Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fengwo Group ad-fraud and residential-proxy ecosystem

Threat Actor Meta
First reported
Last updated
Happening score
H score 69
1 unique sources, 1 articles

Summary

Hide ▲

Fengwo Group now stands exposed as the operator of a monetized ad-fraud and residential-proxy ecosystem tied to H96 streaming sticks, turning consumer devices into a large-scale abuse platform. Researchers traced the operation to Zhejiang Fengwo IoT Technology Co., Ltd after finding shell identities, telemetry collection, and spoofed mobile-device profiles. The infrastructure uses AI-generated websites and phone impersonation to trigger ad clicks only when the visiting device matches the H96 profile. The scale and automation show a fraud-enablement business designed to lower the skill required for high-volume abuse.

Related Happenings

Lurking Lizard ecosystem shift changes threat-actor operations

Threat Actor Meta
H score87 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score69 First: 12.06.2026 21:59 Last: 12.06.2026 21:59 Sources 1

About this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...

Residential proxy traffic evades IP reputation feeds across malicious edge sessions

Trend
H score30 First: 02.04.2026 18:21 Last: 02.04.2026 18:21 Sources 1

About this happening: Residential proxies are increasingly treated as a carding identity-simulation stack, not a standalone anonymity tool, with actors combining them with device fingerprints...

Timeline

  1. 30.07.2026 19:49 2 articles · 0h ago

    Bitsight traces Fengwo Group ad-fraud network on H96 streaming sticks

    Initial Disclosure

    Bitsight TRACE researcher Pedro Falé traced a Fengwo Group ad-fraud and residential-proxy ecosystem centered on H96 streaming sticks, where devices phoned home to an expired coordination domain, spoofed themselves as Samsung, Vivo, Huawei, and Xiaomi phones, and clicked ads on AI-generated websites; the telemetry covered approximately 38,000 TV boxes globally and the network was estimated to generate close to $50,000 a day.

    Show sources