Sophisticated ad fraud and spying operations surface in cheap Android TV boxes

Security researchers uncover a complex campaign exploiting low-cost Android TV boxes to facilitate ad fraud, covert spying, and proxy networks, raising concerns over consumer security and privacy.

Cheap Android TV boxes can offer a bargain, but security researchers say some may also carry hidden costs. According to Bitsight, a covert operation it has dubbed Fuyao Enterprise appears to have used certain low-cost boxes not only to traffic outside internet requests through home connections, but also to pose as smartphones, load AI-generated sites and click adverts in the background. The firm said the activity could earn money through ad fraud or turn the devices into residential proxy nodes that mask the origin of other people’s online activity.

Bitsight said its researchers traced the campaign after examining an expired domain linked to factory backdoors on some devices. Once the team reactivated it, the boxes that connected to it began sending hardware details and lists of installed applications. Many identified themselves as phones from brands such as Samsung, Vivo, Huawei and Xiaomi, despite showing signs of being TV boxes, prompting the researchers to conclude that something was amiss. The company says the software most often appeared on older H96 Max V11 devices, although it stressed that the available evidence does not prove every device in that line is affected or identify exactly where in the supply chain the code was added.

That uncertainty matters, because budget Android TV hardware has been a recurring security problem. Kaspersky has previously warned that cheap boxes can be conscripted into botnets and used as proxy nodes or for ad fraud, while TechRadar and Human Security have reported on other low-cost models that shipped with malware tied to the Badbox campaign and the Mirai trojan. Those cases underline the same broader risk: devices sold with little oversight, weak update support or unofficial software can arrive on a home network already compromised.

Bitsight says Fuyao was unusually sophisticated. The company claims the system could switch roles depending on whether the television was in use: when an HDMI signal suggested someone was watching, the box would act as a residential proxy; when the screen was off, it could move to ad fraud. The researchers said the operation used computer vision to find adverts when page layouts changed and relied on a customised version of Google’s Blockly to automate tasks across a network the firm mapped to 144 websites. On one 24-hour sample, Bitsight observed 65,957 reports tied to about 38,000 unique MAC addresses, and estimated possible ad-fraud revenue of roughly $47,500 a day on that basis, with a larger claimed fleet potentially generating more.

Google, in comments relayed to Fox News, said the affected devices were based on Android Open Source Project software rather than official Android TV OS builds, and were not Play Protect certified. That distinction is important: uncertified devices do not have Google’s security and compatibility test results on record, and factory resets may not remove malware embedded in firmware. The safer approach is to buy from recognised manufacturers, avoid boxes advertised as “fully loaded” or “unlocked”, check Play Protect certification in the Play Store, keep streaming devices on a guest network where possible, and disconnect any box that shows unexplained traffic or suspicious behaviour. The FBI has also warned that compromised streaming devices can be used in residential proxy networks and has asked consumers to report suspected cases through the Internet Crime Complaint Centre.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.