H96 Streaming Devices Linked to Ad Fraud Network, Spoofing Mobile Phones to Defraud Merchants

Published:

spot_img

Recent findings have revealed that H96 streaming devices are linked to an extensive ad fraud network, which not only exploits users’ internet connections but also masquerades as mobile phones to generate fraudulent ad clicks. This alarming discovery was made by Pedro Falé, a threat researcher at Bitsight, who uncovered the operation by registering an expired domain previously used for coordinating fake ad clicks. The implications of this fraud extend to online merchants and advertising networks, raising significant concerns for cybersecurity defenders.

Ad Fraud Mechanism

Falé’s investigation into the H96 devices revealed that they were transmitting data while claiming to be various mobile phone models from manufacturers like Samsung and Huawei. This spoofing allows the devices to participate in a fraudulent ad-clicking scheme on AI-generated websites operated by the Fengwo Group, a company based in mainland China.

Operational Insights

The analysis indicated that the H96 devices were either functioning as residential proxies or engaging in ad fraud, but not simultaneously. When a television is connected, the device acts as a proxy; when the TV is off, it shifts to ad fraud activities. This dual functionality highlights the resource-intensive nature of the ad fraud operations.

Revenue Estimates

Bitsight estimates that this ad fraud network generates approximately $50,000 daily, based on telemetry from around 38,000 devices globally. The Fengwo Group’s claims of having over 120,000 “AI digital humans” at their disposal may serve as a marketing tactic to obscure the true nature of their operations.

For more detailed insights, refer to the full report by KrebsOnSecurity.

spot_img

Related articles

Recent articles

Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities, Revealing Vulnerabilities and Response Gaps

In a significant cybersecurity incident, over 30 water and wastewater utilities in Minnesota were targeted by a coordinated cyberattack between July 26 and July...

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...