买那个电视流媒体棒之前请先读读这篇文章
背景与摘要: 安全专家长期以来一直警告,那些非品牌的通用电视流媒体盒子会秘密出租用户的互联网连接作为住宅代理(residential proxy)。然而,Bitsight 的最新研究揭示了一个更黑暗的现实:这些廉价的杂牌设备还被武装成了大规模、自动化的广告欺诈网络。数以万计的 H96 流媒体棒伪装成手机,在各种 AI 生成的网站上隐蔽地点击广告,据估计,这每天能为一家名为“蜂窝集团(Fengwo Group)”的中国大陆实体创造超过 50,000 美元的收入。
Summary
Security experts have long warned about generic TV streaming boxes that secretly rent out users' internet connections as residential proxies. However, new research from Bitsight reveals a darker reality: these cheap, off-brand devices are also weaponized in massive, automated ad fraud networks. Masquerading as mobile phones, tens of thousands of H96 streaming sticks are covertly clicking on ads across AI-generated websites, generating an estimated $50,000+ a day for a mainland China-based entity known as the Fengwo Group.
广告欺诈网络剖析
Bitsight 的安全研究人员最近调查了一个名为 H96 的热门通用流媒体设备品牌。威胁研究员 Pedro Falé 在注册了一个之前用于设备遥测的过期域名后,深入了解了该操作系统的运作。
The Anatomy of an Ad Fraud Network
Security researchers at Bitsight recently investigated a popular brand of generic streaming devices known as H96. Threat researcher Pedro Falé gained deep visibility into the operation after registering an expired domain previously used for device telemetry.
该域名并没有收到标准的电视盒数据,而是被大量的遥测数据淹没,这些数据声称全球插入电视机中的成千上万个 H96 流媒体棒,实际上是三星、Vivo、华为和小米等制造商生产的手机。
Instead of receiving standard TV box data, the domain was flooded with telemetry claiming that tens of thousands of H96 streaming sticks plugged into television sets globally were actually mobile phones made by manufacturers like Samsung, Vivo, Huawei, and Xiaomi.
[H96 流媒体棒] ---> (伪装成移动设备) ---> [AI 生成的网站] ---> [自动化广告点击 / 欺诈]
进一步的调查显示,所有受感染的设备都共享着两款预装应用,这些应用与浙江蜂窝物联网科技有限公司(以蜂窝集团名义运营)有关联。这些应用通过利用这些被俘获的电视盒去点击托管在 AI 生成的网站(以机器生成的新闻和博客为特色)上的广告,来精心策划这个广告欺诈网络。值得注意的是,这些广告只有当被与伪造的 H96 流媒体棒移动设备配置文件相匹配的设备访问时才会出现。
Further investigation revealed that all infected devices shared two pre-installed apps tied to Zhejiang Fengwo IoT Technology Ltd (operating as the Fengwo Group). These apps orchestrate the ad fraud network by using the captive TV boxes to click on ads hosted on AI-generated websites featuring machine-generated news and blogs. Notably, these ads only appeared when visited by a device matching the spoofed mobile profile of an H96 stick.
AI 数字人与低技能操作
蜂窝集团的主要域名 (fwgcloud[.]com) 宣称该公司专注于用于客户服务和陪伴的“AI 数字人”。然而,在这层伪装之下,隐藏着一台工业级的广告欺诈机器。
AI Digital Humans and Low-Skilled Operations
The primary domain for the Fengwo Group (
fwgcloud[.]com) claims the company specializes in "AI digital humans" for customer service and companionship. However, behind this facade lies an industrial-grade ad fraud machine.
Bitsight 发现,蜂窝集团使用谷歌 Blockly(一种最初为儿童设计的可视化编程语言)的专有实现方案,来构建其虚假网站和自动化脚本。 * 高成本效益: 通过使用 Blockly,低技能的操作人员可以拖放代码块来定义欺诈程序,而无需具备深厚的技术专长。 * 拟人化交互: 为了确保机器人成功导航并点击广告,蜂窝集团集成了模仿人类浏览行为的视觉和推理系统,在后台静默启动浏览器、管理标签页并与登陆页面进行交互。
Bitsight discovered that the Fengwo Group uses a proprietary implementation of Google’s Blockly—a visual programming language originally designed for children—to build its sham websites and automation scripts. * Cost Efficiency: By using Blockly, low-skilled operators can drag and drop code blocks to define fraud routines without needing deep technical expertise. * Human-Like Interaction: To ensure the bots successfully navigate and click ads, the Fengwo Group integrates vision and reasoning systems that mimic human browsing behavior, silently launching browsers, managing tabs, and interacting with landing pages.
电视开机与关机:白天是代理,夜晚行欺诈
Bitsight 的分析揭示了 H96 设备内一种巧妙的运作双重性: * 电视开机(检测到 HDMI 信号): 该设备充当住宅代理,将用户的互联网带宽出租给匿名的第三方(从网页抓取者到网络犯罪分子不等)。 * 电视关机: 该设备转换模式,执行资源密集型的广告欺诈任务,确保后台恶意活动不会干扰用户的视频流媒体体验。
TV On vs. TV Off: Proxy by Day, Fraud by Night
Bitsight's analysis uncovered a clever operational duality within the H96 devices: * TV On (HDMI Signal Detected): The device functions as a residential proxy, renting the user's internet bandwidth to anonymous third parties (ranging from web-scrapers to cybercriminals). * TV Off: The device switches gears to execute resource-intensive ad fraud tasks, ensuring the background malicious activity doesn't interfere with the user's video streaming experience.
尽管联邦调查局(FBI)和各网络安全机构多次发出警告,但亚马逊、百思买(Best Buy)和新蛋(Newegg)等主要电子商务平台仍在继续营销和销售数以百计这种不安全、未经认证的基于安卓的设备。
Despite repeated warnings from the FBI and cybersecurity agencies, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to market and sell hundreds of these insecure, uncertified Android-based devices.
运作规模
- 全球足迹: Bitsight 追踪到大约 38,000 个电视盒 曾尝试连接回仅有的一个过期蜂窝集团域名。
- 每日收入: 保守估计表明,该广告欺诈网络每天产生近 50,000 美元的收入,这还不包括来自住宅代理业务方面的额外利润。
- 无回应的操作者: 当 KrebsOnSecurity 试图联系蜂窝集团寻求置评时,邮件因收件箱已满的提示而被退回,这标志着冲击其基础设施的流量之大。
The Scale of the Operation
- Global Footprint: Bitsight tracked approximately 38,000 TV boxes phoning home to just one expired Fengwo Group domain.
- Daily Revenue: Conservative estimates suggest the ad fraud network generates close to $50,000 per day, excluding additional profits from the residential proxy side of the business.
- Unresponsive Operators: When KrebsOnSecurity attempted to reach out to the Fengwo Group for comment, the inquiry bounced back with a full inbox notification, signaling the sheer volume of traffic hitting their infrastructure.
如何保护自己
为了保护您的家庭网络和个人数据免受僵尸网络和广告欺诈集团的利用: 1. 坚持选择知名品牌: 仅从具有官方操作系统构建和安全认证的信誉良好的制造商(例如,Google TV, Apple TV, Amazon Fire Stick, Roku)购买流媒体设备。您可以使用谷歌的官方指南来验证官方 Android TV 操作系统和 Play 保护机制的状态。 2. 审查您的应用: 对您在智能电视和流媒体棒上旁加载(sideload)或安装的应用程序要极其挑剔,因为许多应用可能捆绑了隐藏的代理软件。 3. 查看威胁情报列表: 安全公司 Synthient 维护着一个可公开访问的物联网产品列表,列出了已知附带预装恶意应用和住宅代理的产品(包括某些通用数码相框和流媒体盒)。
How to Protect Yourself
To safeguard your home network and personal data from being exploited by botnets and ad fraud syndicates: 1. Stick to Name Brands: Only purchase streaming devices from reputable manufacturers (e.g., Google TV, Apple TV, Amazon Fire Stick, Roku) that feature official OS builds and security certifications. You can verify official Android TV OS and Play Protect status using Google's official instructions. 2. Audit Your Apps: Be extremely selective about the apps you sideload or install on smart TVs and streaming sticks, as many can bundle hidden proxy software. 3. Check Threat Intelligence Lists: Security firm Synthient maintains a publicly accessible list of IoT products known to ship with pre-installed malicious applications and residential proxies (including certain generic digital photo frames and streaming boxes).