Operation Fuyao: Cheap Android TV Boxes Hid an Army of Ad Fraud and SOCKS5 Proxies
Bitsight uncovers Operation Fuyao, a malware campaign turning cheap Android TV boxes into ad fraud nodes and SOCKS5 proxies, linked to Zhejiang Fengwo.
Illustrative image generated with AI
Bitsight has uncovered a large-scale operation dubbed Fuyao, which turns uncertified Android set-top boxes into nodes for automated ad fraud and traffic relay. The devices, sold cheaply without Play Protect certification, reach users already infected. In a single day of observation, researchers collected nearly 66,000 reports from about 38,000 unique MAC addresses.
How the Malware Works: YOLOv8s and Spoofed Hardware Profiles
Pre-installed apps, including a key executable and a component called Script, falsify device identity. The real chipset—Rockchip, Amlogic, or Allwinner—is hidden and replaced with attributes typical of Samsung, Huawei, Xiaomi, or Vivo smartphones. The command-and-control infrastructure sends full phone profiles, blending a base configuration with model-specific variants, but erasing all traces of the underlying hardware.
To perform ad fraud, Script uses an object detection model, YOLOv8s, named lourui_2. The model recognizes twelve screen elements and is combined with Android accessibility data and optical character recognition via Google ML Kit. Fraudulent campaigns are assembled in a Blockly-based editor, exported as JavaScript code, and pushed to infected devices.
The malware has a dual nature. When it detects an active HDMI signal, it activates a SOCKS5 exit node that relays others' traffic through the owner's broadband connection. During idle periods, it clicks ads on sites controlled by the campaign operators.
Bitsight took over an expired domain used as a backdoor and telemetry collector. Filtering for devices with the Fuyao apps, it received 65,957 reports from roughly 38,000 distinct MAC addresses in 24 hours. Virtually all devices were posing as phones. The most common model was H96_MAX_V11, a cheap Android TV box.
The Monetization Chain: 84 Domains and a Taboola Tag
Monetization flows through 144 domains traceable to the operators. Of these, 84 load a Taboola tag on the homepage. By cross-referencing Taboola's public sellers.json file, Bitsight linked the domains to revenue-collecting entities based in Hong Kong and Singapore.
Revenue estimates, not directly observed, hover around $1.25 per device per day. With 38,000 active devices, that would approach $47,500 daily. Assuming the advertised fleet of over 120,000 “AI digital human” units, a 70% fill rate, and 30–40% fraud reporting, the annual potential could reach $40 million.
Attribution to Zhejiang Fengwo: Certificates and Patents
Bitsight attributes the operation to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland Chinese company founded in 2019. The attribution rests on shared TLS certificates, exposed wikis, reused email addresses, and links to the revenue chain. Two public Chinese patents—CN117421142B (granted November 2024) and CN117478834A—describe technologies for executing and monitoring “digital-human behaviors”: execution flow tracking and remote screen control via cloud thumbnails.
Neither document mentions ad fraud. The patents do not prove the company ran Fuyao or committed fraud, but they add to the circumstantial picture.
Risks and Mitigations: What to Do with Uncertified Boxes
The harm to owners is real. Bandwidth is degraded, the IP address risks being flagged for malicious traffic, and the device participates in ad fraud without the user’s knowledge. For advertisers, there are direct losses from non-existent clicks and impressions. The SOCKS5 proxy presence turns these devices into a resource for illicit anonymous activities.
Google recommends verifying that the device is Play Protect certified (the official list is on the Android TV website). In a June 2025 alert, the FBI advised assessing connected devices, disconnecting suspicious ones, and treating generic boxes promising free content as high risk.
As of July 31, 2026, Bitsight had not published full lists of packages, firmware, or network indicators. Pinpoint identification of Fuyao remains partial. The most immediate defense is to avoid purchasing unbranded, uncertified set-top boxes.
Sources
This article is an original reworking based on the sources below.




