Risk Alert
Cheap TV Boxes Become Automated Ad-Fraud Nodes
Bitsight found Fuyao apps on some H96 Android TV boxes that impersonate phones and use YOLO/OCR and Accessibility to browse and click ads automatically.
A July 30 analysis from Bitsight finds that Fuyao apps on some H96 Android TV boxes do more than exploit household internet connections: they can impersonate several smartphone brands and automatically browse and click advertisements. Bitsight's sinkhole confirmed roughly 38,000 devices. The evidence moves the risk from passive proxy abuse toward programmable ad-fraud terminals combining computer vision with Android Accessibility.
Observed and Claimed Scale Are Different
Bitsight confirmed about 38,000 devices through sinkhole data while recording an operator claim of access to 120,000. The figures represent an observable floor and a claim that has not been verified on the same basis, so they should not be combined. Bitsight found Fuyao apps on some H96 boxes and saw devices impersonating phones from Samsung, Vivo, Huawei, and Xiaomi. Krebs reports that such boxes may generate mobile ad clicks in addition to renting out users' connections.
The Fraud Workflow Is Being Software-Defined
Bitsight describes a stack involving Blockly, WebRTC, YOLO/OCR, and Android Accessibility. Blockly can express task flows, visual recognition can interpret pages and ad elements, and Accessibility can execute interface actions. Device-brand and model spoofing then makes activity from a television box resemble mobile traffic. The material change is not merely another malicious app, but a remotely orchestrated chain for browsing, recognizing, and clicking advertisements.
Part of a Larger Gray-Device Ecosystem
HUMAN's 2025 BADBOX 2.0 investigation identified more than one million affected off-brand, uncertified AOSP devices used for ad fraud, click fraud, proxyjacking, and botnet activity. The FBI later highlighted unlocked streaming devices as a risk indicator. That million-device figure covers the wider BADBOX 2.0 ecosystem and is not a Fuyao count. Google identifies Play Protect certification as a practical marker that a device has passed compatibility and security testing.
What to watch next
Concrete follow-up signals include whether the Bitsight sinkhole population declines, whether marketplaces remove relevant H96 listings, and whether carriers or ad platforms can detect the spoofed traffic. For users, the immediate checks are Play Protect certification, unusual outbound traffic, and device provenance. Network activity after isolating or replacing a box can provide additional confirmation.
Sources
- Bitsight — The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids’ Coding Blocks
- Brian Krebs — Read This Before You Buy That TV Streaming Stick
- Federal Bureau of Investigation — Home Internet Connected Devices Facilitate Criminal Activity
- HUMAN Security — HUMAN Exposes BADBOX 2.0 Scheme Infecting 1 Million Off-Brand Android Open Source Project Devices
- Google Android — Android – Certified