Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
- ID
- 9685
- Status
- summarized
- Published
- 31 Jul 2026, 10:45 PM
- Fetched
- 31 Jul 2026, 11:59 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 01 Aug 2026, 12:03 AM
- Tags
- Audience
- developersai_ml_learnerssaas_founders
What happened
Bitsight researchers uncovered that cheap Android TV boxes—most identifiable as the H96_MAX_V11 model—ship with apps that spoof their hardware identity as Samsung, Huawei, Xiaomi, or Vivo phones, then run ad-fraud clicks and act as SOCKS5 proxy exit nodes when HDMI is active. The operation, dubbed Fuyao, is attributed to Zhejiang Fengwo IoT Technology Co., Ltd. and uses a YOLOv8s object-detection model trained on 12 screen elements plus Google ML Kit OCR and Android accessibility data to locate and click ads, with campaign logic assembled in a Blockly-based drag-and-drop editor.
Why it matters
If you or anyone in your household or office runs a cheap uncertified Android TV box, check for Play Protect certification and isolate it from your main network—it may be silently routing other people's traffic through your broadband and burning your data cap. For builders, this is a concrete case study of commodity ML models (YOLOv8s) being weaponized in embedded IoT malware, and it underscores that SOCKS5 proxy abuse from consumer devices is active in the wild, not theoretical.
Discussion angle
How cheap Android TV boxes—extremely common in Malaysian and Southeast Asian households—could be silently turning home broadband into proxy exit nodes, and what network-level detection or isolation steps are practical for non-technical family members.