
H96 Devices Spoof Phones for Fengwo Ad Fraud Network
H96 streaming devices are centrally orchestrated to spoof mobile identities and generate fraudulent ad clicks on AI-generated sites run by Zhejiang Fengwo. The operation uses expired-domain telemetry, shell monetization entities, and visual programming tools to scale with minimal expertise. Consumer purchases of these sticks directly subsidize downstream fraud against merchants and advertisers.
Pedro Falé registered the expired domain previously used for H96 hardware and app telemetry. Incoming traffic showed uniform app installs from Fengwo Group and consistent mobile spoofing profiles. The devices funneled traffic exclusively to sites that rendered ads only for those exact profiles. Shell entities in Hong Kong and Singapore collected payments while patents filed by the mainland China firm matched the observed click coordination logic.
Fengwo maintains fwgcloud.com, which advertises 120,000 AI digital humans and hosts an internal Blockly workspace. Operators assemble fraud routines by dragging visual blocks rather than writing code, enabling rapid deployment of machine-generated finance, health, and gaming pages. This matches patterns seen in earlier proxyware and click-farm operations where consumer IoT hardware supplies captive bandwidth and identity pools.
Mainstream coverage focused on the streaming-stick purchase warning. It missed the direct link between consumer device compromise and downstream merchant and ad-network losses, as well as the low-skill tooling that lowers barriers for new entrants. Procurement records and app-store telemetry indicate the same Zhejiang entity has shipped similar firmware since 2019.
Bitsight expects continued operation until payment processors or major ad exchanges blacklist the associated domains and app signatures. Regulators in the EU and US have not yet issued takedown notices tied to these specific indicators.
Bitsight: At least 30,000 additional H96 or rebranded devices will appear in similar telemetry within 90 days unless app signatures are blocked by Google Play Protect.
Sources (3)
- [1]Bitsight TRACE H96 Analysis(https://www.bitsight.com/resources/h96-ad-fraud)
- [2]KrebsOnSecurity H96 Report(https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/)
- [3]Zhejiang Fengwo Patent Filings(https://patents.google.com/?assignee=Zhejiang+Fengwo+IoT)