New, by me: Read This Before You Buy That TV Streaming Stick
-
@briankrebs So you're saying there's pros and cons?

@adamshostack @briankrebs Cons? /s
-
@mo @adamshostack Well, IDK about getting accused, but your device almost certainly will at some point be leased by cybercriminals.
@briankrebs you 100% would fall under suspicion, because traces would end at your house
and then it depends, if cops want to find a real criminal, or just increase KPI without doing much work
Where I live, I would never trust cops with this
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs IOW they rent out your ip address as a residential proxy but they also defraud adtech companies, so who can tell if they're good or bad?
-
A couple of teasers from the story:
Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.
Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.
According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.
@briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?
-
@briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?
@dalias @briankrebs i'll take 100
-
@briankrebs IOW they rent out your ip address as a residential proxy but they also defraud adtech companies, so who can tell if they're good or bad?
@dalias it is said you can tell the quality of a tree by its fruit, and by that yardstick the fruit is primarily traffic tied to account takeover attempts, ad fraud, mass content scraping for AI projects, or outright cybercrime.
The residential proxy services enabled by these devices are sold and resold under a number of agreements, and some have multiple proxy SDKs funneling traffic. And these devices are a shitshow on security because the underlying hardware has not even basic authentication requirements.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs
Nice article.
Just no end to people inventing new products to abuse consumers. -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Dang it! Sometimes being a procrastinating elderly Luddite does have a silver lining. I still have a mechanical answering machine and a copper wire DC (POTS) landline rotary phone stuck to the kitchen wall. No sticks, no V-mo, no streaming.
-
A couple of teasers from the story:
Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.
Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.
According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.
@briankrebs Reminding us once again that ad fraud is the best fraud because the people who could stop it don't because it makes them money too!
-
@briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?
@dalias @briankrebs Kind of thing where it could make sense to get one to publish the IPs they're controlling it from, plus any sort of protocol fingerprints. -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs Nothing good come out this AI generated bullshit while people losing jobs and their work is stolen by AI companies.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs the clickfraud is a nice feature, but pretty shady overall
-
@briankrebs So you're saying there's pros and cons?

@adamshostack @briankrebs yes, it does seem to be an operation run by pro cons.
-
@briankrebs Defrauding advertising networks? That doesn't sound so bad.
@tessarakt @briankrebs defrauding ad customers sounds worse: some of those are bottom-feeders selling dreck but almost every small business owner I've heard from has stories about paying for online ads, burning through their budget, and seeing absolutely no impact on sales. No matter how you feel about ads in general, that's not sending money to deserving parties and the ad networks still get their cut.
-
@dalias @briankrebs i'll take 100
@ariadne @dalias @briankrebs Me, too!
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I love seeing ad supported parasite apps and devices start eating each other. With luck this will lead to corporate execs doing time, getting a small taste of what we would get if we cloned their phones for free service and got caught.
Stuff like this though does make me glad I don't watch TV at all though.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs Brian, My in-laws'


swear by it.
I told em, they don't care as long as they can watch
Grace and Frankie, The Great British Baking Show, and The Crown 4 free.

-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs We used a "real" FireStick but I still don't trust it. Makes me really glad that our whole TV/stereo setup is on a switched outlet and stays off when not in use.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs "ad fraud" is just botnets fighting one another, change my mind