Read this before you buy that TV streaming stick
Read this before you buy that TV streaming stick
在购买电视流媒体棒之前,请先阅读本文
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. 多年来,安全专家一直对使用那些承诺“一次付费即可无限观看流媒体内容”的通用电视盒所带来的风险发出警告,并指出这些设备会秘密地将用户的互联网连接出租给陌生人。但一项开创性的新分析发现,这些设备还会经常伪装成手机,在人工智能生成的网站上点击广告,作为其欺诈在线商家和广告网络的大规模行动的一部分。
Pedro Falé is a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96. Pedro Falé 是安全公司 Bitsight 的一名威胁研究员。Falé 告诉 KrebsOnSecurity,他通过注册一个已过期的域名,成功窥探到了一个庞大且复杂的广告欺诈网络内部。该域名此前被用于协调一种名为 H96 的热门流媒体设备上的虚假广告点击。
Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. Falé 表示,他所获取的域名此前用于遥测,定期从全球各地连接到电视上的数万个 H96 流媒体棒中收集完整的硬件信息和已安装应用程序列表。但在检查传输到该域名的流量时,他发现几乎所有传输数据的电视盒都声称自己是来自三星、Vivo、华为和小米等不同制造商的手机型号。
“We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’” “我们注意到情况非常不对劲,”Falé 说,“向这个工厂预留的安卓电视盒后门报告的多个设备竟然是‘手机’。”
The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name Fengwo Group. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps. 研究人员发现,所有设备都报告安装了相同的两个应用程序,而这些应用程序是由一家名为浙江丰沃物联网科技有限公司(Zhejiang Fengwo IoT Technology Ltd)的公司开发的。该公司成立于 2019 年,在中国大陆运营,以“丰沃集团”(Fengwo Group)的名义经营广告发布业务。对丰沃集团的进一步调查显示,该公司已注册多项专利,与这些应用程序的内部运作机制相吻合。
“Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Falé wrote in a report released today about their findings. “Bitsight TRACE 识别出几个用于收取收益的香港、新加坡及个人‘法律’空壳身份,并将该行动追溯到一家名为浙江丰沃物联网科技有限公司的中国大陆公司,该公司在丰沃集团旗下运营,”Falé 在今天发布的一份关于其调查结果的报告中写道。
Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group. Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices. Falé 表示,对这些应用程序的分析显示,它们协助协调了一个广告欺诈网络,利用这些 H96 设备作为受控流量来源,点击由丰沃集团运营的人工智能生成网站上的广告。Bitsight 发现,这些网站包含涵盖金融、健康、教育、游戏、音乐和美食博客等多个类别的机器生成新闻文章和图片。但他们也发现,除非访问页面的设备与这些 H96 设备伪造的移动端配置文件相匹配,否则这些网站不会显示任何广告。
AI DIGITAL HUMANS
人工智能数字人
The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design. 丰沃集团的域名 fwgcloud[.]com 声称该公司正在“重新定义人机交互的边界”,并已创建了超过 12 万个“人工智能数字人”,可供租赁用于从情感陪伴到 24/7 客户服务以及创意设计等各种用途。
Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software. Falé 表示,丰沃集团的域名与 H96 设备上发现的应用程序(特别是手机伪装机制)相关的其他域名共享了 SSL 证书数据。他指出,该域名还有一个内部维基平台,直接将丰沃集团与谷歌开发的名为 Blockly 的可视化编程语言的专有实现联系起来,该语言最初旨在帮助儿童学习编写软件。
According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work. 据 Bitsight 称,丰沃集团的员工使用 Blockly 构建虚假网站,允许技术水平较低的操作员在 Blockly 编辑器中拖拽代码块,而无需了解底层代码块的功能或工作原理。
“An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsight’s report. “Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.” “操作员可以在 Blockly 编辑器中拖拽代码块,根据任务类型定义每个欺诈流程,”Bitsight 的报告写道,“一旦流程保存,它就会被导出为 JavaScript 并上传到 S3 存储桶中。操作员不需要深入了解底层技术细节,因为一切都已设置好,方便使用。”
Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that “only a small number of highly-skilled developers are needed to build the template execution-unit images,” and that “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.” Bitsight 甚至发现丰沃集团的一名应用程序开发人员明确提到了这些优势,该开发人员指出,“只需要少数高技能开发人员来构建模板执行单元镜像”,并且“从这些模板创建执行单元的开发人员技术要求显著降低,大大降低了公司的运营成本。”
Falé said if a user’s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads. Falé 表示,如果用户的 H96 流媒体棒被选中执行特定的欺诈任务,它将根据所需任务被推送相应的 Blockly 模块,其中包括静默启动网页浏览器、访问网站、浏览页面、管理标签页以及点击广告。
To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group “fuses three vision and reasoning systems into a single interface,” allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed. Bitsight 的报告指出,为了确保伪装成手机的电视盒能够可靠地点击人工智能生成网站上显示的广告,丰沃集团“将三个视觉和推理系统融合到一个界面中”,使机器人能够像人类一样准确识别网页上的广告并浏览网站。
TV ON? PROXY. TV OFF? AD FRAUD
电视开着?代理。电视关了?广告欺诈。
Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs. Bitsight 发现,H96 设备要么在转发住宅代理流量,要么在参与广告欺诈,但从不同时进行。事实上,他们得出的结论是,当这些电视盒检测到来自连接电视的 HDMI 信号(表明用户打算观看流媒体内容)时,该盒子通常作为住宅代理运行。当电视关闭时,它会切换回等待广告欺诈任务的状态。
Falé said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device’s stated purpose — streaming video content over the Internet. Falé 表示,他认为电视盒之所以这样设置,是因为其广告欺诈活动对资源的需求要大得多,可能会干扰设备的主要用途——通过互联网播放流媒体视频。