In a recent investigation, Bitsight has uncovered a troubling trend involving inexpensive Android TV boxes that have been shipped with applications capable of altering their hardware identity. These apps enable the devices to masquerade as popular smartphone brands such as Samsung, Huawei, Xiaomi, or Vivo, subsequently generating fraudulent ad clicks on websites managed by the same operators.
Operation Fuyao: A Closer Look
The operation, dubbed Fuyao, has been traced back to Zhejiang Fengwo IoT Technology Co., Ltd., a company based in mainland China and established in 2019. The researchers at Bitsight identified this scheme by registering an expired domain that had previously served as a factory backdoor and telemetry collector.
Among the devices identified, the model H96MAXV11 was most frequently reported. However, Bitsight noted that their data was skewed towards older models from a single brand, preventing a comprehensive list of affected devices from being established. In a single day, the sinkhole received an astonishing 65,957 reports from approximately 38,000 unique MAC addresses, with many of these reports misidentifying the devices as phones. This discrepancy arises from the system’s ability to rotate spoofed identifiers, complicating the verification process.
Interestingly, Fengwo has also been promoting over 120,000 “AI digital humans,” although the specifics of this marketing term remain unclear. The figures presented do not correlate directly with the physical fleet size, leaving device owners with general guidance: they are advised to verify Play Protect certification and disconnect any suspicious devices from their networks.
The command-and-control (C2) server associated with Fuyao is responsible for pushing comprehensive phone profiles to each device. This process involves merging a base configuration with model-specific differences while eliminating chipset properties that could reveal the underlying hardware, such as Rockchip, Amlogic, or Allwinner boards.
Fuyao employs machine vision technology within its automation workflow to identify advertisements. The Script app utilizes a YOLOv8s object-detection model, named lourui_2, which has been trained on 12 screen elements, including generic banner regions and Taboola widgets. This model works in conjunction with Android accessibility data and Google ML Kit’s optical character recognition capabilities.
Pedro Falé, a threat researcher at Bitsight, noted that the operation integrates three vision and reasoning systems into a unified interface. Operators create campaign logic using a custom editor based on Blockly, Google’s drag-and-drop programming framework. Each fraud routine is then exported as JavaScript, uploaded to S3, and dispatched to the box for execution.
Through testing across four devices, Bitsight documented around 40 fraud tasks, 21 unique campaigns, and 166 distinct modules. A comment from a recovered developer suggested that the template system allows a small team of skilled engineers to support less experienced campaign operators, thereby reducing operational costs.
The payout structure for Fuyao runs through a publishing network, with Bitsight mapping 144 operator-owned domains across seven beneficiary clusters. Notably, at least 84 of these domains featured a Taboola tag on their homepage. By utilizing Taboola’s public sellers.json file, researchers connected these domains to revenue-generating entities located in Hong Kong and Singapore. Bitsight estimated gross returns at approximately .25 per device per day, translating to around ,500 daily if all 38,000 devices were active.
Furthermore, the annual revenue potential could reach million based on the advertised fleet size, factoring in a 30-40% fraud flagging rate and a 70% ad-fill rate. However, these figures remain estimates and are not derived from observed revenue.
Attribution of the operation to Fengwo is supported by various indicators, including shared TLS certificate data, exposed wiki files, reused email addresses, revenue connections, and patents. Public Chinese patent records also identify Zhejiang Fengwo as the assignee of technologies related to digital-human execution and monitoring. Notably, CN117421142B, granted in November 2024, pertains to execution-flow tracking for digital-human behavior modules, while CN117478834A describes the monitoring of remote screens through cloud-hosted thumbnails and keyframe comparisons. However, neither patent explicitly addresses advertising, nor do they confirm Fengwo’s involvement in the Fuyao operation.
As of the latest updates, there remains uncertainty regarding the installation of these apps and the point in the supply chain at which they were introduced. As of July 31, 2026, Bitsight’s blog index had yet to provide a comprehensive overview of Fuyao, and The Hacker News was unable to locate the anticipated technical follow-up. Consequently, the identification guidance specific to Fuyao remains incomplete.
For device owners, Google offers instructions on verifying Play Protect certification. Additionally, the FBI has advised users to regularly assess their connected devices, disconnect any that appear suspicious, maintain up-to-date firmware, and approach generic streaming boxes marketed with promises of free content with caution.