🟡 Medium  |  Source: The Hacker News


Cheap Android TV boxes manufactured by a Chinese IoT firm have been found pre-loaded with apps that spoof their device identity to impersonate major smartphone brands, committing ad fraud on behalf of the manufacturer. The same apps also silently enrol owners’ home broadband connections into a residential proxy network, effectively monetising victims’ internet bandwidth without consent. Dubbed ‘Fuyao’ by Bitsight researchers, the operation has been attributed to Zhejiang Fengwo IoT Technology Co., Ltd.

Security Architect’s Take: Treat consumer-grade Android TV boxes and similar low-cost IoT devices as untrusted endpoints — enforce network segmentation so they cannot reach internal resources or be used as pivot points, and consider blocking or monitoring residential proxy traffic egressing your corporate or cloud environments. If your organisation allows BYOD or guest network access, audit what device categories can connect and review egress anomaly detection for unusual outbound proxy patterns.

Original advisory: Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies