Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies — What You Need to Know

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies — What You Need to Know

Some cheap Android TV boxes may secretly click ads and route strangers’ traffic through your home internet. Here’s how to check your device and protect your network starting right now.

What Happened?

According to The Hacker News, Bitsight found suspicious apps on some low-cost Android TV boxes in a report published July 30, 2026.

The apps acted like malware, meaning harmful software that secretly performs unwanted tasks. They made the boxes imitate Samsung, Huawei, Xiaomi, or Vivo phones.

The boxes then clicked online ads automatically. They could also route other people’s internet traffic through the owner’s home connection.

This turned the box into a proxy, which passes traffic between another user and the internet.

Bitsight named the operation Fuyao and linked it to Zhejiang Fengwo IoT Technology. However, public patent records alone do not prove the company operated the network.

Researchers observed 65,957 reports from about 38,000 unique device identifiers in one day. Still, this does not confirm 38,000 physical boxes because identifiers could change.

Bitsight did not report that owners’ passwords, files, or personal details were stolen. However, a device quietly using your internet can still create security concerns.

Cases like this show how harmful activity can remain unnoticed. Many people also discover data leaks only after suspicious messages or account activity appear.

If you are unsure whether your information was leaked online, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Which Android TV Boxes May Be Affected?

Bitsight said most identifiable devices reported the model name H96_MAX_V11. However, its data mostly covered older models from one brand.

The report did not provide a complete list of affected models, apps, or firmware versions. It also did not confirm every H96_MAX_V11 box was affected.

The exact number of physical devices remains unknown. Some boxes could change their digital identifiers and appear as several different devices.

The sources also did not establish who installed the apps or when they entered the supply chain.

That means the software could have appeared during manufacturing, distribution, or later setup. However, this has not been confirmed.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

How Fuyao Used Android TV Boxes

A remote control server sent each box a false phone profile. This changed identifying details that could reveal the box’s real hardware.

The apps also used image recognition to locate advertisements on the screen. Accessibility tools then helped the software interact with those ads automatically.

When the box detected an HDMI connection, it often routed outside traffic through the owner’s broadband.

With HDMI off, it waited for ad-clicking tasks.

Operators could create new tasks with a drag-and-drop editor and send them to the boxes. Bitsight captured about 40 tasks across four test devices.

Researchers also connected 144 websites to the operation. They estimated possible earnings, but those figures were models rather than confirmed revenue.