Overview
- Researchers discovered the operation after registering an expired domain used by factory backdoors on low-cost Android TV boxes, which revealed devices reporting as phones and contacting a multi-tier command-and-control system.
- The malware runs two modes: with an HDMI display attached the box acts as a SOCKS5 residential proxy that forwards third-party traffic, and without a display it runs ad-fraud tasks on attacker-controlled sites.
- Fuyao spoofs device identities to appear as premium mobile visitors and uses Android accessibility APIs combined with a YOLO object-detection model and OCR to locate and click ads in a human-like way.
- Operators assemble campaign logic in a Blockly-based visual editor, export modules to cloud storage, and push reusable fraud routines to the fleet, allowing low-skilled staff to run and scale campaigns quickly.
- Bitsight’s live sinkhole telemetry captured tens of thousands of unique MAC identifiers over a day, linked ad-payout accounts to shell companies in Hong Kong and Singapore, and estimated the advertised network could produce multimillion-dollar annual revenue.