Fengwo Group ad-fraud and residential-proxy ecosystem
Threat Actor Meta
Summary
Hide ▲
Show ▼
Fengwo Group's Fuyao Happening spans a monetized ad-fraud and residential-proxy ecosystem on cheap Android TV boxes. Bitsight said the devices rewrite hardware identities to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then switch to SOCKS5 relaying when HDMI is active. The same operation uses Blockly-built task logic, a YOLOv8s model named lourui_2, Android accessibility data, and Google ML Kit OCR to automate ad interaction and camouflage the boxes. Bitsight also mapped 144 operator-owned domains, found at least 84 loading a Taboola tag, and said its sinkhole saw 65,957 reports from about 38,000 unique MAC addresses in one day, while revenue estimates remained source-specific and not interchangeable.
Related Happenings
Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor Meta
H score87
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...
Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android botnet that forces consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android botnet that forces consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score69
First: 12.06.2026 21:59
Last: 12.06.2026 21:59
Sources 1
About this happening:
The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Timeline
-
31.07.2026 17:45 1 articles · 13d ago
Bitsight details Fuyao's machine-vision ad-fraud automation on Android TV boxes
Technical Analysis UpdateBitsight described Fuyao as an ad-fraud and proxy operation on cheap Android TV boxes that rewrites hardware identities to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then switches to SOCKS5 relaying when HDMI is active. The Script app uses a YOLOv8s model named lourui_2, Android accessibility data, and Google ML Kit optical character recognition, while campaign logic is assembled in Blockly and exported as JavaScript for execution on the box. Bitsight also mapped 144 operator-owned domains across seven beneficiary clusters, found at least 84 domains loading a Taboola tag on the homepage, and said its sinkhole view captured 65,957 reports from about 38,000 unique MAC addresses in one day.
Show sources
- Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies — thehackernews.com — 31.07.2026 17:45
-
30.07.2026 19:49 2 articles · 13d ago
Bitsight traces Fengwo Group ad-fraud network on H96 streaming sticks
Initial DisclosureBitsight TRACE researcher Pedro Falé traced a Fengwo Group ad-fraud and residential-proxy ecosystem centered on H96 streaming sticks, where devices phoned home to an expired coordination domain, spoofed themselves as Samsung, Vivo, Huawei, and Xiaomi phones, and clicked ads on AI-generated websites; the telemetry covered approximately 38,000 TV boxes globally and the network was estimated to generate close to $50,000 a day.
Show sources
- Read This Before You Buy That TV Streaming Stick — krebsonsecurity.com — 30.07.2026 19:49
- Read This Before You Buy That TV Streaming Stick — krebsonsecurity.com — 30.07.2026 19:49