Providing trusted research, analysis and insight in telecom security

Subscribe to receive HardenStance reports

a
M

Subscribe to receive HardenStance reports

Cujo AI’s Res Proxy feature points to additional drivers for home router security

By Patrick Donegan, Principal Analyst, HardenStance

6 Oct 2026

By Patrick Donegan, Principal Analyst, HardenStance

Last Thursday’s announcement by Cujo AI of a feature to protect telcos and their subscribers from abuse by residential proxies is an important milestone. The solution doesn’t just identify the specific households being subjected to residential proxy abuse. It also identifies the specific device that’s infected.

When, in January, Google announced the takedown of IPIDEA it stated that the number of devices forming part of that residential proxy network ran into the millions. When Comcast’s security team looked into 6 suspicious IP addresses last year, it found that they formed part of a 750,000 strong residential proxy network. One of the important aspects of this latest switch in threat actor tactics techniques and procedures is that besides the individual householder, there are many more stakeholders with an interest in mitigating the threat from residential proxies driving malicious traffic out from home networks. Telco security operations teams have to protect all their subscribers against the risk of DDoS traffic triggering service outages and degradations. They also have their organization’s IP reputation to protect. Further afield, Internet users all over the world are threatened by this abuse of millions of home networks at scale. Many of the web scraping use cases that rely on residential proxies are illegal or at best unethical. They include the ingestion of copyrighted content by AI models and ticket pricing by scalpers or ticket touts.

Limited engagement by telco security operations

Up until now, the business case for getting device intelligence and cybersecurity software onto home routers has been driven by a householder’s willingness to pay for better protection and the ability of consumer product team in the telco to monetize that demand. It’s these consumer product teams that buy the device intelligence and home router security software from vendors like Cujo AI and competitors like Allot, Bitdefender, F-Secure and Sam Seamless Network (now part of Qualcomm). You might think telco security operations must be heavily engaged with these vendors as well but for the most part, they’re not. Some of these vendors do report some amount of engagement with security operations in a subset of telco accounts. In a few cases, some of the data that can be shared in compliance with data privacy laws is already shared with security operations as well as with the consumer product folks. But even in those cases where data is shared with security operations teams today, it’s only as a byproduct of chasing additional ARPU.

Last Friday I spoke with Steven Offerein, Vice President of Product, Device Intelligence and Protection Services, about Cujo AI’s announcement. I suggested to him that working with lead customers to develop these new residential proxy protection features must surely have required engaging some new faces in those telco organizations. The answer was encouraging. “Yes, we have engaged with new people in our customer organizations”, Steven said. “What we have been working on with this residential proxy solution has further widened the scope of stakeholders. Most obviously that’s been with security operations but also, interestingly, among customer support organizations because the solution gives them visibility to help them improve the user experience, which can be impacted by residential proxy activity, and reduce their costs.”

Lots of vendors have their eye on new router security features

I’ve been actively engaging with industry stakeholders to drive greater engagement by telco security operations teams in the home router domain for over a year. Most of Cujo AI’s competitors in router security apps are trying to drive those same conversations too.  Interestingly, so are established vendors in the Wi-Fi management and optimization space. Last month, Plume published very detailed threat research on residential proxies. Just a few days ago, Airties announced that it is building its own home router security apps for consumer and small businesses. During HardenStance‘s ‘Mass Market Router Security for ISPs’ webinar that I hosted last week, Airties CEO, Metin Taskin, stated that “security upsell to the consumer is the focus now but very soon I think we will get to a place where security is needed for the operator themselves, not just for the end user’s protection.”

From a completely different starting point, the world’s leading providers of DDoS protection solutions have also been considering extending their portfolio to the home router. In June, Nokia Deepfield stated that it has been considering the potential for deploying Genome Shield-informed ACLs in a home gateway. Netscout, the largest provider of DDoS protection solutions to telcos, hasn’t made any public comment about extending its footprint into the home. However, some among the Netscout Arbor leadership team have confirmed to HardenStance that the idea could have some potential to be interesting.

The prospect of more stakeholders converging on the home router to drive 360-degree security solutions to the abuse of home networks should certainly be welcomed. It’s nevertheless worth considering the emergence of an unhelpful headwind that has to be navigated. Like other segments of the tech sector, the home router market is suffering from a sharp and sustained spike in the cost of storage and memory. Some vendors report pressure from customers and partners to compensate for this by reducing the footprint of their software (some even report one or two delays in refreshing home router portfolios). This will make optimizing the balance between edge and cloud deployments increasingly important, something which SAM Seamless Networks expects to excel at thanks to the expertise it gets from Qualcomm, its new owner.

Operational security in the home matters

Most of today’s government and industry dialogue around protecting home networks against cyber threats revolves around banning foreign made routers; minimum cybersecurity standards for new IoT products; and taking down malicious infrastructure. Much like aerial bombardment in warfare, these efforts make an impression but they’re not decisive. The FCC ban defends American homes against foreign backdoors in new routers, but it doesn’t stop foreign hackers exploiting benign vulnerabilities in home grown products. Baseline IoT security regulations begin a process of replacing vulnerable smart home products with more secure ones, but it takes years to complete. Once malicious infrastructure has been taken down, the same threat group is often back up and running again within days, or another one is able to quickly acquire its assets.

Operational security in the home matters. It matters for the individual householder, but it matters for the telecom operator and for other stakeholders too. It’s great to see Cujo AI step up to protect telcos and their users against residential proxies. It’s great to see that there’s a rising tide of other stakeholders rising to the same challenges as well.