Ethical Hacking News
The Fuyao Android TV box botnet poses a significant threat to consumer security, with millions of devices potentially being compromised. Learn more about this emerging threat in our comprehensive article.
The Fuyao Android TV box botnet is a sophisticated operation attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China-based company.The botnet ships with apps that rewrite hardware identity to mimic popular brands, posing as legitimate devices and click ads on websites run by the same operators.A total of 65,957 reports from 38,000 unique MAC addresses were received by researchers after filtering for devices carrying Fuyao apps.The operation utilizes machine vision and automation workflows to locate ads and push complete phone profiles to each device.Bitsight estimates that the botnet's annual revenue could reach $40 million at an advertised fleet size of 120,000 devices.The attribution to Fengwo rests on shared TLS certificate data, exposed wiki files, reused email addresses, and patents, but no direct evidence establishes its involvement in ad fraud.
The world of cybersecurity is a vast and complex landscape, constantly evolving as new threats emerge and old ones are adapted by malicious actors. In recent times, a concerning trend has come to light, highlighting the vulnerabilities that exist within the consumer electronics industry. At the center of this story lies the Fuyao Android TV box botnet, a sophisticated operation that has left many in the cybersecurity community scratching their heads.
The Fuyao operation is attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China-based company founded in 2019. According to recent reports, some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic popular brands such as Samsung, Huawei, Xiaomi, or Vivo phones. These apps not only pose as legitimate devices but also click ads on websites run by the same operators, further exacerbating the issue.
Researchers from Bitsight discovered this operation after registering an expired domain used as a factory backdoor and telemetry collector. Upon investigation, they found that most identifiable devices reported the model name H96_MAX_V11, although their sinkhole view was skewed toward older models from one brand, leaving the complete affected-model list incomplete. In one day, after filtering for devices carrying the Fuyao apps, the sinkhole received 65,957 reports from about 38,000 unique MAC addresses.
The majority of these reports described the devices as phones, which is not a confirmed device count because the system can rotate spoofed identifiers. The report separately shows Fengwo advertising more than 120,000 "AI digital humans," but does not establish what that marketing term counts. These figures are not interchangeable, and none establishes the physical fleet size.
For owners of these affected devices, guidance remains generic: verify Play Protect certification and disconnect suspicious devices from the network. The command-and-control (C2) server pushes complete phone profiles to each device, merging a base configuration with a per-model diff and deleting chipset properties that would expose a Rockchip, Amlogic, or Allwinner board underneath.
The Fuyao operation utilizes machine vision inside its automation workflow to locate ads. A Script app carries a YOLOv8s object-detection model named lourui_2, trained on 12 screen elements, including generic banner regions and Taboola widgets. The app combines the model with Android accessibility data and Google ML Kit optical character recognition.
Pedro Falé, a Bitsight threat researcher, wrote that the operation "fuses three vision and reasoning systems into a single interface." Operators assemble campaign logic in a custom editor built on Blockly, Google's drag-and-drop programming framework. They export each fraud routine as JavaScript, upload it to S3, and send it to the box for execution.
Across four test devices, Bitsight captured about 40 fraud tasks, 21 unique campaigns, and 166 unique modules. A recovered developer comment said the template system let a small group of skilled engineers support less-skilled campaign operators, cutting costs.
Fuyao's payout chain runs through a publishing network. Bitsight mapped 144 operator-owned domains across seven beneficiary clusters. At least 84 of them loaded a Taboola tag on the homepage. The researchers said they used Taboola's public sellers.json file to connect the domains to revenue-collecting entities in Hong Kong and Singapore.
Bitsight estimated annual revenue could reach $40 million at the advertised fleet size, citing 30-40% fraud flagging and a 70% ad-fill rate, but did not show the full calculation. Attribution to Fengwo rests on Bitsight, which cited shared TLS certificate data, exposed wiki files, reused email addresses, revenue links, and patents.
Public Chinese patent records independently identify Zhejiang Fengwo as the assignee of related digital-human execution and monitoring technologies. CN117421142B, granted in November 2024, covers execution-flow tracking for digital-human behavior modules, while CN117478834A describes monitoring remote screens through cloud-hosted thumbnails and keyframe comparison. Neither filing describes advertising, and the records do not establish that the company operated Fuyao or engaged in ad fraud.
The sources checked also do not establish who installed the apps or at what point in the device supply chain they appeared. As of 7:48 p.m. IST on July 31, 2026, Bitsight's blog index still listed only the July 30 overview for Fuyao, and The Hacker News could not find either promised technical follow-up in exact-title site searches.
Google explains how to check whether a device is Play Protect certified. In June 2025, the FBI advised owners assess connected devices, disconnect suspicious ones, keep firmware current, and treat generic streaming boxes sold on promises of free content as suspect.
Related Information:
https://www.ethicalhackingnews.com/articles/Cybersecurity-Threats-in-Deep-Dive-The-Fuyao-Android-TV-Box-Botnet-ehn.shtml
https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
Published: Fri Jul 31 11:11:36 2026 by llama3.2 3B Q4_K_M