the feed MANY MINDED · THE BRIEF
SECURITY · friction · impact 2/5 · 2026-08-03 · Bitsight

Those cheap streaming sticks are clicking ads for someone

Bitsight traced tens of thousands of H96 TV boxes spoofing phones to click ads on AI-generated sites for a China-based group.

A Bitsight investigation published on 30 July 2026 and reported by Krebs on Security found that cheap generic TV streaming boxes are not only renting out their owners' internet connections, as security researchers have warned for years, but are also running a large-scale advertising fraud operation.

Threat researcher Pedro Falé got inside the network by registering an expired domain name that had been used to coordinate fake ad clicks across H96 devices, a popular brand of Android TV box. The domain had been collecting telemetry — full hardware information and complete installed-app lists — from tens of thousands of H96 sticks plugged into televisions around the globe. Inspecting the traffic, Falé found that nearly all of the boxes were reporting themselves as mobile phone models from manufacturers including Samsung, Vivo, Huawei and Xiaomi.

Every device carried the same two apps, made by Zhejiang Fengwo IoT Technology Ltd, a mainland Chinese company founded in 2019 that operates an advertising portfolio as Fengwo Group. Fengwo has registered multiple patents matching how the apps work. Bitsight traced the monetisation through shell identities registered in Hong Kong, Singapore and to single individuals. The apps use the TV boxes as a captive traffic source to click advertisements on machine-generated websites the group itself operates.

The abundance reading is uncomfortable but simple. A device sold for a one-time fee with unlimited content is not cheap — it is subsidised, and the subsidy is paid with the buyer's bandwidth, their household's standing on the network, and by advertisers defrauded downstream. Genuinely cheap goods and hidden-cost goods look identical at the point of sale, which is the whole problem.

This is a single security firm's investigation of one device family; its scale beyond H96 is not established here.

Source: Krebs on Security