🛡 CIBERCRIMEN 🛡

Lee esto antes de comprar ese dispositivo de streaming para TV.

🛡CyberObservatorio
Lee esto antes de comprar ese dispositivo de streaming para TV.
Idioma

Lee esto antes de comprar ese dispositivo de streaming para TV.

Fuente: Krebs on Security

Durante años, los expertos en ciberseguridad han estado alertando sobre los riesgos asociados al uso de cajas de televisión genéricas que prometen streaming de contenido ilimitado a cambio de un único pago. Estas advertencias se centran en que, en la mayoría de los casos, estos dispositivos alquilan de manera clandestina la conexión a Internet del usuario a extraños. Sin embargo, un análisis innovador ha revelado que estos dispositivos también se hacen pasar de forma rutinaria por teléfonos móviles que hacen clic en anuncios en sitios web generados por inteligencia artificial, en el marco de una operación amplia destinada a defraudar a comerciantes y redes publicitarias en línea.

Pedro Faléis, un investigador de amenazas de la firma de seguridad Bitsight, consiguió adentrarse en esta vasta y compleja red de fraude publicitario al registrar un nombre de dominio caducado que se utilizaba para coordinar clics fraudulentos en anuncios relacionados con una marca de dispositivos de streaming muy popular conocida como H96.

Los dispositivos de streaming H96 actualmente están disponibles para la venta en plataformas como Amazon, lo que pone de relieve su accesibilidad. Falé explicó que el dominio que logró capturar había sido previamente utilizado para la telemetría, recopilando de manera periódica información completa sobre el hardware y una lista exhaustiva de las aplicaciones instaladas en decenas de miles de sticks de streaming H96 conectados a televisores en todo el mundo. Sin embargo, al analizar el tráfico dirigido a dicho dominio, descubrió que casi todos los dispositivos de televisión que transmitían datos afirmaban ser modelos de teléfonos móviles de diversos fabricantes, como Samsung, Vivo, Huawei y Xiaomi.

Imagen del articulo

"Nos dimos cuenta de que algo no cuadraba," afirmó Falé. "Múltiples dispositivos que informaban a este backdoor de Android TV Box se identificaban como 'teléfonos'."

El investigador observó que todos los dispositivos reportaban tener instaladas las mismas dos aplicaciones, desarrolladas por una empresa llamada Zhejiang Fengwo IoT Technology Ltd, una entidad fundada en 2019 en China continental que opera un portafolio de publicación de anuncios bajo el nombre de Fengwo Group. Una investigación más profunda sobre el Fengwo Group reveló que ha registrado múltiples patentes que coinciden con el funcionamiento interno de estas aplicaciones.

"Bitsight TRACE identificó varias identidades 'legales' en Hong Kong, Singapur y de una sola persona que se utilizaban para la recolección de monetización, y rastreó la operación hasta una empresa de China continental conocida como Zhejiang Fengwo IoT Technology Co., Ltd, que opera bajo el Fengwo Group," escribió Falé en un informe publicado hoy sobre sus hallazgos.

Imagen del articulo

El análisis de estas aplicaciones demuestra que ayudan a coordinar una red de fraude publicitario que utiliza los dispositivos H96 como fuente de tráfico cautivo, generando clics en anuncios en sitios web creados por inteligencia artificial operados por el Fengwo Group. Bitsight descubrió que estos sitios web contienen artículos de noticias y gráficos generados por máquinas en una variedad de categorías, que incluyen finanzas, salud, educación, videojuegos, música y blogs de comida. Sin embargo, también observaron que ninguno de estos sitios mostraba anuncios a menos que el dispositivo que visitara la página coincidiera con el perfil móvil suplantado de los dispositivos H96.

El dominio del Fengwo Group, fwgcloud[.]com, afirma que la compañía está "redefiniendo los límites de la interacción humano-AI" y que ha creado más de 120,000 "humanos digitales AI" disponibles para alquilar, abarcando desde compañía emocional hasta servicio al cliente 24/7 y diseño creativo.

Falé indicó que el dominio del Fengwo Group compartía datos de su certificado SSL con otros dominios asociados a las aplicaciones encontradas en los dispositivos H96, específicamente el mecanismo de suplantación de teléfonos. Destacó que el dominio también cuenta con una plataforma wiki interna que vincula directamente al Fengwo Group con una implementación propietaria de un lenguaje de programación visual creado por Google llamado Blockly, que fue diseñado originalmente para ayudar a los niños a aprender a escribir software.

Imagen del articulo

Según Bitsight, los empleados del Fengwo Group utilizan Blockly para construir estos sitios web fraudulentos, permitiendo a operadores poco cualificados unir bloques de código en su editor de Blockly, sin necesidad de entender el funcionamiento de los bloques de código subyacentes.

"Un operador puede arrastrar bloques juntos en su editor de Blockly para definir cada rutina de fraude, dada una tarea específica," señala el informe de Bitsight. "Una vez que la rutina se guarda, se exporta como JavaScript y se sube a los buckets S3. Un operador no necesita tener un gran entendimiento de las complejidades técnicas, ya que todo está dispuesto para facilitar su uso."

Bitsight incluso encontró a uno de los desarrolladores de aplicaciones del Fengwo Group mencionando exactamente estas ventajas, indicando que "solo se necesita un número reducido de desarrolladores altamente cualificados para construir las imágenes de unidad de ejecución de plantillas," y que "los desarrolladores que crean unidades de ejecución a partir de esas plantillas tienen requisitos técnicos significativamente más bajos, lo que reduce considerablemente los costos operativos de la empresa."

Imagen del articulo

Falé comentó que si un stick de streaming H96 es seleccionado para una tarea específica de fraude, se le enviará el módulo Blockly apropiado en función de la tarea deseada, que puede incluir lanzar silenciosamente un navegador web, visitar sitios, navegar por páginas, gestionar pestañas y hacer clic en anuncios.

Para asegurar que las cajas de televisión que se hacen pasar por teléfonos móviles puedan hacer clic de manera confiable en los anuncios mostrados en los sitios web generados por inteligencia artificial, el Fengwo Group "fusiona tres sistemas de visión y razonamiento en una única interfaz," permitiendo que los bots identifiquen correctamente un anuncio en la página web y naveguen por el sitio de forma similar a como lo haría un ser humano, según observó el informe de Bitsight.

Bitsight concluyó que los dispositivos H96 estaban retransmitiendo tráfico proxy residencial o participando en fraude publicitario, pero nunca ambas cosas al mismo tiempo. De hecho, llegaron a la conclusión de que cuando estas cajas de televisión detectan una señal HDMI de un televisor conectado —indicando que el usuario tiene la intención de transmitir contenido de video—, el dispositivo suele funcionar como un proxy residencial. Cuando el televisor está apagado, vuelve a estar a la espera de trabajos de fraude publicitario.

Falé expresó su creencia de que las cajas de televisión están configuradas de esta manera porque sus actividades de fraude publicitario son mucho más intensivas en recursos y podrían interferir con el propósito declarado del dispositivo: transmitir contenido de video a través de Internet.

A pesar de las reiteradas advertencias del FBI y de líderes en la industria de la ciberseguridad sobre los riesgos de seguridad y privacidad asociados al uso de dispositivos de streaming, grandes proveedores de comercio electrónico como Amazon, Best Buy y Newegg continúan ofreciendo a la venta cientos de modelos y marcas que integran versiones no oficiales del sistema operativo Android de Google. Estos dispositivos son frecuentemente promocionados, a través de influenciadores en línea, como una solución para acceder a una amplia variedad de servicios de streaming y transmisiones en vivo sin necesidad de suscripción.

Además de involucrar a los dispositivos de televisión de los usuarios en redes de fraude publicitario, estos dispositivos de streaming de marcas no reconocidas vienen, casi sin excepción, con software de proxy residencial preinstalado. Este tipo de software permite alquilar la dirección IP del usuario a clientes anónimos que pueden incluir desde empresas agresivas de recopilación de contenido hasta reventa de entradas y cibercriminales manifiestos.

Es importante señalar que estos dispositivos genéricos, que suelen ser muy baratos, son inherentemente inseguros por defecto y carecen de cualquier tipo de autenticación. La instalación de uno de estos dispositivos en una red doméstica o de oficina puede facilitar aún más actos maliciosos. En enero, el servicio de seguimiento de proxies Synthient documentó cómo múltiples botnets habían esclavizado rápidamente millones de TV boxes mediante un complejo entrelazado de vulnerabilidades de seguridad tanto en el software de proxy residencial como en los propios dispositivos de streaming.

La firma de análisis Bitsight informó que había rastreado aproximadamente 38,000 TV boxes a nivel global que se conectaban al dominio caducado del Fengwo Group. Basándose en esa cifra, el informe estima que esta red de fraude publicitario genera ingresos cercanos a los 50,000 dólares diarios, sin contar los ingresos substanciales provenientes de la actividad de proxy residencial. Sin embargo, Falé, uno de los analistas, subrayó que estas estimaciones son altamente conservadoras y se basan en la telemetría de solo uno de los dominios centrales (aunque más antiguos) del Fengwo Group.

En cuanto a la afirmación del Fengwo Group de contar con 120,000 "humanos digitales" a su disposición, el informe de Bitsight sugiere que podría ser simplemente una estrategia de marketing ingeniosa y/o un intento de evitar despertar sospechas sobre las operaciones de la empresa. “Históricamente, al tratar con servicios de proxy o DDoS, a veces observamos que estos sitios adoptan fachadas discretas para no publicitar su capacidad de DDoS o el tamaño de su botnet,” escribió Falé en el informe. “Este podría ser también el caso aquí.”

Si el Fengwo Group realmente cuenta con decenas de miles de "humanos de IA" a su disposición, no parece haber dedicado ninguno de ellos a gestionar consultas a través de su propio sitio web. KrebsOnSecurity intentó contactar al Fengwo Group enviando un correo electrónico a la dirección de contacto que aparece en la página principal de la empresa, pero la solicitud fue devuelta con el mensaje: “Su mensaje no pudo ser entregado a postmaster@fwgcloud[.]com. Su bandeja de entrada está llena, o está recibiendo demasiados correos en este momento.”

Como muestra el análisis de Bitsight, en el ámbito de las TV boxes y dispositivos de streaming, es recomendable optar por marcas reconocidas de fabricantes de confianza y, además, ser selectivo y cauteloso con las aplicaciones que se decidan instalar en el dispositivo, ya que muchas de ellas también pueden incluir software de proxy residencial. Google ha indicado que los consumidores pueden verificar si un dispositivo está construido con el sistema operativo oficial Android TV y cuenta con la certificación Play Protect siguiendo ciertas instrucciones.

Adicionalmente, Synthient mantiene una lista actualizada de dispositivos IoT que se ha conocido que son enviados a los consumidores con software de proxy residencial y otras aplicaciones maliciosas preinstaladas. Los lectores más observadores notarán que la lista de Synthient incluye otros dispositivos IoT además de los sticks y cajas de streaming: como ha advertido el FBI, el software de proxy residencial también ha sido hallado en otros populares dispositivos IoT de marcas aleatorias, particularmente en marcos digitales para fotos.

Read This Before You Buy That TV Streaming Stick

Source: Krebs on Security

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro Faléis a threat researcher with the security firmBitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known asH96. An H96 TV streaming device currently advertised for sale on Amazon. Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. “We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'” Image: Bitsight. The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company calledZhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the nameFengwo Group. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps. “Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Faléwrotein a report released today about their findings. Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group. Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices. The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design. The homepage for fwgcloud dot com. Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language calledBlockly, which was originally designed to help kids learn how to write software. According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work. The Blockly homepage. “An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsight’s report. “Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.” Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that “only a small number of highly-skilled developers are needed to build the template execution-unit images,” and that “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.” Falé said if a user’s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads. To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group “fuses three vision and reasoning systems into a single interface,” allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed. Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight. Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs. Falé said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device’s stated purpose — streaming video content over the Internet. Despite repeatedwarnings from the FBIand security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription. Image: fbi.gov. In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come withresidential proxysoftware pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals. What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking serviceSynthientdocumented how multiple botnets hadrapidly enslaved millions of TV boxesusing a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves. Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain, and based on that number the report estimates this ad fraud network brings in revenues of close to $50,000 a day (not counting substantial revenue from the residential proxy side of the business). However, Falé emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group’s core (but older) domains. As for the Fengwo Group’s claim to have 120,000 “digital humans” at their disposal, Bitsight’s report concludes it could be just a clever marketing scheme and/or a way to avoid drawing suspicion to the company’s operations. “Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size,” Falé wrote in the report. “This could also be the case here.” If the Fengwo Group truly does have tens of thousands of “AI humans” at its beck and call, it does not appear to have dedicated any of them to fielding inquiries from its own website. KrebsOnSecurity sought comment from the Fengwo Group by emailing the contact address listed on the company’s homepage, but the request bounced back with the reply, “Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now.” As Bitsight’s analysis shows, when it comes to TV boxes and streaming sticks, it’s best to stick to name brands from reputable manufacturers, and then to be sparing and careful with any apps you choose to install on the device — asmany of those can bundle residential proxy software as well. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by followingthese instructions. Additionally, Synthient maintainsa running list of IoT devicesthat have been known to ship to consumers with residential proxy software and other malicious apps pre-installed. Careful readers will notice Synthient’s list includes other IoT devices apart from streaming sticks and boxes: As the FBI has warned, residential proxy software has also been found in other popular consumer IoT devices from random brands, particularly digital photo frames.

Lee esto antes de comprar ese dispositivo de streaming para TV. | Ciberseguridad - NarcoObservatorio