购买电视棒之前请阅读本文

标签: | 发表时间:2026-07-31 08:55 | 作者:
出处:https://krebsonsecurity.com

多年来,安全专家一直警告称,使用那些承诺一次性付费即可无限量观看流媒体内容的通用电视盒存在风险,因为它们会暗中将用户的互联网连接出租给陌生人。但一项突破性的新分析发现,这些设备还会伪装成手机,点击人工智能生成的网站上的广告,这是旨在欺骗在线商家和广告网络的庞大行动的一部分。

佩德罗·法莱是安全公司 Bitsight的威胁研究员。法莱告诉KrebsOnSecurity,他通过注册一个过期域名,得以窥探一个庞大而复杂的广告欺诈网络。该域名被用于协调在一种名为 H96的热门流媒体设备上的虚假广告点击。


Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.

Pedro Faléis a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96.

An H96 TV streaming device currently advertised for sale on Amazon.

Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.

“We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'”

Image: Bitsight.

The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name Fengwo Group. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

“Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Falé wrotein a report released today about their findings.

Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group.

Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices.

AI DIGITAL HUMANS

The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design.

The homepage for fwgcloud dot com.

Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

The Blockly homepage.

“An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsight’s report. “Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.”

Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that “only a small number of highly-skilled developers are needed to build the template execution-unit images,” and that “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.”

Falé said if a user’s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads.

To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group “fuses three vision and reasoning systems into a single interface,” allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed.

Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight.

TV ON? PROXY. TV OFF? AD FRAUD

Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

Falé said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device’s stated purpose — streaming video content over the Internet.

Despite repeated warnings from the FBIand security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed ( via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.

Image: fbi.gov.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxysoftware pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.

What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthientdocumented how multiple botnets had rapidly enslaved millions of TV boxesusing a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.

SHOW ME THE MONEY

Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain, and based on that number the report estimates this ad fraud network brings in revenues of close to $50,000 a day (not counting substantial revenue from the residential proxy side of the business). However, Falé emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group’s core (but older) domains.

As for the Fengwo Group’s claim to have 120,000 “digital humans” at their disposal, Bitsight’s report concludes it could be just a clever marketing scheme and/or a way to avoid drawing suspicion to the company’s operations.

“Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size,” Falé wrote in the report. “This could also be the case here.”

If the Fengwo Group truly does have tens of thousands of “AI humans” at its beck and call, it does not appear to have dedicated any of them to fielding inquiries from its own website. KrebsOnSecurity sought comment from the Fengwo Group by emailing the contact address listed on the company’s homepage, but the request bounced back with the reply, “Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now.”

As Bitsight’s analysis shows, when it comes to TV boxes and streaming sticks, it’s best to stick to name brands from reputable manufacturers, and then to be sparing and careful with any apps you choose to install on the device — as many of those can bundle residential proxy software as well. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.

Additionally, Synthient maintains a running list of IoT devicesthat have been known to ship to consumers with residential proxy software and other malicious apps pre-installed. Careful readers will notice Synthient’s list includes other IoT devices apart from streaming sticks and boxes: As the FBI has warned, residential proxy software has also been found in other popular consumer IoT devices from random brands, particularly digital photo frames.

相关 [购买 电视 阅读] 推荐:

购买电视棒之前请阅读本文

- -
多年来,安全专家一直警告称,使用那些承诺一次性付费即可无限量观看流媒体内容的通用电视盒存在风险,因为它们会暗中将用户的互联网连接出租给陌生人. 但一项突破性的新分析发现,这些设备还会伪装成手机,点击人工智能生成的网站上的广告,这是旨在欺骗在线商家和广告网络的庞大行动的一部分. 佩德罗·法莱是安全公司 Bitsight的威胁研究员.

移动阅读与阅读

- - 扯氮集--上海魏武挥的博客 - 扯氮集--上海魏武挥的博客
近日,由中国新闻出版研究院组织实施的第十次全国国民阅读调查显示,国民在数字阅读这个维度上的比例有所上升,从11年的38.6%小幅增加到12年的40.3%,而电子书阅读,更是有比较可观的增幅,从11年的人均1.42本到12年的2.35本. 另外一个消息是,搜狐移动设备上的新闻客户端,累计下载安装量已经破亿.

伪阅读

- coen - 情书
    在一次百老汇大街边的午餐交谈中,关于阅读,我和我的荷兰同事达成一个共识:学术生涯实际上是一个摧毁阅读的过程.    从道理上来说,怎么会呢. 从事学术工作,尤其是社会科学的学术工作,我们最有条件进行大量阅读了.     但事实是,学术工作从以下几方面摧毁了阅读及其乐趣:第一,为了“研究”需要,你的阅读范围一般都非常狭窄.

社会化阅读:阅读的未来

- waco - 互联网的那点事...
本文来自MTC联合创始人,社会化阅读观察员钟雄的投稿,新浪微博@钟雄这Y. 从传统阅读到数字阅读,不仅是媒介的变化,更是阅读习惯的改变,它降低了阅读门槛,提高了获取知识的效率,推动了文明的进程,更催生了网络原创文学. 但是,看到自己想看的内容,并与志同道合的朋友交流分享的需求并没有被很好的满足,因此以读者为中心,基内内容获取个性化,分享交流社区化的社会化阅读正成为阅读的未来.

未来的阅读

- xj - 左岸读书_blog
雪茉莉灵感突至,写了一篇对未来阅读的设想. 2010年年末的时候,听了一场主题为“新媒体的未来”的讲座,引发了我对未来阅读模式的思考,在我的想象中,未来的阅读体验应该是这样的:. 下班的途中,坐在车上,我从包包里拿出了我的“墨宝”,开始阅读. “墨宝”(Mobile Book Reader)是类似于Ipad的东东,但是比Ipad轻、薄、更小巧,更时尚,功能更强大,使用更方便.

《观止》阅读录

- Calvin998 - 阿朱=行业趋势+开发管理+架构
观止这本书讲的是微软在1989年-1993年这5年开发WINDOWS NT的故事.观止,是叹为观止的意思.意思是好到了极点.但事实上WINDOWS NT的产生九曲九弯、筋疲力尽、歇斯底里、极度焦虑、几乎失控,但最终还是完成. 卡特勒是NT的开发主管,是这个开发团队的领袖,是主宰一切的头. 他一直是争强好胜、斗勇好狠的角.

阅读的力量

- - 简单文本
阅读,以灵魂融合的方式阅读,或许会战栗,恐惧,喜悦,哭泣,甚至紧张,却可以让你成为阅读的人存在,你既是独立的,又陷入作品中成为你臆想和理解的另一个人. 乔治.斯坦纳(George Steiner)在《语言与沉默(Language And Silence)》的第一篇《人文素养》中如是评价阅读:. 一个人读了《伊利亚特》第十四卷(普里阿摩斯夜会阿基琉斯),读了阿廖沙.卡拉玛佐夫跪向星空那一幕,读了《蒙田随笔》的第二十章,读了哈姆雷特对这章的引用,如果他的人生没有改变,他对自己生命的领悟没有改变,他没有用一点点彻底不同的方式大量他行走其中的屋子,打量那些敲门的人,那么,他虽然是用肉眼在阅读,但他的心眼却是盲视.

有关英语阅读

- kezhuw - 云风的 BLOG
不知不觉,我最近两年居然读了许多英文读物. 书、手册、论文、blog 等等. 前段想翻一点资料原文,居然记错了,以为自己曾在中文版中读到的,后来才发现我以前读的是英文版. 昨天晚上在小店客厅的沙发里窝着,读 Dungeon Twister 2 Prison 的规则书. 然后把游戏 setup 好自娱.

关于阅读的生意

- AJ - 南都周刊-热点新闻
这一群85后的年轻人,正在做着一件充满想象的事情,图书馆商业化. 图书免租金,借阅快递还免费帮你送货上门,虽然听起来有些诧异,不过民营的深圳青番茄图书馆确实在做着这样的事情. 青番茄上线不足一年,但其已在北上广深等20个城市开通了分站点. 因为商业模式新颖,融到巨资的京东甚至与之传出了“绯闻”:京东CEO刘强东不久前通过新浪微博公布的四项图书战略中,“在图书领域将会有重大投资并购披露”的对象就是青番茄.

无觅阅读的革新

- - 望月的博客
作为一直关注 无觅网的老用户,在得知无觅网的转型以及最近推出的重大革新之后,心中备感欣奋. 无觅作为一个小的创业公司,从最开始做相关文章插件,到今年开始转型为 个性化阅读社区,到现在结束内测开放注册,以及推出安卓客户端,不停地在紧跟互联网节奏步伐进行革新,尤其是率先推出安卓客户端让人感到意外,因为众所周知,安卓的开发难度要比iOSF复杂得多.