Executive Overview
The modern internet operates on a foundational, Faustian bargain: users receive "free" access to vast oceans of news, entertainment, and utilities in exchange for submitting to an invisible, continuous stream of behavioral monitoring. For decades, determining exactly who is profiting from this surveillance—who is hosting the malicious advertisements on trusted websites, which data brokers are harvesting mobile telemetry, and where corporate profits ultimately flow—has been a formidable challenge. While much of this infrastructure relies on semi-public files, the data has historically remained walled behind complex protocols, fragmented across exchanges, and virtually impenetrable to anyone without specialized analytic tooling.
Enter DecryptAds (decryptads.com), a powerful, free-to-use platform fundamentally shifting the power dynamic between digital consumers and the advertising technology (adtech) ecosystem. By continuously scraping, parsing, and cross-referencing public disclosures—such as ads.txt, app-ads.txt, and sellers.json files—DecryptAds bridges the gap between raw corporate disclosures and actionable intelligence. Developed by a team including Infoblox threat researcher and Chief Research Officer Zach Edwards, the platform approaches adtech through a rigorous security and privacy lens. It exposes high-risk geopolitical ties, tracks illicit cross-domain cloning, maps supply-chain integrity failures, and offers unprecedented visibility into the murky world of malvertising and artificial intelligence (AI)-generated "slop" content farms.
As privacy legislation slowly forces data brokers into the open and cybercriminals increasingly weaponize automated content generation to distribute malware, tools like DecryptAds are no longer just for industry insiders. They are vital instruments for anyone seeking to understand the vast digital apparatus tracking their every move online.
Detailed Chronology and Technical Architecture: How DecryptAds Works
To understand the magnitude of DecryptAds’ breakthrough, one must first examine the architecture of the web’s self-regulatory transparency mechanisms. Over the past decade, the Interactive Advertising Bureau (IAB) and other standards bodies introduced text files—namely ads.txt (Authorized Digital Sellers) for websites and app-ads.txt for mobile and smart TV applications—alongside JSON-based exchange registries like buyers.json and sellers.json. These files were ostensibly designed to combat ad fraud, domain spoofing, and unauthorized reselling by allowing publishers to explicitly declare which companies are authorized to sell their ad inventory.
However, these files were never designed to be evaluated in isolation. Supply-chain integrity issues rarely announce themselves neatly within a single document; instead, they manifest as broken cross-references, sudden metadata disappearances, and mismatched seller identifiers across disparate ad exchanges.

DecryptAds automates the ingestion and correlation of these massive, fragmented datasets on a continuous loop. The service constructs a holistic, relational map of the digital advertising ecosystem for millions of domains and applications. Rather than forcing a security analyst or privacy advocate to manually parse tens of thousands of lines of code across disparate servers, DecryptAds provides an interface that can trace a single seller ID from a benign-looking mobile game all the way back to sanctioned foreign financial institutions or obscure shell companies.
Mapping the Giants: The ESPN Case Study
A prime example of DecryptAds’ capabilities involves major mainstream properties. A search for the sports media monolith espn.com instantly reveals a staggering ecosystem: 143 ad partners and 19 registered data broker domains are explicitly declared within its ads.txt and app-ads.txt files.
This level of granular disclosure is increasingly coming to light due to a patchwork of emerging state-level privacy laws in the United States. Jurisdictions such as California, Oregon, Texas, and Vermont have enacted legislation mandating that entities buying or selling consumer data must formally register. When cross-referenced via DecryptAds, the results are sobering: nearly half of ESPN’s listed data brokers are actively collecting precise geolocation data from visitors who do not employ ad-blocking technologies. Furthermore, another subset of these brokers openly discloses the collection of sensitive personal information and advanced device fingerprints, illustrating how mainstream media properties function as pipelines for extensive third-party data harvesting.
Supporting Context & Metrics: Geopolitical Risks, Sanctions, and AI Slop
Beyond domestic data brokerage, DecryptAds provides critical visibility into the national origins and ultimate beneficiaries of the entities lurking inside digital advertising supply chains. The platform features an explicit "Geo-Risk" classification system, flagging adtech partners based in high-risk jurisdictions—such as Russia and China—as well as intermediary financial havens with deep political ties to both, including Cyprus and the United Arab Emirates (UAE).
The Russian Sanctions Nexus: Between Digital
A striking illustration of this geopolitical exposure involves Between Digital, an adtech firm that lists a New York corporate address but is categorized by DecryptAds as a Russian enterprise. DecryptAds’ dossier on the firm reveals that its publisher payouts and financial operations are processed through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank was heavily sanctioned by the United States government in 2022 following the Kremlin’s invasion of Ukraine.

Despite these sanctions and its clear foreign origin, Between Digital’s tentacles extend deeply into critical American digital infrastructure. A DecryptAds query targeting prominent U.S. military news publications—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveals that all of these properties authorize Between Digital to serve advertisements and track users. Additional ad partners linked to these military sites trace back to the UAE and the corporate secrecy jurisdiction of Panama. Globally, DecryptAds reports that Between Digital collects advertising data across approximately 55,000 partner websites.
Furthermore, analyzing Between Digital’s app-ads.txt footprint uncovers hundreds of domains tied to simple, web-based minigames frequently interrupted by ad placements. According to Zach Edwards, Between Digital is listed as both a publisher and a reseller on roughly two-thirds of its own portfolio. This duality—acting on both sides of the bidding equation—creates inherent conflicts of interest, enabling entities to direct ad spend toward their own infrastructure without independent oversight.
Similar patterns emerge across major consumer applications. For instance, the Opera web browser, which has been majority-owned and controlled by Chinese firm Kunlun Tech since 2016 (while maintaining operational headquarters in Oslo, Norway), exhibits a massive international ad footprint. Opera.com’s DecryptAds profile identifies 27 registered data brokers, including 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine—numbers that represent a mere 7 percent of the total adtech partners specified in its authorization files.
Malvertising, AI Slop, and H96 Streaming Sticks
The security implications of unmonitored ad networks extend far beyond passive data collection; they serve as the primary distribution vector for "malvertising"—malicious advertisements designed to deploy malware, initiate zero-click exploits, or redirect unsuspecting users to sophisticated phishing portals.
Recent investigations by cybersecurity firm Bitsight highlighted a widespread supply-chain compromise involving popular H96 TV streaming sticks. These devices were discovered covertly renting out residential internet connections to strangers while spoofing their device signatures to mimic mobile phones. In this fraudulent state, the streaming devices automatically clicked through ads hosted on vast networks of AI-generated "slop" content farms—machine-generated blogs and image galleries covering mundane topics like home improvement, recipes, and consumer electronics.

Cross-referencing these AI slop sites via DecryptAds’ Legal Dossier lookup uncovers direct structural linkages. For instance, dormant domains tied to the malicious Fengwo Group—such as medicalbeautyhub.com—share specific seller IDs (e.g., Seller ID 1674071) with seemingly unrelated gaming sites, which in turn connect to broader networks operating within Russia’s Yandex advertising system.
Edwards notes that unlike high-traffic destinations like ESPN or HuffPost, which invest heavily in security tooling to intercept malicious creatives, AI slop content farms operate with zero protective oversight. They willingly onboard the lowest-tier, highest-risk ad networks, creating a greased rail for delivering zero-click malware payloads directly to unsuspecting consumers.
Official Statements and Industry Mechanics
The opacity of the adtech ecosystem is exacerbated by industry practices designed to shield bad actors from accountability. According to Edwards, when mainstream advertising networks suspect an affiliate of generating fraudulent traffic or serving malicious ads, standard operating procedure is often to quietly excise the offender from their sellers.json files without issuing a public warning or notifying industry peers.
"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards explained to KrebsOnSecurity. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."
To counteract this information vacuum, DecryptAds incorporates a Quiet Removals Feed. This diagnostic tool aggregates and correlates historical sellers.json removals across multiple exchanges, exposing when and where specific seller domains or identifiers have been silently purged.

The Missing Piece: Supply Chain Objects (SCO)
Solving the systemic crises of malvertising and ad fraud will require a fundamental shift in transparency from the major ad platforms. Specifically, Edwards emphasizes that platforms must begin broadly sharing Supply Chain Objects (SCO)—structured data attached to server-side advertising bid requests that reveal every intermediary, seller, reseller, and final buyer involved in passing an ad impression.
Without access to the SCO, security researchers can identify that a malicious redirection or zero-click payload occurred, but they remain legally and technically blind to the exact financial conduit that purchased the impression. Encouraging the adtech industry to expose server-side supply chain objects is viewed by researchers as an essential step toward holding the true architects of digital malfeasance accountable.
Future Outlook & Consumer Defense Strategies
As automated content generation proliferates and threat actors continue to weaponize the digital advertising supply chain, transparency tools like DecryptAds are becoming indispensable for enterprise security teams, threat intelligence analysts, and privacy advocates alike. By offering automated application programming interfaces (APIs) that allow researchers to integrate adtech mapping into popular AI platforms and automated workflows, DecryptAds paves the way for a more accountable digital infrastructure.
However, systemic reform in the adtech industry will take years. In the interim, security experts agree that individual consumers must take proactive measures to protect their privacy and security.
Actionable Mitigation Strategies
- Deploy Network-Level Ad Blocking: For the most robust, scalable, and secure defense, technically inclined users can implement a hardware-based ad blocker. Deploying a low-cost Raspberry Pi running Pi-hole at the local network level acts as a DNS sinkhole, preventing advertisements and tracking requests from loading on any device—including smart TVs, IoT gadgets, and mobile phones—connected to the home network.
- Utilize Modern Browser-Based Blockers: For standard desktop and laptop browsing, open-source extensions such as uBlock Origin Lite offer exceptional, lightweight protection. iOS users can rely on utilities like Adblock Plus, while power users can augment these tools with custom blocking rules from community-maintained repositories like
easylist.to. - Exercise Extreme Caution with Mobile Apps: Mobile applications are primary vectors for intensive data harvesting and precise geolocation tracking. Whenever possible, users should bypass dedicated mobile apps and interact with web services directly through a secure browser equipped with tracking protections.
- Audit Smart TVs and IoT Devices: As demonstrated by security analyses of streaming sticks and connected displays, residential devices are frequently co-opted into proxy networks and ad-fraud rings. Consumers should audit the applications installed on their smart TVs and leverage research platforms like DecryptAds to vet the hidden data-sharing practices of the services they invite into their homes.
Ultimately, until international regulators and major advertising exchanges enforce strict provenance and mandatory data-sharing regarding supply chain objects, the burden of defense rests squarely on the shoulders of the end-user. Armed with transparency engines like DecryptAds, consumers and security professionals finally possess the intelligence required to navigate and resist the sprawling apparatus of digital surveillance.
