Some cheap Android TV boxes come with hidden apps that change the device's identity to look like Samsung, Huawei, Xiaomi, or Vivo smartphones, security researchers at Bitsight found. The fake identities are then used to click on online ads, generating illegal revenue for threat actors behind the operation.
Researchers named the operation ‘Fuyao,’ describing it as a large and highly organized botnet that had avoided public detection for several years.
When the TV box detects an HDMI connection, the hidden apps can turn the owner's internet connection into a residential proxy without permission, allowing other people's internet traffic to pass through the home network. When the TV is not in use, the device switches back to carrying out ad fraud tasks.
Bitsight discovered the operation after taking control of an expired domain that had been used as a factory backdoor and telemetry server. Many of the devices reported themselves as the H96_MAX_V11 model, although researchers said a complete list of affected devices is wider.
In a single day, the company's sinkhole recorded nearly 66,000 reports from around 38,000 unique MAC addresses. However, researchers warned this is not an accurate count because the malware frequently changes its hardware identifiers. The operators also advertise more than 120,000 ‘AI digital humans,’ but Bitsight said that figure does not confirm the actual number of infected devices.
According to the report, Fuyao receives complete smartphone profiles from its command server, allowing Android TV boxes to hide the real hardware. The malware removes details that could reveal the devices are actually powered by Rockchip, Amlogic, or Allwinner chipsets.
The botnet combines a YOLOv8 object detection model, optical character recognition, and Android accessibility features to find and interact with online advertisements in a way that appears similar to human behavior. Fraud campaigns are created using Google's Blockly programming framework and then sent to infected devices for execution.
Bitsight observed about 40 fraud tasks, 21 different campaigns, and 166 software modules across four test devices. The researchers also identified 144 websites controlled by the operators, many of which displayed Taboola advertising. Bitsight estimated the operation could generate about $1.25 per device each day, equal to roughly $47,500 daily if around 38,000 devices were active. The company also estimated annual revenue could reach $40 million if the larger advertised network size is accurate.