Security researchers have identified a coordinated campaign in which inexpensive Android TV boxes leave the factory already loaded with software that spoofs mobile-device identities and converts home broadband connections into covert SOCKS5 proxy nodes. The discovery underscores how supply-chain compromise at the hardware level can turn everyday consumer gadgets into dual-purpose tools for advertising fraud and traffic laundering.

According to analysis from Bitsight, certain low-cost Android TV boxes ship with pre-installed applications that rewrite the devices' hardware fingerprints. The boxes then present themselves as popular smartphones from brands such as Samsung, Huawei, Xiaomi or Vivo. Once online, the software automatically generates fraudulent ad clicks on websites controlled by the same operators, monetising the deception through automated advertising abuse.

Researchers have labelled the campaign "Fuyao" and linked it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland Chinese firm established in 2019. The same applications perform a second, equally lucrative function: they enrol the compromised boxes into residential proxy networks using SOCKS5 exit nodes. Because the devices sit behind ordinary household IP addresses, the resulting proxy traffic appears legitimate to many security filters, making it attractive for a range of illicit activities that benefit from anonymity.

This two-stage model maximises the value extracted from each unit. First the device identity is spoofed to drive ad revenue; later the same hardware is pressed into service as a residential exit node. The approach exploits both consumer appetite for bargain electronics and the premium that residential IP addresses command on underground markets.

The implications extend well beyond individual households. Device owners may unknowingly host malicious traffic, exposing themselves to bandwidth theft, degraded network performance and potential legal scrutiny if their connections are used in further crimes. Advertisers lose budget to fabricated clicks, while the wider internet absorbs an expanded pool of hard-to-block proxy capacity. Because the malware is embedded before sale, conventional endpoint defences and user-initiated clean-up efforts are often ineffective.

For IT professionals and organisations that manage large numbers of connected devices, the episode highlights the limits of software-only security models. Supply-chain verification, network-behaviour monitoring and careful procurement policies become essential layers of defence. Budget IoT and media-streaming hardware, in particular, warrants heightened scrutiny when it originates from opaque manufacturing channels.

Platform marketplaces, internet service providers and enterprise buyers all have roles to play. Sellers can tighten listing requirements and demand greater transparency from manufacturers; operators can flag unusual traffic patterns originating from consumer premises equipment; and end users can be encouraged to prefer devices with verifiable update channels and minimal pre-loaded software. Multi-layered controls—combining procurement diligence, continuous network visibility and public awareness—offer the most practical path to reducing exposure.

The Fuyao operation demonstrates that the economics of cheap hardware and residential anonymity remain powerful incentives for attackers. As long as those incentives persist, pre-installed malware that turns living-room gadgets into fraud engines and proxy farms will continue to surface. Independent verification of device integrity, rather than reliance on brand reputation or price alone, is becoming a necessary habit for anyone responsible for securing modern digital environments.


網絡安全研究人員識別到一項協調行動,當中廉價Android電視盒出廠時已預載軟件,可偽造流動裝置身份,並將家庭寬頻連接轉換為隱蔽的SOCKS5代理節點。此發現突顯硬件層面的供應鏈入侵,如何能將日常消費電子產品轉化為兼具廣告詐騙與流量洗白功能的雙重工具。

根據Bitsight的分析,部分低成本Android電視盒預裝應用程式,可修改裝置硬件指紋。這些電視盒隨後會將自身偽裝為三星、華為、小米或Vivo等品牌的流行智能手機。一旦連線,軟件會自動於同一營運商控制的網站生成詐騙性廣告點擊,透過自動化廣告濫用將欺騙行為貨幣化。

研究人員將該行動命名為「富堯」,並追溯至2019年成立的中國大陸企業浙江豐沃物聯網科技有限公司。這些應用程式同時執行第二個同樣牟利的功能:將已被入侵的電視盒透過SOCKS5出口節點納入住宅代理網絡。由於裝置位於普通家庭IP地址背後,產生的代理流量對多數安全過濾器而言顯得合法,使其成為一系列受益於匿名性的非法活動的吸引力目標。

這兩階段模式最大化榨取每部裝置價值。首先偽造裝置身份以驅動廣告收益;隨後將相同硬件投入用作住宅出口節點。此策略同時利用消費者對廉價電子產品的渴求,以及住宅IP地址在地下市場享有的溢價。

其影響遠超個別家庭。裝置用戶可能在不知情下承載惡意流量,面臨頻寬被竊、網絡效能下降及潛在法律審查風險——若其連接被用於進一步犯罪活動。廣告商因虛假點擊損失預算,而整個互聯網則吸收了更龐大且難以封鎖的代理容量。由於惡意軟件在銷售前已植入,常規終端防禦措施及用戶主導的清理工作往往無效。

對管理大量聯網裝置的IT專業人員及機構而言,此事件突顯純軟件安全模式的局限性。供應鏈驗證、網絡行為監控及謹慎的採購政策成為必要防禦層級。特別是來自不透明製造渠道的平價物聯網及媒體串流硬件,更需提高審查標準。

平台市場、互聯網服務供應商及企業買家均扮演角色。賣家可收緊上架要求,要求製造商提高透明度;營運商可標記源自用戶端設備的異常流量模式;並鼓勵終端用戶優先選擇具可驗證更新通道及最小預載軟件的裝置。多層次管控——結合採購謹慎度、持續網絡可視性及公眾意識——提供了降低暴露風險最實用的路徑。

富堯行動證明,廉價硬件經濟學及住宅匿名性對攻擊者仍是強大誘因。只要這些誘因存在,將客廳裝置轉化為詐騙引擎與代理農場的預載惡意軟件將持續出現。獨立驗證裝置完整性,而非僅依賴品牌信譽或價格,正成為任何負責保護現代數字環境安全者的必要習慣。

新聞來源 / Original News Source