Cheap Android TV boxes are more than just streaming gear; they are now being used to generate ad revenue and create covert proxy servers.
Bitsight's latest investigation found that a subset of these devices ship with a suite of apps that reconfigure the device's hardware fingerprint to resemble popular smartphones such as Samsung, Huawei, Xiaomi, or Vivo.
By masquerading as high‑profile phones, the boxes can bypass certain content restrictions and access ad networks that otherwise would be blocked on generic hardware.
The same applications also contain a second function that turns the home network into a proxy. Once the box is online, the apps use the device’s IP address to forward traffic from other devices on the same Wi‑Fi.
Researchers named the operation Fuyao and linked it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China‑based company founded in 2019 that supplies hardware for the Android TV market.
In a public statement, Bitsight noted that the firmware modifications are installed at the factory level, meaning consumers receive the devices fully configured for the illicit activity.
The proxy behavior is subtle: the traffic is routed through the device’s own IP, making it appear as though the household’s own traffic originates from the box itself.
This not only erodes user privacy but also introduces potential security risks, as the device may be used to route malicious traffic without detection.
The companies behind the boxes have not issued a formal response, but the industry watchdogs urge manufacturers to audit firmware before shipping.
For consumers, the lesson is clear: when buying a budget Android TV box, verify the firmware source and consider using a dedicated network segment to isolate the device.