Fengwo Group, including Zhejiang Fengwo IoT Technology Co., Ltd. and related Fengwo corporate entities, is a China-linked cybercriminal operation associated with the Fuyao Enterprise botnet and a large-scale ad-fraud and residential proxy ecosystem centered on Android TV boxes. The operation has been tied to preinstalled malicious or unauthorized applications on H96-brand devices and likely other OEM-customized Android TV boxes, enabling monetization of victim devices without user consent. The group’s activity centers on two primary criminal revenue streams: automated advertising fraud and residential proxy resale. In the ad-fraud workflow, infected TV boxes are spoofed to appear as mobile phones in order to generate higher-value advertising traffic, load operator-controlled websites, and perform fraudulent ad impressions and clicks while attempting to evade anti-bot controls. The ecosystem uses modular Android components, persistent command-and-control communications, browser automation, and human-behavior simulation techniques. Reported capabilities include device spoofing, screenshot capture, screen livestreaming, visual ad detection using computer vision and OCR, and workflow orchestration through a Blockly-based system that allows fraud routines to be assembled and deployed at scale. The same infected devices can also be turned into residential proxy nodes, allowing third parties to route traffic through victims’ home connections. Attribution links the operation to mainland China, specifically Zhejiang Fengwo IoT Technology Co., Ltd., which has been identified as the operating entity behind the scheme. Publicly associated Fengwo infrastructure and corporate artifacts, including overlaps in certificates, backend systems, monetization entities, and patents aligned with observed technical subsystems, support this assessment. The operation has also been associated with shell entities in Hong Kong and Singapore used to collect or route monetization proceeds. The group’s victims include advertisers, advertising platforms, and owners of compromised Android TV boxes whose bandwidth and devices are abused for fraud and proxy services. Observed fraudulent traffic has affected advertising across sectors such as finance, health, education, gaming, retail, music, food, and lifestyle content. Fengwo Group is best characterized as a financially motivated cybercriminal enterprise focused on large-scale ad fraud, proxy monetization, and stealthy post-compromise abuse of consumer IoT and Android-based devices.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a large-scale ad fraud and residential proxy operation via preinstalled backdoor apps on H96 TV boxes, including mobile device impersonation, automated ad-click fraud, and leasing victim IP addresses as residential proxies.
Operates and profits from the Fuyao Enterprise, an enterprise-scale Android TV box botnet used for ad fraud and residential proxy monetization. The operation uses preinstalled apps, device spoofing, computer vision-assisted ad interaction, Blockly-authored fraud workflows, and shell entities to collect advertising revenue.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.