If you've shopped for a streaming stick lately, you've seen them: generic Android TV boxes with names like H96, T95, or X96, selling for a third of what a Roku or Chromecast costs, often with specs that sound implausibly good for the price. It's worth pausing on that gap before you buy, because researchers have recently shown exactly how some of these devices make up the difference — and it isn't through thinner profit margins.

Security firm Bitsight investigated one such device family, the H96, after researcher Pedro Falé registered an expired domain that the boxes were still phoning home to. What he found, as reported by Krebs on Security, was a large ad-fraud network: the devices were secretly spoofing themselves as different phones entirely — falsely identifying as Samsung, Vivo, Huawei, and Xiaomi handsets — and using that fake identity to click ads on AI-generated websites. The effect is to defraud advertisers and merchants who pay for ad impressions and clicks that were never made by a real person on a real phone. That's on top of an already-known risk with this category of device: some have been used to quietly rent out the owner's home internet connection to third parties, turning your residential IP address into a proxy that strangers route their own traffic through — traffic you have no visibility into and no ability to vet.

Why the cheap ones, specifically

The economics explain the behavior. A legitimate Android TV device — a Chromecast, an Nvidia Shield, an official Google TV or Fire TV box — is priced to make money on the hardware, the app store, or a subscription ecosystem, and it goes through a manufacturer's certification process before it ships. A no-name box selling for a fraction of that price, with no recognizable company standing behind it, has to make its margin somewhere else. If the sale price doesn't plausibly cover manufacturing, shipping, and a profit, something else is being monetized after the sale — and your network bandwidth and device identity are the obvious candidates, because they're both invisible to you and valuable to ad-fraud and proxy-rental operators.

What to check before you buy

  • Look for a real, accountable manufacturer. Google TV, Roku, Amazon Fire TV, Nvidia Shield, and Chromecast devices are tied to a company with a certification process and a reputation to lose. A box sold only under a generic model number (H96, T95, MXQ, X96, and similar) through third-party marketplace listings has neither.
  • Check for Google Play Protect certification. Google maintains a list of Android devices that have passed its Play Protect compatibility and security testing — you can search a model number before buying. An uncertified device hasn't been vetted at all, which is a meaningful gap for something that stays connected to your network 24/7.
  • Read reviews for the right complaints. Before researchers catch a device doing something malicious, owners often notice side effects first: unexplained heat, a device that never seems to sleep, or unusually high data usage for something that's "just streaming." Search the exact model number plus words like "data usage," "always on," or "proxy" before you buy, not after.

What to check if you already own one

  • Look at your router's device list overnight. Most home routers show bandwidth per connected device. Check what the streaming box is doing at 3 a.m. when nobody's watching anything. Steady upload traffic, or traffic at all, from a device that should be idle is a red flag worth investigating.
  • Watch what it's talking to. If your router supports connection logs, or you run something like Pi-hole or a similar DNS-logging tool, look for the box repeatedly contacting unfamiliar or rotating domains rather than the handful of streaming-service endpoints you'd expect.
  • Put it on a separate network. Most home routers support a guest network or, on better hardware, a VLAN. Isolating streaming boxes and other IoT devices from your phones, laptops, and file shares limits the damage if one of them turns out to be misbehaving — it can't proxy traffic through devices it can't see, and a compromise on it doesn't hand over the rest of your network.

If you find something wrong

There's no reliable way to "clean" a device whose firmware is doing this by design — a factory reset won't remove behavior baked into the firmware image itself, and there's usually no legitimate update channel to fix it, since the manufacturer built it this way on purpose. The realistic options are to unplug it and stop using it, or replace it with a certified device from an accountable manufacturer. If it's been sitting on your main network for a while, it's also worth changing your Wi-Fi password afterward, on the chance it had opportunities to observe or interact with other devices on the same network.

The broader habit worth keeping: treat an implausibly low price on any always-connected device as a question, not a bargain — because if you can't tell what's paying for the discount, there's a decent chance it's you.

Source: Bitsight research on H96 Android TV boxes, reported by Krebs on Security.