CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Cheap Android TV Boxes Hijacked as Ad-Fraud Proxies: Fuyao Operation Exposed

July 31, 2026

Cybersecurity firm Bitsight has uncovered a large-scale operation dubbed ‘Fuyao’ involving cheap Android TV boxes that secretly impersonate smartphones to commit ad fraud and turn owners’ broadband connections into proxy exit nodes. The malicious apps, attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019, rewrite the devices’ hardware identity to mimic popular phone brands such as Samsung, Huawei, Xiaomi, and Vivo.

According to Bitsight’s research, the apps perform two primary functions. When the TV box detects an HDMI signal, it switches to relaying other people’s internet traffic through the owner’s broadband line as a SOCKS5 exit node. When HDMI is off, the device waits for ad-fraud tasks. The operation uses machine vision, including a YOLOv8s object-detection model named ‘lourui_2’, combined with Android accessibility data and Google ML Kit OCR, to locate and click on ads. Campaign logic is assembled using Google’s Blockly framework and executed as JavaScript.

Bitsight discovered the operation by registering an expired domain used as a factory backdoor and telemetry collector. In a single day, the sinkhole received 65,957 reports from about 38,000 unique MAC addresses, though the actual device count may be lower due to spoofed identifiers. The researchers mapped 144 operator-owned domains across seven beneficiary clusters, with at least 84 loading Taboola tags. They estimated gross returns at $1.25 per device per day, potentially reaching $47,500 daily if 38,000 devices were active, and annual revenue could hit $40 million at the advertised fleet size.

Attribution to Fengwo is based on shared TLS certificates, exposed wiki files, reused email addresses, and patents. Public Chinese patent records identify Fengwo as the assignee of related digital-human execution and monitoring technologies, though these do not directly link the company to ad fraud. The researchers noted that the full technical details, including affected packages and network indicators, have not yet been published. Owners are advised to verify Play Protect certification and disconnect suspicious devices from their networks.

CVEs: CVE-2026-50522

Attack groups: Fuyao

Malware: Fuyao apps

Companies: Bitsight, Zhejiang Fengwo IoT Technology Co., Ltd., Google, Taboola

Products: Android TV boxes, YOLOv8s, Google ML Kit, Blockly