Smart refrigerators, cars and computers can show ads after updates, raising privacy and ownership concerns, Kurt "CyberGuy" Knutsson explains.
You plug a streaming box into your television, connect it to Wi-Fi and settle in for a movie. Meanwhile, that little device may have a completely different job running in the background.
Security researchers say some cheap Android TV boxes can secretly route outside traffic through a household's internet connection. New research from Bitsight shows that some boxes may also pretend to be smartphones, visit AI-generated websites and click online ads.
The hidden activity can generate advertising revenue or turn the box into a residential proxy that lets strangers use your home internet connection. Bitsight's latest findings reveal how organized and technically advanced one such operation may have become. That inexpensive streaming box could cost you far more than its purchase price.
BRINKS HOME DATA BREACH PUTS 1M CUSTOMERS ON ALERT
New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats
Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt "CyberGuy" Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
Security researchers say some cheap Android streaming boxes can secretly click ads, spoof smartphones and route outside traffic through a home internet connection. (Kurt "CyberGuy" Knutsson)
Bitsight threat researcher Pedro Falé uncovered the operation while studying security risks involving cheap Android TV boxes. His team found an expired domain that had previously managed factory backdoors on certain devices. Bitsight registered the domain and began observing the information sent to it.
The domain collected hardware information and lists of installed apps from connected boxes. Researchers quickly noticed something unusual: Many of the devices identified themselves as phones from brands including Samsung, Vivo, Huawei and Xiaomi even though their software revealed signs of TV boxes. Falé wrote that researchers noticed "something was wildly wrong." Bitsight eventually named the operation the Fuyao Enterprise.
Bitsight says the Fuyao apps appeared to arrive preinstalled on some Android TV boxes sold under the H96 name. Researchers found the apps most often on older H96 Max V11 devices. However, the available data covered only certain older models that reported to the expired domain.
The findings do not establish that every H96 device contains the software. Bitsight also raised the possibility that an original equipment distributor, reseller or custom firmware provider added the apps before the boxes reached consumers. That means researchers cannot say from the available evidence exactly where in the supply chain the software was added.
A Google spokesperson told CyberGuy, "The infected devices are Android Open Source Project devices, not Android TV OS devices or Play Protect certified Android devices. If a device isn't Play Protect certified, Google doesn't have a record of its security and compatibility test results."
That distinction is important. These boxes may use Android's open-source code, but they should not be confused with devices running Google's official Android TV OS.