Technology

H96 Streaming Sticks Caught Running Coordinated Ad Fraud Network Tied to Chinese Firm Fengwo Group

Martin HollowayPublished 15h ago5 min readBased on 4 sources
Reading level
H96 Streaming Sticks Caught Running Coordinated Ad Fraud Network Tied to Chinese Firm Fengwo Group

A Bitsight threat researcher has uncovered a large-scale ad fraud operation that weaponizes low-cost H96 TV streaming sticks as a captive click farm, coordinating fake ad traffic through AI-generated websites operated by a Chinese advertising company.

Pedro Falé, a threat researcher at security firm Bitsight, registered an expired domain name that the operation had used to coordinate fraudulent ad clicks across H96 streaming devices. By sinkholing that domain, Falé gained visibility into the operation's telemetry, which periodically collected full hardware information and the complete list of installed apps from tens of thousands of H96 sticks worldwide. Bitsight published Falé's findings in July 2026, with Brian Krebs reporting on the investigation in a KrebsOnSecurity article the same month. KrebsOnSecurity

The telemetry revealed a consistent profile across the infected H96 devices. Nearly all of the boxes transmitting data to the sinkholed domain claimed to be mobile phone models from manufacturers including Samsung, Vivo, Huawei, and Xiaomi. Every device reported having the same two apps installed, both produced by Zhejiang Fengwo IoT Technology Ltd., a company founded in 2019 in mainland China that operates an advertising portfolio under the name Fengwo Group. KrebsOnSecurity

Those two apps function as the coordination layer for the fraud network. The H96 devices serve as a captive traffic source, clicking on ads displayed at AI-generated websites operated by Fengwo Group. These websites contain machine-generated news articles and graphics spanning categories such as finance, health, education, gaming, music, and food blogs. The sites are engineered to display ads only when the visiting device matches the spoofed mobile profile of the H96 devices, meaning a human browsing the same URL from a desktop or real mobile phone would see no advertising at all. This device-fingerprint gating is a deliberate evasion technique designed to frustrate detection by ad-platform anti-fraud scanners that simulate or inspect human browsing behavior. KrebsOnSecurity

The connection between Fengwo Group and the phone-spoofing mechanism is corroborated by infrastructure evidence. Fengwo's domain fwgcloud[.]com shared SSL certificate data with other domains associated with the H96 spoofing infrastructure. The same domain hosts an internal wiki platform linking the company to a proprietary implementation of Google's Blockly visual programming language. Fengwo Group has also registered multiple patents matching the inner workings of the two apps found on H96 devices. KrebsOnSecurity

Bitsight's TRACE unit identified several Hong Kong, Singapore, and single-person shell identities used by Fengwo Group to collect monetization from the ad fraud operation. KrebsOnSecurity Bitsight

The fwgcloud[.]com domain also claims that Fengwo has created more than 120,000 "AI digital humans" available for rent, pointing to a broader business model that extends beyond ad fraud into synthetic content generation at industrial scale. KrebsOnSecurity

Bitsight's history with this threat ecosystem predates the current investigation. In March 2019, the firm published a report titled "Fraudulent Android Advertising SDK Installed In Over 15 Million Devices," finding that a fraudulent Android advertising SDK had been installed on over 15 million devices. As part of that investigation, Bitsight sinkholed a domain related to the SDK. Bitsight Wired reported in October 2023 that the operation uncovered by Bitsight also involved dozens of Android and iOS apps beyond the TV streaming devices, indicating that the fraud infrastructure spans multiple device categories and platforms. Wired

The operation's architecture is worth pausing on. The H96 devices are inexpensive Android-based TV boxes sold primarily through online marketplaces. Users who purchase them are likely unaware that the firmware ships with apps designed to silently participate in ad fraud. The devices spoof mobile phone identities to make their automated traffic appear as legitimate mobile ad impressions, then route that traffic to AI-generated content sites that serve ads only to matching spoofed profiles. The result is a closed loop: the same operator controls the traffic source, the content destination, and the monetization shell companies. Each layer reinforces the others, and each is designed to be invisible to a different class of auditor.

The use of AI-generated content sites as ad inventory is a notable evolution. Earlier ad fraud operations typically hijacked legitimate publisher inventory or created low-effort fake sites. Fengwo's network generates entire content sites with machine-written articles and graphics across multiple verticals, creating the appearance of legitimate publisher traffic to any ad network that inspects the destination URL or page content. The fingerprint-gating mechanism ensures that ad-platform crawlers and human investigators encounter what looks like a normal content site, while only the compromised H96 devices trigger actual ad serving.

The shell company structure Bitsight traced through Hong Kong and Singapore registrations follows a familiar pattern for operations seeking to monetize fraudulent ad revenue across jurisdictions while obscuring ultimate beneficial ownership. The single-person shell identities in particular suggest a layered approach to collecting payments that is designed to complicate financial tracing.