Cheap Android TV Boxes Pose as Phones, Exploit User Networks

Recent investigations have uncovered that certain low-cost Android TV boxes are pre-installed with applications that manipulate their hardware identifiers to impersonate popular smartphone brands such as Samsung, Huawei, Xiaomi, and Vivo. This deceptive practice enables the devices to engage in fraudulent activities, including generating fake ad clicks on websites operated by the same entities responsible for the malware.

The operation, dubbed “Fuyao,” has been linked to Zhejiang Fengwo IoT Technology Co., Ltd., a company based in mainland China and established in 2019. The malicious applications not only falsify device identities but also exploit users’ broadband connections. When these TV boxes detect an active HDMI signal, they transform the user’s network into a proxy, routing external traffic through the owner’s internet connection. In the absence of an HDMI signal, the devices revert to executing ad fraud tasks.

Security researchers identified this scheme by registering an expired domain previously used as a factory backdoor and telemetry collector. Analysis revealed that a significant number of these compromised devices report the model name H96_MAX_V11. However, this finding may not represent the full scope of affected models. In a single day, the monitoring system received nearly 66,000 reports from approximately 38,000 unique MAC addresses, with most devices masquerading as smartphones. It’s important to note that these figures may be inflated due to the devices’ ability to rotate spoofed identifiers.

Further examination of the operation revealed that the command-and-control server dispatches comprehensive phone profiles to each device. These profiles merge base configurations with model-specific differences and omit chipset properties that would reveal the underlying hardware, such as Rockchip, Amlogic, or Allwinner boards.

The fraudulent activities are sophisticated, employing machine vision to identify and interact with advertisements. The malicious applications utilize object-detection models trained to recognize various screen elements, including banner ads and widgets. This technology is combined with Android accessibility features and optical character recognition to execute the ad fraud seamlessly.

Operators behind Fuyao design their fraudulent campaigns using a custom editor built on Google’s Blockly framework, allowing them to create and deploy JavaScript-based fraud routines efficiently. Analysis of test devices uncovered numerous fraud tasks and campaigns, indicating a well-organized and scalable operation.

Financially, the operation appears lucrative. Researchers estimate that each compromised device could generate approximately $1.25 per day, leading to potential daily earnings of around $47,500 if all identified devices are active. Projections suggest that, at the advertised fleet size, annual revenues could reach up to $40 million, though these figures are based on estimates and not confirmed earnings.

Attribution to Zhejiang Fengwo IoT Technology Co., Ltd. is supported by various indicators, including shared TLS certificate data, exposed internal documentation, reused email addresses, revenue links, and related patents. Public Chinese patent records further identify the company as the assignee of technologies pertinent to the operation.

For consumers, this development underscores the importance of vigilance when purchasing and using internet-connected devices. To mitigate risks, users should verify the certification of devices, such as ensuring they are Play Protect certified, and disconnect any suspicious devices from their networks. This incident highlights the broader issue of security vulnerabilities in budget electronics and the need for increased scrutiny and regulation to protect consumers from such malicious activities.