The proliferation of Set-Top Boxes and other uncertified Android devices in homes has opened a new front for Internet service providers. Compromised devices have begun to appear on the networks of various ISPs, operating normally from the user’s perspective while using residential connectivity in the background for malicious activities such as residential proxying, denial-of-service attacks, port scanning and generating anomalous traffic.