

For end users, the most important lesson is the need to adopt proactive security measures. Experts recommend:

  • Avoiding non-certified or unknown-origin devices
  • Installing regular security updates
  • Monitoring the network activity of your devices
  • Using advanced security solutions on your home routers

Consumer associations are working to raise awareness of these risks, while IoT device manufacturers are encouraged to adopt more stringent security standards.

The future of cybersecurity

The Fuyao case demonstrates that cybersecurity must evolve to keep pace with emerging threats. Universities and research centers are developing new approaches, including:

  • Defensive artificial intelligence systems
  • Advanced behavioral analysis methods
  • Real-time anomaly detection tools

Collaboration between academia, industry, and government will be crucial to developing effective solutions against these sophisticated threats.

A call to action

The global tech community must join forces to combat operations like Fuyao. This requires:

  • Greater transparency from tech platforms
  • Investments in research and development of security solutions
  • International collaboration between law enforcement and regulators
  • Public education on risks and best practices

Only through an integrated and coordinated approach will it be possible to effectively address this growing threat and protect the integrity of the digital ecosystem.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.