← Back to blog

Android TV Boxes Exploited as Proxy Devices for Ad Fraud

Cheap Android TV boxes are being manipulated to spoof phone identities and generate fraudulent ad clicks. Security researchers have traced the campaign back to a Chinese IoT firm.

TL;DR

  • Cheap Android TV boxes found mimicking popular smartphone brands.
  • Devices used to generate fake ad clicks for profit.
  • Campaign dubbed 'Fuyao' linked to Zhejiang Fengwo IoT Technology.
  • Boxes covertly turned into proxy nodes for malicious traffic.
  • Organizations should vet device suppliers and monitor network anomalies.

A recent discovery has revealed that inexpensive Android TV boxes are being exploited in an ad fraud scheme. These devices, often sold without proper oversight, come preloaded with apps that alter their hardware identity to impersonate well-known smartphone brands.

Once disguised, these boxes begin generating illegitimate web traffic by clicking ads on sites operated by the same threat actors. The operation, named Fuyao, has been traced back to Zhejiang Fengwo IoT Technology Co., Ltd., a company based in mainland China. Beyond ad fraud, the infected devices also serve a secondary purpose: acting as unwitting proxies in broader malicious campaigns.

How the Attack Works

  • Infected TV boxes spoof their hardware identifiers to appear as Samsung, Huawei, Xiaomi, or Vivo smartphones.
  • Apps installed on these devices automate ad clicks on operator-controlled websites.
  • Traffic伪装 makes it difficult for ad networks to detect fraudulent activity.
  • The boxes are also configured to route malicious traffic through compromised home networks.

Implications for Businesses

  • Organizations using unverified IoT devices risk exposure to proxy-based threats.
  • Networks may unknowingly host malicious infrastructure due to compromised endpoints.
  • Enterprises should audit third-party device vendors for security compliance.
  • Monitoring for anomalous outbound traffic can help detect similar compromises.
  • Supply chain security for connected devices is critical to prevent unauthorized access.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Android TV Boxes Exploited as Proxy Devices for Ad Fraud — Agent Breach Blog | Agent Breach