Particle.news
Download on the App Store

Fuyao Ad-Fraud Ring Uses Cheap Android TV Boxes to Pose as Phones and Click Ads

Researchers say the operation automates human-like ad clicks, repurposes owners’ home bandwidth as residential proxies, and funnels payouts through shell companies to scale revenue.

Overview

  • Researchers discovered the operation after registering an expired domain used by factory backdoors on low-cost Android TV boxes, which revealed devices reporting as phones and contacting a multi-tier command-and-control system.
  • The malware runs two modes: with an HDMI display attached the box acts as a SOCKS5 residential proxy that forwards third-party traffic, and without a display it runs ad-fraud tasks on attacker-controlled sites.
  • Fuyao spoofs device identities to appear as premium mobile visitors and uses Android accessibility APIs combined with a YOLO object-detection model and OCR to locate and click ads in a human-like way.
  • Operators assemble campaign logic in a Blockly-based visual editor, export modules to cloud storage, and push reusable fraud routines to the fleet, allowing low-skilled staff to run and scale campaigns quickly.
  • Bitsight’s live sinkhole telemetry captured tens of thousands of unique MAC identifiers over a day, linked ad-payout accounts to shell companies in Hong Kong and Singapore, and estimated the advertised network could produce multimillion-dollar annual revenue.