Cheap streaming boxes can seem like a smart buy, but some off-brand Android devices may be doing a lot more than playing shows. Security researchers have found signs that certain boxes can spoof smartphones, click on ads, and even use a home internet connection for outside traffic without the owner noticing. That turns a simple living room gadget into a quiet little problem machine.
The deeper concern is how normal everything can look on the surface. The TV still works, the menu still loads, and the box still streams, while hidden software may be running in the background. In some cases, that hidden layer is tied to ad fraud and proxy activity that can benefit operators while putting households at risk.
Bitsight’s researchers traced one of these operations after finding an expired domain linked to factory backdoor activity on certain devices. Once they started watching the data sent to that domain, they saw hardware details and installed app lists coming in from connected boxes. Even stranger, many of those devices identified themselves as popular phone brands like Samsung, Vivo, Huawei, and Xiaomi, even though the software behavior pointed to TV hardware.
That mismatch was a major clue. The team eventually labeled the activity the Fuyao Enterprise, and the picture that emerged was ugly: some low-cost devices appeared to come with suspicious apps already present, especially older H96 boxes. That does not mean every unit of that brand is infected, but it does show how a bargain device can carry baggage from the start.
Google drew an important line in the sand as well, saying the affected devices were Android Open Source Project devices, not official Android TV OS devices or Play Protect certified devices. That difference matters because uncertified boxes do not go through the same security and compatibility testing. A shiny interface and a familiar app store logo are not the same thing as a certified, trusted platform.
The fraud itself is clever in a grim sort of way. According to the research, the software could present a TV box as if it were a smartphone, then quietly visit ad-heavy websites and click around like a real person. Bitsight also said the operators used tools to help the bots find ads when page layouts changed, which makes the whole scheme more resilient than simple click fraud.
One of the most unsettling twists was the split behavior based on whether the television was on. When an HDMI signal showed that someone was watching, the box often acted as a residential proxy. When the TV was off, it could shift into ad fraud mode, which suggests the box was trying to keep one activity from stepping on the other.
A residential proxy is basically a detour for internet traffic through a normal home connection. To the outside world, it looks like the traffic came from the household’s public IP address, not from whoever is actually sending it. That can make abuse harder to trace and can leave the owner with no obvious clue that the connection is being used for someone else’s business.
The scale matters too. Bitsight said it saw nearly 66,000 reports tied to about 38,000 unique MAC addresses in just one day, though spoofing may have inflated the count. Based on that slice of activity, the researchers estimated the operation could have produced tens of thousands of dollars daily in ad fraud revenue alone.
The warning signs for consumers are pretty straightforward. Cheap boxes from unfamiliar sellers, devices marketed as unlocked or fully loaded, and setups that push unofficial app stores should all trigger caution. If a box asks for Google Play Protect to be turned off, or shows as not certified, that is a loud signal to slow down and look closer.
Checking the exact model number is a smart start, especially when the device is an older H96 Max V11 or another rock-bottom model from a third-party reseller. A factory reset may clear some problems, but it will not necessarily remove malicious firmware baked into the device itself. In those cases, unplugging it, replacing it, and keeping it off the main network can be the safer move.
Network separation helps too. Putting streaming gear and other smart devices on a guest or IoT network can keep a compromised box from poking around your laptop, phone, or other sensitive devices. It also makes strange traffic easier to spot, which matters when a device is supposed to be sitting quietly in the corner and not chatting with the internet all night long.
For households that already have a low-cost streaming box in use, it is worth checking the settings and the router logs before trouble starts. If the device is uncertified, from an unknown brand, or behaving oddly when nobody is streaming, that is not something to shrug off. A cheap box can be a bargain, but not when it is secretly working two jobs on your dime.
