Security experts discover a large-scale ad fraud operation via generic TV boxes
Security experts have been raising the alarm for years about the risks associated with using generic TV boxes that promise unlimited streaming of content for a one-time cost. In addition to exploiting the user's Internet connection for illicit activities, these boxes are now at the center of a large-scale ad fraud operation involving AI-generated websites.
Pedro Falé, a threat researcher at security firm Bitsight, discovered a complex ad fraud network by registering an expired domain used to coordinate fake ad clicks on streaming devices known as H96. Falé revealed that the domain, previously used for telemetry, collected complete hardware information and the list of installed apps from tens of thousands of H96 devices worldwide.
Mobile device spoofing
By analyzing the traffic directed to the domain, Falé discovered that almost all TV boxes transmitting data were posing as mobile phone models from various manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. "We noticed something was off," Falé stated. "Many devices reporting to this Android TV Box backdoor were 'phones.'"
The researcher found that all devices reported having the same two apps installed, developed by a company called Zhejiang Fengwo IoT Technology Ltd, based in China. Further investigations revealed that the Fengwo group had registered several patents corresponding to the internal workings of these apps.
AI-generated websites
Bitsight discovered that the Fengwo group's websites contain machine-generated news articles and graphics across a wide range of categories, including finance, health, education, gaming, music, and cooking blogs. However, none of these sites displayed advertisements unless the visiting device matched the spoofed mobile profile of these H96 devices.
AI digital humans
The Fengwo group's domain, fwgcloud[.]com, claims that the company is "redefining the boundaries of human-AI interaction" and has created over 120,000 "AI digital humans" available for rent for various services, including emotional companionship, 24/7 customer support, and creative design.
Blockly and ad fraud
Falé noted that the Fengwo group's domain shared SSL certificate data with other domains associated with the apps found on H96 devices, particularly the phone spoofing mechanism. He also observed that the domain has an internal wiki platform that directly links the Fengwo group to a proprietary implementation of a Google visual programming language called Blockly, originally designed to help children learn to write software.
According to Bitsight, Fengwo group employees use Blockly to build fake websites, allowing operators with limited technical skills to assemble code blocks in their Blockly editor without needing to understand the underlying workings.
Fraud activities
If a user's TV box is selected for a specific fraud task, it will receive the appropriate Blockly module based on the desired task, which can include silently launching a web browser, visiting websites, navigating pages, managing tabs, and clicking on advertisements.
To ensure that TV boxes disguised as mobile phones can reliably click on advertisements displayed on AI-generated websites, the Fengwo group "merges three vision and reasoning systems into a single interface," allowing bots to correctly identify an advertisement on the webpage and navigate the site as a human would.
TV on? Proxy. TV off? Ad fraud
Bitsight discovered that H96 devices were engaged in either ad fraud activities or residential traffic proxy relay, but never simultaneously. When these TV boxes detect an HDMI signal, they assume the TV is on and start running the proxy. When the signal disappears, they switch to ad fraud. If the signal returns, they switch back to proxy mode.
The investigation continues
Bitsight is continuing its investigation into the Fengwo group and its ad fraud network. The security firm believes that this is just the tip of the iceberg and that more such operations may be uncovered in the future.
The discovery of the Fengwo group and its ad fraud network reveals a complex and sophisticated criminal ecosystem. The findings demonstrate the need for a multifaceted approach to address these threats, including technical measures, regulations, and user awareness. Only through close collaboration among all stakeholders will it be possible to effectively combat this form of cybercrime.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are advised to always inform themselves independently before making any decisions.