The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids’ Coding Blocks

fuyao enterprise blog
Pedro Fale
Written by Pedro Falé
Threat Researcher

In this post, we will uncover the “Fuyao Enterprise,” a previously unknown, sophisticated and highly modular botnet operating within Android TV boxes. This operation marks a shift in modern ad-fraud, where automated bots fake both clicks and views to defraud advertisers and ad-networks. While deploying novel tactics and techniques, Fuyao managed to escape public research for several years. Now, its operators openly advertise their network of over 120,000 “AI digital humans."

Fuyao has the capability of executing a dual-monetization strategy through residential proxy, where network traffic is forwarded via your home network, without consent, and the previously mentioned ad-fraud. To conduct sophisticated ad-fraud, they employ multiple bots mimicking human-like behaviour across thousands of AI content generated websites, that interact undetected with the ads. 

Key takeaways

  • Fengwo Group: Operates an enterprise level ad-fraud scheme, under the guise of over +120,000 AI digital humans.
  • Multiple bots conduct sophisticated ad-fraud, mimicking human-like behavior across thousands of AI content generated websites. The botnet base is Android TV boxes, whose identities are spoofed as mobile phones.
  • The operation has the ability of a dual monetization strategy of its bots: ad-fraud and residential proxies.
  • Apps identified, which appear to come pre-installed in some H96 brand devices, can also livestream the screen back to the C2 and employ novel technology such as computer vision models for ad-detection.
  • The Fengwo Group fraud tasks are created using a custom-built editor of Blockly, and can give visual feedback of current fraud campaign task execution, per bot.
  • Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group.
  • Zhejiang Fengwo IoT registered patents match the inner workings of the Fuyao apps (ad-fraud) and supporting systems, as researched by Bitsight TRACE.

In the Fuyao operation, ad-fraud is treated as a product. The entire operation showcases great adaptability, incorporating novel technology for internal development and execution layers. In Fuyao, a singular app orchestrates multiple task dedicated apps, devices livestream the screen back to the server, and its operators constantly seek to implement novel technology within their processes. Fuyao overcomes the fragility of pure script-based automation (which frequently breaks with UI updates) by employing computer vision models (VLMs), exploring the usage of generative AI and many other features. Furthermore, the Enterprise employs novel techniques to bypass contemporary anti-bot measures. It utilizes robust identity spoofing mechanisms by masquerading at-will as mobile smartphones rather than cheap streaming devices, constantly seeking to evade ad-network detection algorithms

The logic behind each fraud campaign is entirely built using their custom editor of Blockly, a visual programming language for kids, where you drag blocks “of code.” With this, they can delegate tasks to less technically inclined operators, who can build fraud campaigns by dragging several fraud blocks together.  The ad-fraud is never visible to the user; even with a TV screen connected, it happens silently, mimicking human-like activity. The landing websites, where the ad-fraud is conducted, indicate usage of AI to template and generate content to legitimize appearances, while maintaining coherentness with the overall website context / category.

For the financial kickback, the Fuyao operators registered multiple accounts under fake identities with popular ad networks, such as Google AdSense and Taboola. These accounts operate under ‘legal‘ / shell entities, mostly out of Hong Kong and Singapore, to collect the ad-revenue on the other end. We also followed this trail and TRACED the operators to a Mainland China incorporation, whose registered patents match some of the systems supporting the ad-fraud operation.

All these features, and many more, are documented for you the reader, in this blog. Fuyao strays from traditional, low effort modus operandi of ad-fraud. In fact, an entire company was created and is solely dedicated to building a product that conducts this fraudulent activity. Sitting at the cutting edge, its novelty features all serve as an augmentation of existing processes over time, and not hype based blind replacement.

This post presents the first end-to-end highlight dissection of “Fuyao,” an enterprise level ad-fraud scheme, with a final attribution to mainland China company known as the “Fengwo Group.” This research has taken quite some time, so I hope you as the reader enjoy it. 

To the discovery of this operation, I named it: The Fuyao Enterprise.

Author note: The publication of this post will be followed by two detailed technical publications released sequentially. Anatomy of a Fuyao Box, focusing on APK analysis and tech, and Fuyao Ad-fraud as a Product, covering Fuyao’s ad-fraud ecosystem and infrastructure extensively.

Preamble

This discovery, like many, happened by chance. As I was writing about the dangers to consumers when acquiring cheap Android TV Boxes, I stumbled upon this. The initial research was simple, documenting factory backdoors (in Android TV boxes), used mostly for remote management in dev, which are shipped to production and sold to consumers. The case was made that shipping this backdoor, which was a remote shell with full root execution, was poor sanitization practice. If the domain associated with this backdoor expired, full access would be granted to over 400k devices inside homes, and companies. Free to install any additional apps, and explore other devices within the same networks.

Our team at Bitsight TRACE managed to register this domain, as it was expired. The domain in question didn’t just ‘help’ manage each device: it was also used for telemetry collection. Each Android TV box would periodically send full hardware information and the entire list of installed apps. Here lay the issue, upon condensing telemetry for a period of 24h hours, we noticed something was wildly wrong…

Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’ From Xiaomi models, to Huawei, Vivo, Samsung and multiple other profiles. This made no sense.

Early highlight of ‘phone’ models, reporting to a TvBox backend
Figure 1 - Early highlight of ‘phone’ models, reporting to a TvBox backend.

These logs appeared to be phones through and through, minus some minor inconsistencies. The vast majority of entries were consistent, with hardware properties matching phone profiles. One thing quickly stood out by looking at the installed packages, for each ‘phone’ device. Some of these still had TvBox related packages, such as launchers, settings, and other apps. Doing some quick data analysis on the list of installed apps across every record, showed 2 apps consistently appearing on ‘phone’ profiles, and sometimes on Android TV boxes. The culprits were the first Fuyao Apps.

At this point, a colleague rightly pointed out, we need to get to the bottom of this.
That was the beginning of the research on “The Fuyao Enterprise”.

What is Fuyao?

Fuyao was the name given to this operation, it appears in naming of apps, internal code and credentials. But you might be wondering, what does Fuyao mean? In Chinese, “Fuyao” means to soar in a whirlwind trajectory, “symbolizing both rapid success, ambition and luck.” This name is consistently mentioned across the operation ecosystem, starting with its apps.

The Fuyao apps are shipped pre-installed, on TV-Boxes. Likely by some form of customization via OEM distributor, re-selling, and/or spreading their customized ROMs for download /re-flashing. There are some very obvious pieces of evidence pointing to this, such as install paths and user privileges.

From a factory Android TV Box, to a trusted ad-fraud bot
Figure 2 - From a factory Android TV Box, to a trusted ad-fraud bot.

The follow-on sub-packages are both installed dynamically to /data/local/system.

Fuyao’s business model operates under its ability to always identify where an ad lives on a website, spoof the device as a phone for more premium clicks, increasing revenue gained from each click and avoiding getting flagged as a bot by mimicking human behavior. The operators run AI content generated websites and register legal entities as publishers under Google or Tabooba. Obtaining the revenue for each click or every thousand views, on the ads displayed in their websites. 

Revenue estimations

On a conservative estimate of 10 clicks per device at $0.10 on average (which could vary based on device spoofing success and other aspects such as geolocation, landing pages, etc.), that would be around $1 per day, per device. Add to that a cost-per-thousand of $0.25  for impressions alone and you would get around $1.25 per device, per day. It might not seem like much, but on an advertised fleet of ~120,000 that would still be an astonishing amount of ~$150k per day.

A globally-distributed fleet feeds ad clicks and impressions through registered publisher accounts
Figure 3 - A globally-distributed fleet feeds ad clicks and impressions through registered publisher accounts.

Even for the lowball fleet of ~38k devices we managed to confirm via sinkhole, it would still mean ~$47.5k /day. Sure, some clicks may get flagged, there might be post fraud-filtering, and impressions could be invalidated due to bot traffic. But even on a 30–40% flag and 70% ad-fill it’s still undeniably a massive revenue source, with potential to reach up to $40 million a year in revenue.

We also observed some overlap with our residential proxy data, which confirmed this botnet is also likely sold as residential proxies. Passively adding another revenue stream on top of the ad-fraud scheme.

Next, we will look into 3 chapters: inter-app connectivity and the novel tech powering the ad-fraud, how the fraud ecosystem works, and finally, attribution linking active campaigns to a Mainland China corporation profiting from the scheme.

The apps 

After restless nights going down the analysis rabbit hole of dealing with several versions of mostly huge 60MB APKs, I'm glad to synthesize it all for you, starting with the capabilities of this botnet. The Fuyao suite has two modes: running in full-mode, or just a proxy run. Below you can see an image depicting a very high-level overview of the Fuyao system.

Fuyao apps ecosystem
Figure 4 - Fuyao apps ecosystem.

The Fuyao Enterprise targets Android TV boxes to use as a base for their operational activity by having these boxes ship with the Fuyao apps pre-installed. Threat actors possess the ability to spoof TV boxes as premium devices (phones) via hardware system property changes, browser injection, user-space process execution (user-sharding), and much more. This app ecosystem also sends logs, periodic screenshots, and can even livestream the ‘screen’ back to the C2. This is possible via their WebRTC implementation and current C2 command suite.

This fraudulent activity materializes in a robust human-mimicking way. The latest versions of the apps show an evolution from pure javascript, to automating fraud utilizing pre-trained machine learning models to improve, automate, and failsafe fraud execution.

Fraud tasks are pushed only after the client successfully completes a series of readiness tasks, given by the C2. When considered a ‘ready’ node, and depending on location, a fraud task is given to the infected TV box. These ad-fraud tasks are created via Blockly. We will cover this novelty feature, as well as the reason behind this choice. The entirety of the Fuyao ecosystem is highly modular, with functionality spread across applications.

The Center app serves as an orchestrator that performs device checks, proxy service and is ultimately responsible for orchestrating between the C2 and other sub-packages, like Script and Remote. The following image provides an overview of this inter-app connectivity:

Fuyao inter-app connectivity
Figure 5 - Fuyao inter-app connectivity.

The Center app is also responsible for communicating and maintaining a persistent websocket connection, with the Command & Control infrastructure. The existence of these 2 packages (Script,Remote) has been fairly consistent through time, while some other packages have been removed.

systemUpdate – Exists in parallel with the Center app, but not on every model. It is responsible for the process of spoofing / changing Android TV box hardware properties into mobile phones. Although this capability seems to have been migrated into the Center app later on.

Webfetcher – Comes embedded within the Center app, it’s a dedicated headless browser that injects a stealth.min.js into every page it visits, also spoofing system properties, such as CPU, GPU, etc.

Tech on a box: UI perception

One of the distinctive qualities in the Fuyao Enterprise is their approach that enables ad-fraud. Allow me to explain. Traditionally, ad-fraud and social-media botnets relied purely on scripting automation, such as DOM injection (breaks easily on UI updates) or naive accessibility-service scraping, implementing a singular approach. Fuyao instead fuses three vision and reasoning systems into a single interface: Android Accessibility nodes, ncnn-based YOLO object detection, and Google MLKit OCR, using VLMs to augment and create a failsafe for ad-detection.

The Script app ships with a YOLOv8s (You Only Look Once) object detection model, named “lourui_2”, inside the assets/ folder.

Homepage of a YOLO model
Figure 6 - Homepage of a YOLO model.

Their computer vision model is pre-trained and acts as the "eyes" of the bot, as a failover when attempting to identify an ad on a webpage, allowing it to navigate a user interface visually, much like a human would. 

Fuyao fuses accessibility, computer vision and OCR so a bot can “see” and click ads like a person
Figure 7 - Fuyao fuses accessibility, computer vision and OCR so a bot can “see” and click ads like a person.

The YOLO model, named lourui_2 has been trained to recognize 12 distinct types of objects, such as buttons, search fields, etc, that function as an ad-layout classifier. We have also seen some exploratory code around this using Azure GPT instead. Although the developers seem to have strayed away from this option, leaving the deprecated code behind. See below, the pre-trained ad-layout classifier (VLM) and a note regarding Azure GPT.

Fuyao fuses accessibility, computer vision and OCR so a bot can “see” ads
Figure 8 - Fuyao fuses accessibility, computer vision and OCR so a bot can “see” ads.

Two classifier classes quickly stand out, being purely ad-related:

  • Adv: Generic ad / banner regions 
  • Taboola: Taboola "around-the-web" content-recommendation widgets 

These are explicitly used in the context of ad-networks. The rest of the classes focus around page navigation (header, footer, searchbar, menu ,etc). Lourui_2.param can also be loaded into the netron.app, for a clearer visualization, see the image below.

lourui_2.param loaded into netron.app_..
Figure 9 - lourui_2.param loaded into netron.app. 

The decisions are split into two specialized streams: one focuses exclusively on the location of a button, while the other focuses on the classification (what that button actually is).

Nonetheless, this already indicates enough that the actor has a grasp on ML architecture and showcases they are keeping up with implementing ML research into their process, molding it to their needs. They also developed their own customized version of the Android features, allowing them to converge the 3 data sources into the subsequent downstream benefits of using Android Accessibility. This process, and many others (which they patented), will be further detailed in the first part of a two part upcoming technical blogpost Anatomy of a Fuyao Box.

Azure GPT-4o

From what I've observed over time in Fuyao, the actors have sought to improve an already existing process, or add flexibility / resilience to this process with the usage of AI. AI might lower the barrier for some, but I believe that for more experienced actors, it’s a tool that can improve existing workflows, for scale or flexibility. For those interested in reading a little more about this evolution / adoption beyond the hype, I really recommend reading the human security post on “AI-Powered Fraud.”

From what I was able to tell there is a lot built around its usage, but it’s not hooked up anywhere in the code. So it seems to be deprecated scaffolding left behind. Its usage however, is very apparent, as it was being implemented for decision making on where to click, and rational on where to navigate next.

Residential proxy

Still within the box, the Center app also runs a foreground server. The role of this proxy server is to turn the infected device into a residential SOCKS5 exit node. The device will continuously poll the HTTP endpoint of /app/device/getBoxProxySer to fetch the proxy backconnect servers. These are servers a box will then establish a persistent tunnel / connection to and be forwarded traffic. This tunnel is layered between standard Netty pipeline and a custom protocol encoder and decoder. The custom protocol is split in two: An outer custom layer handling session metadata, and an inner layer using standard SOCKS5 payload.

Proxy custom packet parsing with a SOCKS5 payload
Figure 10 - Proxy custom packet parsing with a SOCKS5 payload.

Within the encrypted metadata, a localChannelId allows the Fuyao app to multiplex several concurrent proxy sessions over a single Netty tunnel, between the TV Box and the backconnect bridge: one tunnel, many concurrent SOCKS5 sessions.

As previously mentioned, there is an overlap with residential proxy data. Even though we have limited visibility, we could still see that at least one in six Fuyao boxes overlapped with our residential proxy data in a 24 hour period, and one in four for a 7 day period. That means the Fuyao operators very likely rent out their bandwidth to commercial residential proxy providers. An overwhelming majority (over 90%) of the Fuyao boxes performing residential proxy only had the Center app installed. Matching our initial assessment of the Fuyao apps workflow, where CheckSelf() mostly translates to run proxy when the HDMI cable is on, run ad-fraud when the HDMI cable is off.

The fraud

The Fuyao Enterprise consists of multiple tiers of C2s, each serving different purposes, the system however relies on a set of hardcoded IP addresses and ports for initial contact and to posteriorly establish persistent websocket connections. One Tier dedicated to initial contact, a second to spoofing, and a final for the persistent websocket. There are also S3 buckets for sharing configs / files.

Spoofing 

This sub-chapter focuses on the spoofed ‘phone’ profiles being sent by the C2 server. This happens under the endpoint /app/device/getBoxModel. While we had some success requesting to the endpoint directly, with 40 requests over different days, we only got 7 distinct profiles returned,even though the universe of spoof profiles is much larger. Here’s why.

In the example below, you can see a decrypted C2 response to enforce a complete spoofing of a Meizu M3 Note phone profile.

C2 pushed Meizu M3 spoofing config
Figure 11 - C2 pushed Meizu M3 spoofing config.

The properties config is merged between the base config and the provided diff config. It can also delete properties related to platform-specific identifiers from rockchip, amlogic, allwinner and others.

They also make sure that the spoofed version doesn’t diverge far from what the underlying ROM actually exposes, in order to reduce detection of inconsistencies. The spoofing properties are likely real phone profiles, which has been a trend somewhat alluded to recently by castle research.

It became clear the spoof template assigned probabilities (weights), which dictate how frequently each profile is deployed. These weights varied across days, so there is likely server side logic that rotates these campaign weights, because there are actually hundreds of spoofing profiles. We uncovered this by recursing to our initial backdoor and telemetry domain, which led to this entire research.

All devices reported to the domain with a payload containing device model, and other system properties, such as: brand, board, firmware version, cpu and many other fields. As you can imagine this was a researcher's gold. Below is an example of an entry.


JSONH96_MAX_V11
{"width": "1920", "height": "1080", "buildId": "RQ2A.210505.XXX", "buildDisplay":
"20230504.XXXX", "product": "rk3328_box", "board": "rk30sdk", "brand": "Rockchip", "device":
"rk3328_box", "model": "H96_Max_V11", "bootloader": "unknown", "hardware": "rk30board",
"fingerprint":
"Rockchip/rk3328_box/rk3328_box:11/RQ2A.210XXX.XXX/eng.pc.20230XXX.XXXXXX:userdebug/release-k
eys", "sdkInt": "30", "incremental": "eng.pc.20230XXX.XXXXXX", "release": "11", "baseOS": "",
"securityPatch": "2021-XX-XX", "mac": "XX:XX:XX:XX:XX:XX", "serial": "XXXXXXXXXXXXX",
"cpuserial": "XXXXXXXXXX", "pkgs": [...]}

This reporting also came with a 'pkgs': [''] field that discloses all current packages in the devices, and we observed both the sysserver.systemUpdate and the Fuyao apps packages in these devices. The Fuyao apps were found mostly H96_MAX_v11, which could definitely be skewed due to the domain being present in older models, but they were also observed in spoofed devices reporting as “phones.”

Sinkholed phone spoofing

After parsing a sample of 24 hours of logs associated with the backend sinkholed domain, filtering exclusively for entries that reported Fuyao apps installed, we got the following statistics: 65,957 device reports across ~38,000 unique MAC addresses. And most of them were not the phones they claimed to be.

Figure 12 - 24H Sinkhole telemetry
Figure 12 - 24H Sinkhole telemetry

The first two packages, on the right, are universally pre-baked into the firmware. Although the unique MAC count of spoofed phone profiles likely overestimates physical device counts, depending on how spoofed identities rotate, the domain only gives us visibility into some older TV box models from one brand. So the true universe of affected devices is probably larger.

Blockly

Enterprise ad-fraud

Probably one of the most fun chapters in the blogpost, and something I‘ve never seen documented before: a complete novelty. The operators use Blockly, a visual programming language, usually reserved to teach kids learning to code, to construct on their side the logic behind the extremely modular fraud tasks, which then gets pushed to the TvBox.

Blockly is a Google built visual programming language, where you can drag blocks together instead of coding. Yes, this is what all those languages that help kids learn programming with ease now use underneath. And Fuyao is using this in the middle of their fraud process. Some of you might remember learning programming with Scratch(3.0), which uses Blockly technology to create its blocks. In Blockly, you can still export the underlying code in several formats, one of which is javascript.

Google Blockly homepage
Figure 13 - Google Blockly homepage.

And the threat actors use it on their build side, which goes hand in hand with the ‘commercial’ or ‘Enterprise’ like feel on this whole operation. An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type. Once the routine is saved, it gets exported as JavaScript (JS) and uploaded to the S3 buckets. The client executes this JS and it actually never sees this Blockly structure. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use. Some quick wins for the operator are: authoring speed, reusability, visibility.

We actually found a Fuyao developer mentioning exactly these advantages. The comment translated to the following: "Only a small number of highly-skilled developers are needed to build the template execution-unit images; developers who create execution units from those templates have significantly lower technical requirements (...) greatly reducing the company's operating costs." 

If the device is chosen in the long list of devices, for a fraud specific task, a push of a pushMsg event called pushTaskModule triggers a chain that ends with a browser on the box clicking ads on websites. The fraud task comes with a pre-config: target website, browser distribution, click and cache cleanup probabilities, and bounce-rate target. When the pushTaskModule event arrives, it comes with a scriptModulesSnapshotZip link to a "modules.txt” file. Inside there were links to ~56 ad-fraud modules created using Blockly.

The following are approximations of what the Blockly blocks could look like on the operator side. Of course it’s not 1-to-1, but a visual approximation due to the operators having built their own Blockly editor, containing the fraud specific custom blocks. In general, most modules would have the size of the ones depicted below, so you get an idea.

Approximation of Blockly fraud modules - operator view
Figure 14 - Approximation of Blockly fraud modules (operator view).

Once a device starts receiving these tasks, it means it has successfully passed all C2 checks, and is now a trusty node within the botnet, ready to carry out fraud tasks.

Fraud modules

After registering some devices to this network, running two separate runs. A first run for ~24h and second run ~2 hours. In that second run, we registered 4 unique devices, and were able to capture around 40 fraud tasks and extract meaningful insights. From the 40 tasks, some of them were duplicated, 21 unique campaigns were identified, each pointing to a different destination site.

Profile

UptimeTask pushes captured

Unique snapshot IDs

RK3318

~28 h

3017

MTK6761

~1 h 17 m

43

MTK919

>~47 m

22

Google Pixel

~47 m

44

Overall we got around 166 unique Blockly modules pushed and split them into the following 3 major groups.

  • ~25 core modules (browser, tabs, telemetry)

  • ~32 functionality modules(swipe profiles, browser decision, fallbacks)

  • ~109 single target modules: logic that exists exactly for each targeted website.

I’ve also divided the task modules into 7 distinct category:

Category

Objective

Browser launch & state

Open a specific browser and reach a known clean state. Per-browser variants exist because each browser's launch UI differs.

Browser hygiene

Wipe cache between rounds (bot navigates settings, browser specific)

Tab management

close tabs the bot opened in prior round

Browser-decision

Roll based on input args, (firefox,edge,opera) probability. Install browser if missing

Page navigation

Scroll, browse, simulate reading times

Ad detection & engagement

Ad-clicking related, combines the machine vision, long pressing, compare ad-context to page domain, etc

Telemetry / QA

Session timings, Home page load time, ad load time

Target specific

Usually modules that contain reference to destination site or self-operated

Essentially the fraud resumes to the following: browser orchestration across four major browsers, telemetry channels, ad detection, browser hygiene. A new campaign / target spinned up will bring its own URL, click-rate, browser mix weights, and only a handful of site / target specific modules.

These ad-fraud task modules returned by the C2, will be detailed and made publicly available in the technical report.

Fraud publisher ecosystem

Who benefits when a Fuyao bot clicks an ad.

The Fuyao Enterprise runs an ad-publishing portfolio, using the botnet as a captive traffic source that clicks on ads on the operator’s own pages.  The advertisers pay Cost per Click (CPC) and every thousand views, often referred to as Cost per Mille (CPM). The operators of Fuyao collect the publisher payout by faking this traffic. This chapter follows that trail, from the URLs the bots hit, to how these targeted websites are structured and finally the legal entities collecting the ad revenue behind it.

By the end of this current research, we were able to map 144 operator-owned domains (likely larger), several beneficiary entities, and bridge to identify the operators' mainland Chinese incorporation.

First, let's step into what these landing pages look like and how they operate. These pages exist across several different categories, finance, health, food, etc. The content on them seems to be AI generated, with articles being published on a daily basis. See below some examples of this.

Ad landing websites
Figure 15 - Ad landing websites.

Now you might be thinking, where is the advertising? The websites employ their own client-side scripts that will only show the advertisement sections if the device is i.e android or mobile, etc. The criteria of these scripts differ per website and per advertised network, such as ads only rendered to bots that have freshly cleared cache or accepted the consent banner. But if everything went correctly, you would see the sections. See below.

Ad landing website, with Taboola -Temu- ads
Figure 16 - Ad landing website, with Taboola (Temu) ads.

These sections were not only on the main page, but across several of the pages of the website, including in articles, about-us page, disclaimer, privacy policy, etc.

Operator clustering

By the end of this research we were able to map the 144 operator-owned domains, across 7 beneficiaries clusters. Keep in mind the total corpus of monetization websites is likely larger still. These websites are also spun up and removed on flagging.

Getting paid when a bot clicks
Figure 17 - Getting paid when a bot clicks.

This mapping was done with efforts of recursive pivoting, and attribution to legal entities, either individual, or organizational shells. This clustering was conducted according to Taboola slugs, via the publicly available sellers.json. Where each domain will have the corresponding registered legal entity, to collect the revenue.

Taboola

Out of the 144 domains at least 84 loaded the taboola tag inline html, via the homepage. This enabled us to identify some of the beneficiary shell companies and individuals, including Hong Kong and Singapore entities.

Ad-revenue collected through KYC-registered publisher accounts spread across Hong Kong and Singapore shell entities – corpa
Figure 18 - Ad-revenue collected through KYC-registered publisher accounts spread across Hong Kong and Singapore shell entities – corpa.

Victimology

Who are the victims? There’s two sides to this story: advertisers and ad-networks. Let’s start with the first. Advertisers are being defrauded because they pay to promote content and are being led to believe they’re getting their money's worth of visibility and engagement, except they’re not, it’s all bots. Advertisers can be individuals (like both you and me), small businesses (such as your local bakery and construction store), or even massive corporations. In the case of the advertisements shown in the Fuyao ad-landing pages, we have seen it all. Because the Fuyao ad-landing pages exist across more than 12 verticals (finance, lifestyle, health, education, gaming, music, …), just about anyone paying for advertising can become a victim. We are not privy to the internal algorithms used at Google Ad-Sense or Taboola that perform the ad selection on what and where to display, as these can vary substantially based on country, age, website content, web searches and other user data. What we do know, is what we have seen. From your local fireplace store, to popular online course platforms, to retail giants such as Temu.

Second victim, the ad-networks. Companies such as Google, Taboola, and others are victims too. They employ dedicated teams that create and manage complex algorithms / systems to detect bot traffic, yet in a constant cat and mouse game, cybercriminals always seek to innovate and bypass this. This is one such case, so if you're working in one of these teams and would like to obtain more insight about this threat, feel free to reach out.

Next, we break down attribution: Some key findings resulting from a long investigation linking a China based enterprise to the Fuyao operation.

The enterprise: Fengwo Group

Who is responsible? Zhejiang Fengwo IoT Technology Co., Ltd, founded in 2019, is a main subsidiary branch of Zhejiang Fengwo Holding Group Co., Ltd. Also referred to as the “Fengwo Group.”

The domain fwgcloud[.]com stands for FengwGroup Cloud, the backend infrastructure used across the Fengwo Group. This domain is not only the domain listed as the service email of multiple companies, but also the backend cloud infrastructure for the entirety of Fengwo Group. 

This website is a crucial part of the Fengwo Group operations. More interestingly though, are the services the website advertises: AI-Digital Humans.

Figure 19 - fwgcloud[.]com advertises 120,000 ‘Digital AI Humans’, under Zhejiang Fengwo IoT
Figure 19 - fwgcloud[.]com advertises 120,000 ‘Digital AI Humans’, under Zhejiang Fengwo IoT.

In fact, they boast of having over 120,000+ digital humans. Historically, when dealing with proxy services or DDOS, we sometimes see these websites undertake inconspicuous facades, so as not to  advertise their DDoS capability or botnet size. This could also be the case here. 

The TRACE: Fuyao and Fengwo

Four pieces of evidence that irrefutably connect Fengwo Group to the Fuyao operation / samples. Domain certificates, an e-learning platform, links to ad-revenue shell companies and registered patents.

The domain fwgcloud[.]com shows cross shared ssl certificate data with other domains associated with the Fuyao apps, specifically the phone spoofing mechanism.

fwgcloud[.]com also has an internal wiki platform, where in lapse some files were left public. These files directly tie to the proprietary ad-fraud Blockly system and code, actively pushed by live C2s during ad-fraud campaigns. Multiple other connections can be made between the Fuyao operation and Fengwo Group, including reused emails between ad-fraud revenue collecting shell companies and the mainland China company.

Figure 20 - Four unrelated artefacts independently point to Zhejiang Fengwo IoT
Figure 20 - Four unrelated artefacts independently point to Zhejiang Fengwo IoT.

Lastly, something I’ll just briefly highlight in this non-technical post, is the Mainland China company responsible for fwgcloud[.]com and its AI Digital humans. It holds 20 patents and applications under China National Intellectual Property Administration (CNIPA). Quickly skimming through them revealed invaluable insight. At least 6-8 of them clearly mapped one-to-one onto subsystems Bitsight TRACE researched in the Fuyao ad-fraud operation, including app code/logic, some even sharing the same internal naming. Therefore, undoubtedly attributing the Fuyao Enterprise operation to the Fengwo Group subsidiary. 

We will cover more details around infrastructure, including: C2s, IOCs, Blockly fraud modules, ad-landing websites, shell entities and Mainland China operations in our follow up technical post: Fuyao Ad-fraud as a Product. So make sure to stick around!