We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA. Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
> generic TV boxes that promise unlimited content streaming for a one-time fee
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
Krebs' blog is nice, but quite often it's just re-reporting stuff from somewhere else:
Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...
A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
LG televisions and monitors spy on their users and install unwanted software. Half of all smart tvs are running "residential proxy" malware. Google is banning sideloading but happily hosting apps using the Bright SDK.
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
I do not see problems with fake ad clicks and have no sympathy for ad companies.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
A pirate TV box from China presents a security threat?
This is my surprised face.
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
Using low code tools to build click fraud logic FTW!
What happens when you stick this malware into your windows PC? The PC is now an accomplice to fraud?
it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
You had me at "But"! ::swoon::
Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
How hard is it to get something else on these ?
Looks like cheap small computer with a remote control.
Google clutches pearls and is shocked! Shocked! That anyone would violate its policies (while it pockets 30% of the fraudulent revenue). Shocked!
And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
A better solution is just leech the content and stick it on a generic USB flash stick.
On the other hand, these are great little devices to root and put Linux on.
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads ...
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
No mention of Roku
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.
We're called engineers brian.
To those who are OK with these devices: when you engage in corruption, do you have any moral standing against your politicians when they engage in corruption?
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
> major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
[dead]
I didnt know anybody bought a streaming stick anymore
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.
Didn't know Krebs was a mainstream news puppet.
> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?