> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)
Does having TLS everywhere make this much harder?
Until DoH and ECH are commonplace, DNS lookups and SNI probably leak enough for statistical analysis.
DNS and SNI are usually not encrypted.
Not sure how it would? Because the bad actors are remotely instructing infected computers/devices to make HTTP/TLS requests for them, so they appear totally normal to the other side.