Fengwo Group ad-fraud and residential-proxy ecosystem
Threat Actor Meta
Summary
Hide ▲
Show ▼
Fengwo Group now stands exposed as the operator of a monetized ad-fraud and residential-proxy ecosystem tied to H96 streaming sticks, turning consumer devices into a large-scale abuse platform. Researchers traced the operation to Zhejiang Fengwo IoT Technology Co., Ltd after finding shell identities, telemetry collection, and spoofed mobile-device profiles. The infrastructure uses AI-generated websites and phone impersonation to trigger ad clicks only when the visiting device matches the H96 profile. The scale and automation show a fraud-enablement business designed to lower the skill required for high-volume abuse.
Related Happenings
Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor Meta
H score87
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...
Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score69
First: 12.06.2026 21:59
Last: 12.06.2026 21:59
Sources 1
About this happening:
The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
Trend
H score30
First: 02.04.2026 18:21
Last: 02.04.2026 18:21
Sources 1
About this happening:
Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
TrendAbout this happening: Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...
Timeline
-
30.07.2026 19:49 2 articles · 0h ago
Bitsight traces Fengwo Group ad-fraud network on H96 streaming sticks
Initial DisclosureBitsight TRACE researcher Pedro Falé traced a Fengwo Group ad-fraud and residential-proxy ecosystem centered on H96 streaming sticks, where devices phoned home to an expired coordination domain, spoofed themselves as Samsung, Vivo, Huawei, and Xiaomi phones, and clicked ads on AI-generated websites; the telemetry covered approximately 38,000 TV boxes globally and the network was estimated to generate close to $50,000 a day.
Show sources
- Read This Before You Buy That TV Streaming Stick — krebsonsecurity.com — 30.07.2026 19:49
- Read This Before You Buy That TV Streaming Stick — krebsonsecurity.com — 30.07.2026 19:49