Actor Profile
Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight as the operator behind the Fuyao campaign. The attribution is based on shared TLS certificate data, exposed wiki files, reused email addresses, revenue links, and patents. Chinese patent records (CN117421142B and CN117478142A) identify Fengwo as the assignee of digital-human execution and monitoring technologies, though these patents do not explicitly describe advertising operations. The company markets over 120,000 "AI digital humans," though the exact meaning of this term remains unclear. The actor's motivation appears to be financial gain through large-scale ad fraud and residential proxy monetization, leveraging compromised consumer IoT devices to generate revenue estimated by Bitsight at potentially $40 million annually.
TTPs (Tactics, Techniques, Procedures)
The Fuyao operation employs sophisticated supply chain compromise, delivering pre-installed malicious applications on cheap Android TV boxes (primarily H96_MAX_V11 models). The malware rewrites device hardware identities to spoof Samsung, Huawei, Xiaomi, or Vivo phones, deleting chipset properties that would expose underlying Rockchip, Amlogic, or Allwinner boards. For ad fraud execution, operators use a custom Blockly-based editor to assemble campaign logic exported as JavaScript and delivered via S3. The Script app integrates YOLOv8s object detection (model "lourui_2" trained on 12 screen elements including Taboola widgets), Android accessibility services, and Google ML Kit OCR to locate and click advertisements. The operation implements conditional behavior: when HDMI signals are detected, devices function as SOCKS5 exit nodes, repurposing victims' broadband connections as residential proxies; when HDMI is off, devices revert to ad-fraud tasks. C2 infrastructure pushes complete phone profiles by merging base configurations with per-model diffs. Revenue flows through a publishing network spanning 144 operator-owned domains across seven beneficiary clusters, with at least 84 domains loading Taboola tags and connecting to revenue-collecting entities in Hong Kong and Singapore.
Targets & Patterns
The campaign targets consumers purchasing low-cost Android TV boxes, particularly in markets where cheap streaming devices are sold with promises of free content. Bitsight's sinkhole captured 65,957 reports from approximately 38,000 unique MAC addresses in a single day, though actual device counts remain uncertain due to identifier rotation. The operation exploits consumer electronics supply chains, with malicious apps appearing pre-installed on devices, though the exact supply chain insertion point remains unestablished. The dual monetization model targets both advertising ecosystems (through fraudulent impressions and clicks) and residential proxy markets (by converting home broadband connections into exit nodes). The telecommunications sector is impacted as victims' internet connections are repurposed without consent. The campaign demonstrates particular focus on devices that lack Play Protect certification, exploiting gaps in Android security verification for non-standard hardware. Geographic distribution appears global based on the nature of consumer electronics distribution, though specific victim demographics were not detailed in available reporting.
Historical Context
The Fuyao campaign represents an evolution in IoT-based fraud operations, combining ad fraud with residential proxy abuse in a single platform. Bitsight discovered the operation by registering an expired domain previously used as a factory backdoor and telemetry collector, suggesting the infrastructure had been operational for an extended period before detection. Chinese patent filings show Zhejiang Fengwo obtained CN117421142B (granted November 2024) covering execution-flow tracking for digital-human behavior modules, and CN117423478A describing remote screen monitoring through cloud-hosted thumbnails, indicating the technical foundation was developed over multiple years. The FBI issued guidance in June 2025 advising owners to assess connected devices and treat generic streaming boxes sold on free-content promises as suspect, suggesting awareness of similar supply chain threats predating the Fuyao disclosure. The campaign's use of sophisticated machine vision (YOLOv8s) and multi-layered fraud automation represents a maturation of ad-fraud techniques beyond simple click farms, while the conditional SOCKS5 proxy functionality echoes residential proxy botnet operations seen in other IoT malware families.
Defensive Recommendations
- Verify Play Protect certification on all Android devices before deployment; reject devices lacking Google certification to prevent supply chain-compromised hardware from entering networks
- Monitor network traffic for unexpected SOCKS5 proxy behavior and outbound connections to residential proxy networks, particularly from IoT devices during periods when HDMI signals are active
- Implement network segmentation to isolate Android TV boxes and consumer IoT devices from trusted networks; use firewall rules to restrict outbound connections to known-good streaming services only
- Detect anomalous device identity spoofing by correlating device fingerprints with expected hardware profiles; flag devices reporting phone identities (Samsung, Huawei, Xiaomi, Vivo) while exhibiting TV box network patterns
- Block connections to Taboola and similar ad networks from devices that should not be generating web traffic; monitor for JavaScript execution patterns consistent with automated ad interaction and accessibility service abuse
---
# Geopolitical Context
Geopolitical Context
The Fuyao campaign illustrates the persistent challenge of supply-chain integrity in consumer electronics originating from jurisdictions with limited regulatory transparency. Bitsight researchers attributed the operation to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company, based on technical artifacts including shared TLS certificates, exposed documentation, and patent filings. The campaign involved Android TV boxes shipped with pre-installed malicious applications that spoofed device identities to conduct ad fraud and repurposed users' broadband connections as SOCKS5 proxy exit nodes. While Chinese patent records confirm Fengwo as the assignee of related digital-human execution and monitoring technologies, the available evidence does not establish whether the company directly operated the fraud infrastructure or at what stage in the supply chain the malicious applications were introduced. The incident underscores broader concerns about the opacity of low-cost electronics supply chains, particularly for devices manufactured in regions where corporate governance and export controls may not align with Western standards. It also highlights the dual-use nature of emerging technologies—automation frameworks and machine-vision models—that can be repurposed for financially motivated cybercrime at scale.
State Actor Alignment
No direct state-actor involvement is indicated in the available reporting. The operation appears to be financially motivated cybercrime attributed to a private Chinese technology company. Zhejiang Fengwo IoT Technology Co., Ltd. is identified in public Chinese patent records as the assignee of patents covering execution-flow tracking for digital-human behavior modules and remote screen monitoring technologies. However, the sources do not establish that the company operated the Fuyao infrastructure or engaged in ad fraud, nor do they clarify whether the malicious applications were installed by the manufacturer, a distributor, or another actor in the supply chain. The incident does not appear to be linked to state-sponsored cyber operations, sanctions regimes, or strategic intelligence collection. It does, however, raise policy questions about the adequacy of supply-chain security standards and the enforcement of consumer-protection regulations for electronics exported from China to global markets.
Business Impacty pro region
The Fuyao campaign has global implications given the widespread distribution of low-cost Android TV boxes through e-commerce platforms serving North America, Europe, and other regions. Bitsight's sinkhole telemetry captured approximately 38,000 unique MAC addresses in a single day, though the true scale of affected devices remains uncertain due to identifier spoofing. The operation's use of victims' broadband connections as proxy exit nodes poses risks beyond ad fraud, potentially enabling anonymization of malicious traffic, circumvention of geographic restrictions, or facilitation of other cybercrimes. For European regulators, the incident underscores gaps in pre-market conformity assessment and the challenges of enforcing the Radio Equipment Directive and forthcoming Cyber Resilience Act against opaque supply chains. U.S. agencies, including the FBI, have issued generic guidance advising consumers to verify Play Protect certification and disconnect suspicious devices, but no targeted enforcement action or import restrictions have been publicly announced. The case may inform ongoing debates in Brussels, Washington, and other capitals about mandatory security labeling, supply-chain due diligence, and the risks posed by unvetted consumer IoT devices from jurisdictions with weak regulatory oversight.
Forecast
If attribution to Zhejiang Fengwo is substantiated through further investigation, it is likely that the company will face reputational damage and potential regulatory scrutiny in export markets, though enforcement mechanisms remain limited absent bilateral cooperation. If Western governments prioritize supply-chain security for consumer electronics, the Fuyao case may accelerate policy initiatives such as mandatory security certification, import controls on non-compliant devices, or public advisories targeting specific brands and models. If the command-and-control infrastructure remains active, affected devices will likely continue to generate ad-fraud revenue and proxy traffic until owners manually disconnect them or manufacturers issue over-the-air updates—an outcome that appears unlikely given the opacity of the supply chain. If Bitsight or other researchers publish complete indicators of compromise and affected firmware builds, incident-response teams and internet service providers may be able to identify and notify affected users at scale. If no coordinated takedown or consumer-protection intervention occurs, the Fuyao operation is likely to persist as a case study in the economic viability of supply-chain-embedded cybercrime targeting low-cost IoT devices.
