HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

H96 Android TV Boxes Co‑opted for Ad Fraud and Residential Proxy Traffic

Bitsight found Fuyao software on H96 Android TV boxes enabling operators to fake ad clicks and route proxy traffic through owners’ home connections, exposing a control gap that SOC 2 audit programs must address.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
hackread.com

H96 Android TV Boxes Co‑opted for Ad Fraud and Residential Proxy Traffic

What Happened — Bitsight discovered that the Fuyao software installed on H96 Android TV boxes enables operators to generate fraudulent ad clicks and to route proxy traffic through the owners’ home internet connections, effectively turning consumer devices into a distributed ad‑fraud network.

Why It Matters for Compliance & Audit Readiness

  • Highlights a control gap where unmanaged third‑party hardware can be weaponised, a scenario SOC 2’s System Operations criteria (CC6.1) expects organisations to monitor and mitigate.
  • Demonstrates the need for continuous evidence collection on device inventories and configuration baselines to prove due diligence during audits.
  • Shows how a robust Trust Center can provide verifiable proof of control over external hardware assets, simplifying audit evidence collection.

Who Is Affected — Advertising technology platforms, demand‑side platforms, and any service that relies on third‑party network traffic; also end‑users of H96 Android TV boxes.

Recommended Actions

  • Extend your asset inventory to include consumer IoT devices that connect to corporate networks.
  • Implement continuous monitoring of device configurations and network‑traffic anomalies.
  • Map the control gap to SOC 2 CC6.1 and collect audit evidence via a centralized Trust Center.

Source: HackRead

Technical Notes — The Fuyao software runs on the Android OS of H96 boxes, hijacking the device’s network stack to fabricate HTTP ad‑click events and proxy traffic. No public CVE; the abuse leverages legitimate functionality repurposed for malicious traffic.

📰 Original Source
https://hackread.com/h96-android-tv-boxes-ad-fraud-residential-proxies/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →