Fuyao apps make cheap Android TV boxes mimic phones and relay traffic

Bitsight says cheap Android TV boxes carrying Fuyao apps can pose as Samsung, Huawei, Xiaomi or Vivo phones, click ads and relay others' traffic through the owner's broadband. It attributed the operation to Zhejiang Fengwo IoT Technology Co., Ltd.
Using an expired backdoor domain, Bitsight logged 65,957 reports from about 38,000 unique MAC addresses in one day. Most identifiable boxes reported H96_MAX_V11, while most reports described phones. Rotating identifiers make this neither a device nor fleet count.
Two workloads on one device
When HDMI is detected, a box usually relays others' traffic as a SOCKS5 exit node; otherwise it waits for ad-fraud work. Its command-and-control server supplies phone profiles and strips properties that could expose Rockchip, Amlogic or Allwinner hardware.
The Script app combines a YOLOv8s model named lourui_2, trained on 12 screen elements, with Android accessibility data and Google ML Kit OCR to locate ads. Campaigns are built in Blockly, exported as JavaScript, stored on S3 and sent to boxes.
Evidence, scale and limits
Bitsight captured about 40 fraud tasks, 21 unique campaigns and 166 unique modules across four test devices. It mapped 144 operator-owned domains in seven clusters; at least 84 loaded a Taboola tag. It used sellers.json to link domains to revenue entities in Hong Kong and Singapore.
Bitsight modeled returns of $1.25 per active device a day, or $47,500 daily for 38,000 active devices. It estimated up to $40 million annually at the advertised fleet size, without showing the full calculation. These are estimates, not observed revenue, and the advertised figure does not establish a box count.
Bitsight tied Fuyao to Fengwo using TLS certificates, exposed files, reused emails and patents. Chinese records name Zhejiang Fengwo as assignee on related patents, without proving it ran Fuyao. The evidence does not identify who installed the apps or where they entered the supply chain.
Practical network response
No complete list of affected packages, firmware builds or network indicators was available. Businesses should check Play Protect certification, inventory streaming boxes, keep firmware current and disconnect suspicious devices.

