Post #4250042
2026-07-30 17:35 UTC
A couple of teasers from the story:
Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.
Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.
According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.
Replies (2)
-
@dalias@hachyderm.io 2026-07-30 18:09
@briankrebs@infosec.exchange Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?
-
@ChuckMcManis@chaos.social 2026-07-30 18:26
@briankrebs@infosec.exchange Reminding us once again that ad fraud is the best fraud because the people who could stop it don't because it makes them money too!