Security Researchers Link H96 Streaming Boxes to Ad Fraud and Proxy Networks
Security researchers are warning that some low-cost TV streaming devices may be doing far more than delivering video. A new analysis from Bitsight links a widely sold class of H96 Android-based boxes...
Security researchers are warning that some low-cost TV streaming devices may be doing far more than delivering video. A new analysis from Bitsight links a widely sold class of H96 Android-based boxes to both residential proxy services and an advertising-fraud operation.
Pedro Falé, a threat researcher at Bitsight, investigated an expired domain previously used by the operation for device telemetry. Traffic sent to the domain reportedly included hardware details and installed-application lists from tens of thousands of devices. Although the hardware was identified as TV boxes, many devices presented themselves as smartphones made by companies such as Samsung, Vivo, Huawei and Xiaomi.
Researchers associated the activity with two applications developed by Zhejiang Fengwo IoT Technology, a Chinese company operating under the Fengwo Group name. According to Bitsight, the apps can receive instructions to open browsers, visit webpages, navigate tabs and interact with online advertisements.
The associated websites reportedly contain machine-generated material covering subjects such as finance, health, education, games, music and food. Bitsight said the sites served advertisements only when visitors matched the mobile-device profiles used by the H96 boxes. The operation allegedly uses automated visual and reasoning systems to locate ads and imitate browser activity that appears human.
Two uses for the same device
Bitsight’s analysis suggests the boxes alternate between ad-fraud work and residential proxy activity. When a device detects an active HDMI connection, indicating that a television is being used, it generally operates as a proxy. When the display is off, it may become available for advertising tasks. The separation may help prevent background activity from disrupting streaming performance.
Researchers also found evidence that Fengwo uses Blockly, Google’s visual programming framework, to assemble and distribute fraud routines. This approach can allow less-specialized operators to create task modules without writing conventional code.
Bitsight estimated that about 38,000 devices had contacted the expired domain. The findings add to longstanding warnings from security researchers and law-enforcement agencies about inexpensive, unofficial Android streaming hardware. Such products may include proxy software, weak security controls and undocumented services that expose a household’s Internet connection to third parties.
Consumers should favor reputable streaming platforms, keep network devices isolated where possible, change default credentials and avoid hardware advertised as providing unrestricted access to paid content.
