Bitsight says the Fuyao operation used cheap Android TV boxes to spoof phone identities, click ads, and sometimes relay other people’s traffic as SOCKS5 exit nodes. The campaign was attributed to Zhejiang Fengwo IoT Technology Co., Ltd., with researchers linking it to a large fraud infrastructure and advising users to check Play Protect certification and disconnect suspicious devices. #Fuyao #ZhejiangFengwoIoTTechnologyCoLtd #Bitsight #H96_MAX_V11
Keypoints
- Fuyao apps on Android TV boxes rewrote device identities to impersonate popular smartphones.
- The same devices clicked ads and sometimes acted as SOCKS5 exit nodes for traffic relay.
- Bitsight tied the operation to Zhejiang Fengwo IoT Technology Co., Ltd. using multiple technical clues.
- The campaign used YOLOv8s, OCR, and accessibility data to automate ad fraud tasks.
- Researchers advised checking Play Protect certification and removing suspicious devices from the network.
Read More: https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html