廉价电视盒劫持带宽搞广告欺诈
推荐指数 35.0 NO. 018 · 2026.07.31
发布2026/07/30Score179Comments80
为什么值得看
安全研究员通过接管过期域名,发现H96等廉价安卓电视盒不仅出租用户带宽,还伪装成手机在AI生成的垃圾网站上刷广告点击。这揭示了黑灰产如何将硬件倾销与广告欺诈深度耦合,形成规模化套利链条。
编辑判断
这类设备的商业模式本质是'硬件亏本卖,后端赚黑钱',和早年山寨路由器的逻辑一脉相承,但AI生成网站的加入让流量伪装成本趋近于零。
对做广告技术或风控的工程师来说,这意味着传统的设备指纹识别需要升级——这些盒子会动态切换User-Agent和IP池,单纯依赖静态规则很难拦截。
如果你在做出海广告业务或依赖程序化投放,建议重点排查来自'低端安卓设备+住宅IP'组合的异常流量,这类来源的转化率数据可能已经被严重污染。
社区反馈
负面 79 条评论
核心争论:用户知情同意与黑灰产规模化套利之间的伦理边界
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one
I wonder to what degree malice can be engineered to look like incompetence?
Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.