mediumMalware

Fuyao Android TV Box Ad Fraud and Residential Proxy Botnet

First seen Aug 1, 2026 · Updated Aug 1, 2026

ad-fraudbotnetresidential-proxyiot-securityandroidclick-fraudsupply-chain

Researchers at Bitsight identified an operation dubbed Fuyao in which cheap Android TV boxes ship with pre-installed apps that spoof device identifiers to impersonate Samsung, Huawei, Xiaomi, or Vivo smartphones, enabling large-scale ad fraud. The same devices are also weaponized to covertly route third-party traffic through owners' home broadband connections, effectively turning them into residential proxy nodes. The operation has been attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a China-based manufacturer.

Technical Analysis

The malicious apps modify device hardware identifiers (IMEI, model strings, user-agent data) to mask the true nature of the TV box and present it as a legitimate mobile phone from major OEMs, defeating ad-network fraud detection and enabling click-fraud revenue on operator-controlled ad sites. A secondary function abuses the device's network connection as a residential proxy exit node, likely monetized through proxy-as-a-service offerings that obscure the origin of malicious or fraudulent traffic. This is a firmware/pre-installed software supply-chain issue rather than a post-purchase infection vector, meaning affected devices are compromised out of the box. Organizations using these residential proxy pools for reconnaissance or credential-stuffing operations could gain access to a large, low-attribution IP footprint, complicating network-based threat detection. There is no direct AI agent system impact identified in this report, though enterprises should be aware that residential proxy botnets of this kind are frequently leveraged to mask automated scraping, credential-stuffing, or API-abuse traffic against SaaS and agent-facing endpoints, warranting monitoring of unusual residential-IP traffic patterns hitting agent APIs.

Affected Systems

Low-cost Android-based TV boxes manufactured or supplied with firmware/apps from Zhejiang Fengwo IoT Technology Co., Ltd.; devices with pre-installed apps that spoof Samsung, Huawei, Xiaomi, and Vivo device identifiers

Indicators of Compromise

  • Operation name: Fuyao
  • Attributed entity: Zhejiang Fengwo IoT Technology Co., Ltd.
  • (No specific hashes, IPs, or domains provided in source reporting)

Remediation Steps

  1. 1

    Vet IoT/TV box supply chains

    Avoid procuring low-cost, unbranded Android TV boxes from unverified manufacturers, especially for corporate or shared network environments.

  2. 2

    Network segmentation

    Isolate consumer IoT/streaming devices on separate VLANs away from corporate networks and sensitive systems.

  3. 3

    Traffic monitoring

    Monitor outbound traffic from consumer devices for proxying behavior, unusual ad-network communications, or traffic inconsistent with device function.

  4. 4

    Firmware auditing

    Inspect pre-installed applications and device identifiers on IoT hardware before deployment; flag devices reporting mismatched or spoofed hardware IDs.

  5. 5

    Residential proxy traffic scrutiny

    For organizations exposing APIs or agent endpoints, apply anomaly detection on residential IP-sourced traffic that may originate from compromised consumer devices.

Industries Most Exposed

consumer electronicsadvertising technologytelecommunicationsretail

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.