GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

That $30 Streaming Box Might Be Moonlighting as an Ad Fraud Bot

New research shows many no-name TV streaming devices don't just hijack your bandwidth—they disguise themselves as phones to click fake ads across an AI-generated web of fraud sites.

For years, security researchers have warned that ultra-cheap Android-based streaming boxes—the kind promising every movie and channel imaginable for a single upfront payment—often come loaded with malware that quietly turns your home internet connection into a proxy for hire, letting strangers route their traffic through your network without your knowledge.

A new investigation takes that warning a step further. Researchers found that many of these devices are also being used to impersonate mobile phone browsers, automatically visiting and clicking on ads embedded in networks of AI-generated websites built specifically to look legitimate to ad platforms. The scheme appears designed to siphon money from advertisers and online merchants who pay for clicks and traffic that were never generated by real human users.

The result is a two-pronged fraud operation baked directly into hardware sold openly on major online marketplaces: your streaming box becomes both a bandwidth-for-rent proxy and a bot farm faking mobile engagement, all while you're none the wiser because the box still plays your shows just fine.

Why it matters: This isn't just an abstract fraud problem for advertisers to absorb—compromised devices sitting on home networks can mask criminal traffic behind your IP address, potentially drawing unwanted attention from ISPs or law enforcement. If you're shopping for a streaming device, sticking to major brands (Roku, Google, Amazon, Apple) with locked-down app ecosystems is a lot cheaper than dealing with the fallout of a botnet living in your living room.

Sources: Krebs on Security