Fuyao Operation: Cheap Android TV Boxes Hijacked for Ad Fraud and Proxy Services
A new report from **Bitsight** has uncovered a sophisticated ad fraud and proxy network dubbed **Fuyao**, leveraging low-cost Android TV boxes. These devices are secretly reprogramming their hardware identities to impersonate popular phone brands, engaging in covert ad clicking, and even relaying user traffic as SOCKS5 exit nodes.
Cybersecurity firm **Bitsight** has exposed a large-scale operation, **Fuyao**, attributed to **Zhejiang Fengwo IoT Technology Co., Ltd.**, a Chinese company founded in 2019. The operation exploits inexpensive Android TV boxes, transforming them into tools for illicit ad fraud and proxy services.
### Covert Identity Theft and Ad Fraud
**Fuyao**-infected devices rewrite their hardware identities to mimic smartphones from brands like **Samsung**, **Huawei**, **Xiaomi**, or **Vivo**. This spoofing allows them to click ads on websites controlled by the very operators behind the scheme.
### Dual Functionality: Ad Fraud and Proxy Services
The malicious applications on these devices have a dual purpose. When an HDMI signal is detected (indicating the box is in use), it switches to functioning as a **SOCKS5** exit node, relaying other users' traffic through the owner's broadband connection. When the HDMI is off, it reverts to its ad-fraud tasks.
### Discovery Through Expired Domain Registration
**Bitsight** researchers uncovered the operation by registering an expired domain that served as a factory backdoor and telemetry collector for the devices. The majority of identifiable devices reported the model name **H96_MAX_V11**, though **Bitsight** noted their sinkhole view was skewed towards older models from a single brand.
In a single day, after filtering for devices carrying the **Fuyao** apps, the sinkhole received 65,957 reports from approximately 38,000 unique MAC addresses. Most reports misrepresented these devices as phones, and the actual number of affected devices could be higher due to identifier rotation.
### Sophisticated Automation with AI
**Fuyao** employs a sophisticated automation workflow that includes machine vision to locate ads. The embedded Script app utilizes a **YOLOv8s** object-detection model named *lourui_2*, trained to identify 12 screen elements, including generic banner regions and **Taboola** widgets. This model is combined with Android accessibility data and **Google ML Kit** optical character recognition.
Pedro FalΓ©, a **Bitsight** threat researcher, noted that the operation "fuses three vision and reasoning systems into a single interface."
Operators craft campaign logic using a custom editor built on **Blockly**, Google's drag-and-drop programming framework. These fraud routines are then exported as JavaScript, uploaded to **Amazon S3**, and delivered to the infected boxes for execution.
Across four test devices, **Bitsight** observed about 40 fraud tasks, 21 unique campaigns, and 166 unique modules. A recovered developer comment indicated that this template system enabled a small team of skilled engineers to support less-skilled campaign operators, thereby reducing costs.

### Financial Impact and Attribution
**Fuyao**'s payout chain operates through a publishing network. **Bitsight** mapped 144 operator-owned domains across seven beneficiary clusters, with at least 84 loading a **Taboola** tag. By leveraging **Taboola**'s public *sellers.json* file, researchers linked these domains to revenue-collecting entities in Hong Kong and Singapore.
**Bitsight** estimated gross returns at $1.25 per device per day, potentially reaching $47,500 daily if 38,000 devices were active. Annual revenue could reach $40 million at the advertised fleet size, though these are estimates.
Attribution to **Fengwo** is based on shared TLS certificate data, exposed wiki files, reused email addresses, revenue links, and patents. Public Chinese patent records independently identify **Zhejiang Fengwo** as the assignee of related digital-human execution and monitoring technologies, although these filings do not explicitly mention advertising or ad fraud.
### Supply Chain Concerns and Google's Stance
The exact point in the device supply chain where these malicious apps are installed remains unclear.
**Google** has stated that these off-brand devices are not **Play Protect** certified Android devices. "If a device isn't Play Protect certified, Google doesn't have a record of security and compatibility test results. Play Protect certified Android devices undergo extensive testing to ensure quality and user safety," a Google spokesperson explained.
### Recommendations for Users
In June 2025, the **FBI** advised owners to assess connected devices, disconnect suspicious ones, keep firmware updated, and exercise caution with generic streaming boxes promising free content. IT security professionals and privacy-conscious users should be wary of purchasing uncertified Android TV boxes and consider the potential risks associated with these devices.