Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Cheap Android TV boxes are being used in a massive proxy and ad-fraud botnet, masking devices as mobile phones to evade detection.

This article is original editorial commentary written with AI assistance, based on publicly available reporting by The Hacker News. It is reviewed for accuracy and clarity before publication. See the original source linked below.
A disturbing new frontier in hardware-based cybersecurity threats has emerged with the discovery of "Fuyao," a sophisticated operation that transforms budget Android TV boxes into a massive botnet. Security researchers at Bitsight have identified thousands of low-cost streaming devices that ship with pre-installed malware designed to rewrite the device’s hardware identity. By masquerading as legitimate smartphones from trusted brands like Samsung, Huawei, and Xiaomi, these hijacked devices are being harnessed to commit large-scale ad fraud and provide residential proxy services to anonymous third parties, all while the owners remain oblivious.
The context of this breach lies in the "gray market" of electronics, where unbranded or "off-brand" Android devices are sold globally via major e-commerce platforms. Unlike certified hardware from Google or Amazon, these boxes often lack rigorous security audits and are manufactured by opaque entities. Researchers have traced the Fuyao operation to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese firm established in 2019. This discovery highlights a growing trend where the hardware supply chain itself is weaponized, moving beyond traditional software vulnerabilities into the realm of pre-infected consumer electronics.
Technically, the mechanics of Fuyao are both elegant and insidious. Upon activation, the malware alters the device's build properties, causing it to report itself to networks as a mobile phone rather than a media streamer. This identity theft is critical for two reasons. First, it allows the operators to simulate "human-like" mobile ad clicks on specific websites, generating fraudulent revenue that is harder for ad networks to detect. Second, the devices are enlisted into a residential proxy network. By routing external traffic through a user’s home broadband, malicious actors can bypass geo-blocking or launch cyberattacks while appearing as a standard household internet user.
The implications for the digital advertising and cybersecurity industries are profound. Ad fraud already costs businesses billions of dollars annually; the ability of Fuyao to mimic diverse hardware profiles makes it significantly harder for verification tools to flag fraudulent traffic. Furthermore, the commodification of residential proxies provides a "laundering" service for hackers, who can use these hijacked TV boxes to mask their origins during credential stuffing attacks or data scraping. For consumers, the risk is not just a slowed internet connection, but the potential for their IP addresses to be blacklisted or flagged for illegal activity committed by others.
From a regulatory perspective, this incident underscores the urgent need for stricter oversight of global hardware supply chains. Current frameworks often focus on software updates and data privacy, but they rarely address the "out-of-the-box" integrity of low-cost electronics. As the Internet of Things (IoT) expands, the surface area for these pre-installed threats grows. Manufacturers in jurisdictions with lax oversight can easily embed "backdoors as a feature," prioritizing short-term profit through data monetization and botnet rentals over consumer safety and international cybersecurity standards.
Looking ahead, the primary concern is the persistence and evolution of the Fuyao botnet. As security firms begin to blacklist the Command and Control (C2) servers associated with Zhejiang Fengwo, the operators will likely shift to more resilient, decentralized infrastructures. Consumers should remain wary of significantly underpriced streaming hardware, as the "discount" is often subsidized by the monetization of their home network. The industry must now watch whether major retailers will take responsibility for vetting the third-party hardware sold on their platforms, or if the burden of defense will continue to fall solely on the end-user.
Why it matters
- 01The Fuyao operation represents a sophisticated hardware-level threat where budget Android TV boxes are pre-infected to masquerade as mobile phones for ad fraud.
- 02By turning consumer broadband into residential proxies, the malware allows malicious actors to hide their activities behind the IP addresses of unsuspecting households.
- 03This breach highlights a critical vulnerability in the global electronics supply chain, where unverified manufacturers can weaponize low-cost IoT devices at the point of origin.