The devices ship backdoored before any download.

Fraud and ad-click networks get blocked from data centres, so criminal operators rent ordinary home connections to look legitimate instead.

Security firm Bitsight traced the scheme to Zhejiang Fengwo IoT, a mainland China company.

Sources: Hacker News