Unmasking the Shadows of the Ad-Tech Ecosystem: Inside DecryptAds and the Battle for Supply Chain Transparency

Share
Unmasking the Shadows of the Ad-Tech Ecosystem: Inside DecryptAds and the Battle for Supply Chain Transparency

Executive Overview

For decades, the invisible architecture of the internet has functioned as a vast, unregulated data bazaar. Every time a user loads a webpage, clicks through a mobile app, or streams content via a smart television, a silent, lightning-fast auction takes place behind the scenes. Dozens of data brokers, ad networks, and supply-side platforms scramble to harvest user metrics, deploy tracking trackers, and serve targeted advertisements. For the average consumer—and even for seasoned security professionals—identifying the precise entities responsible for this data extraction has long been a frustrating, nearly impossible task.

Much of this crucial mapping data has historically remained walled off inside proprietary corporate dashboards or obscured by complex, obfuscated supply chains. That opacity is finally beginning to shatter with the launch of DecryptAds (decryptads.com), a powerful, free public service designed to scrape, parse, and correlate ad-tech disclosure files. Co-founded by Infoblox threat researcher and Chief Research Officer Zach Edwards alongside two industry peers, DecryptAds strips away the technical veneer of the advertising ecosystem, turning fragmented text files into a cohesive, searchable intelligence platform.

By methodically cross-referencing files like ads.txt, app-ads.txt, and sellers.json, the platform sheds light on critical security blind spots. It uncovers high-risk geopolitical ties, exposes the murky mechanics behind AI-generated "slop" websites, tracks malvertising networks, and highlights the quiet removal of bad actors from legitimate ad exchanges. As cybercriminals and state-sponsored entities increasingly weaponize the digital advertising supply chain to push malware and evade detection, tools like DecryptAds provide an unprecedented window into a previously lawless frontier.


Detailed Chronology & Mechanics: How the Digital Ad Supply Chain Was Unlocked

To understand the breakthrough that DecryptAds represents, one must first examine the foundational files that govern digital advertising transparency. Over the past decade, the Interactive Advertising Bureau (IAB) introduced standardized disclosure mechanisms—namely ads.txt (Authorized Digital Sellers) and app-ads.txt—to combat domain spoofing and ad fraud. Websites and application publishers publish these public text files on their servers to explicitly declare which ad-tech vendors, exchanges, and intermediaries are authorized to buy and sell their ad inventory. Complementing these are buyers.json and sellers.json files, which map out the corporate entities participating in these transactions.

While theoretically public, these files were practically useless in isolation. They existed as millions of disparate text documents scattered across the web, containing hundreds of thousands of alphanumeric seller IDs, cross-references, and corporate aliases. Without deep analytical tooling, finding the connective tissue between a legitimate publisher and a malicious actor was like searching for a needle in a digital haystack.

Recognizing this systemic gap, Zach Edwards and his co-founders built DecryptAds to continuously scrape and ingest these declarations at scale. Rather than viewing ad-tech through a purely marketing or monetization lens, the platform approaches the ecosystem through an unvarnished security and privacy perspective.

The mechanics of the platform allow users to "pivot" across multiple data points. For instance, a researcher can start by examining a major publisher like espn.com, instantly view its 143 declared ad partners and 19 data brokers, and then trace those relationships down to individual seller IDs. If an obscure gaming app shares a seller ID with a malicious AI-generated content farm, DecryptAds maps the connection, revealing the shared infrastructure running beneath seemingly unrelated properties. By automating this cross-referencing, the platform transforms raw administrative text files into actionable threat intelligence.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Supporting Context & Metrics: Uncovering Geopolitical Risk and Data Brokering

The practical applications of DecryptAds’ analytical engine are starkly illustrated when examining prominent web properties and their downstream partnerships. Consider espn.com: a deep dive using DecryptAds reveals that its authorized supply chain includes 143 ad partners alongside 19 registered data brokers.

The inclusion of data broker data is particularly timely. Four U.S. states—California, Oregon, Texas, and Vermont—have recently enacted legislation requiring data brokers to officially register if they buy or sell consumer data originating within their borders. DecryptAds’ analysis of ESPN’s disclosure files reveals that nearly half of these listed brokers collect precise geolocation data from visitors who do not employ ad-blocking software, while others openly admit to harvesting device fingerprints and sensitive personal details.

High-Risk Jurisdictions and Geopolitical Exposure

Perhaps most alarming is DecryptAds’ "Geo Risk" feature, which flags advertising partners headquartered in adversarial nations or jurisdictions closely tied to them, such as China, Russia, Cyprus, and the United Arab Emirates (UAE).

For example, DecryptAds flags that espn.com maintains commercial relationships with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an ad-tech firm that lists a nominal New York corporate address. However, DecryptAds’ dossier unmasks its true origins as a Russian enterprise, highlighting publisher offers processed directly through Alfa Bank—Russia’s largest private commercial bank, which was placed under heavy U.S. sanctions following the 2022 invasion of Ukraine.

This exposure is far from isolated. A broader query across prominent U.S. military-focused news portals—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveals a striking operational overlap. All of these defense-adjacent publications authorize Between Digital to serve advertisements and track users, alongside additional entities based in the UAE and the corporate secrecy haven of Panama. According to platform telemetry, Between Digital’s tracking and ad infrastructure is embedded across roughly 55,000 partner websites globally.

Pivoting further into Between Digital’s app-ads.txt footprint exposes hundreds of domains dedicated to simple, ad-supported mobile web games. Edwards notes that Between Digital’s own filings list the company as both a publisher and a reseller on approximately two-thirds of its portfolio. This dual role creates an intrinsic conflict of interest, allowing the firm to play both sides of the bidding equation and potentially direct client ad spend toward its own owned-and-operated properties.

Similar patterns emerge when analyzing mainstream consumer software. The Opera web browser, which maintains its operational headquarters in Oslo, Norway, has been majority-owned by the Chinese firm Kunlun Tech since 2016. A DecryptAds profile of opera.com identifies 27 registered data brokers, including 15 ad-tech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine—though these collectively represent only seven percent of the total ad-tech partners declared in Opera’s authorization files.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Official Statements & Industry Insights: Conflict of Interest and "Quiet Removals"

To grasp why these systemic risks persist, one must look at how the ad-tech industry polices itself—or rather, fails to do so. In an interview with security journalist Brian Krebs, Zach Edwards underscored the lack of accountability that has plagued the ecosystem for over a decade.

"The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files," Edwards explained. Supply-chain integrity issues, he noted, rarely manifest cleanly in a single file; instead, they appear as broken cross-references, cloned declaration sets across completely unrelated domains, and discrepancies between authorized seller lists and actual bid logs.

Compounding this opacity is the industry practice of "quiet removals." When major ad exchanges suspect an affiliate of engaging in ad fraud, bot-driven click manipulation, or serving malicious payloads, they frequently purge the offender from their sellers.json file silently. They issue no public warning, notify no external security authorities, and leave no public audit trail explaining why the vendor was cut.

This administrative silence allows shady ad-tech entities to simply hop to another exchange or reincorporate under a new alias, continuing their operations virtually unimpeded. To bridge this visibility gap, DecryptAds introduced a dedicated Quiet Removals Feed, which aggregates and correlates sellers.json removals across multiple ad exchanges. By tracking when a seller domain abruptly vanishes from multiple platforms simultaneously, security researchers can map out coordinated crackdowns on bad actors that the industry prefers to sweep under the rug.


Malvertising, AI "Slop," and the Threat Vector

The weaponization of programmatic advertising reaches its zenith at the intersection of malvertising and the modern explosion of AI-generated content farms, colloquially known as "AI slop."

Malvertising—the practice of injecting malicious code into legitimate ad networks to distribute malware or redirect unsuspecting users to sophisticated phishing pages—traditionally occurred across a wide spectrum of websites. However, high-traffic mainstream destinations like major news outlets or enterprise portals invest heavily in real-time ad verification, security scrubbing, and reputation management to filter out malicious creative assets.

AI-generated content farms, conversely, operate entirely on cheap volume. Populated by machine-generated blog posts, synthetic imagery, and generic topics ranging from home improvement to automotive care, these low-quality sites have zero budget for brand-safety protection.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"None of these slop AI content farms are paying for that kind of protection," Edwards noted. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search."

This dynamic was underscored by recent investigative findings from security firm Bitsight, which exposed a popular line of residential TV streaming sticks known as H96. These devices were found to quietly rent out users’ internet connections as residential proxies to strangers. When idle, the hardware spoofed mobile device user-agents to invisibly click on ads hosted across networks of AI-generated content farms operated by entities like the Chinese Fengwo Group.

A DecryptAds "Legal Dossier" search on defunct Fengwo domains—such as medicalbeautyhub.com—reveals shared seller IDs (1674071) linking directly to low-quality gaming sites and vast webs of Russian Yandex ad network inventory.

Edwards stresses that mitigating these persistent threats requires a fundamental shift in how ad networks handle data transparency. Specifically, major platforms must begin broadly sharing Supply Chain Objects (SCOs). Embedded within server-side bid requests, an SCO outlines every single intermediary, reseller, and ultimate buyer involved in passing an ad impression. Without access to these server-side logs, security teams can witness a malicious zero-click redirection or a malware payload deployment, but remain entirely incapable of identifying the ultimate financial beneficiary who purchased the impression.


Future Outlook & Consumer Defense Strategies

As DecryptAds rolls out features like automated APIs—allowing researchers to feed ad-tech topology directly into large language models and analytical pipelines—the paradigm of digital privacy is shifting. No longer is ad-tech transparency the exclusive domain of programmatic marketing executives; it is now an essential frontier of national security, corporate threat intelligence, and consumer defense.

However, waiting for regulatory bodies or advertising consortiums to clean up the supply chain is a losing game. For the individual user, the realities uncovered by platforms like DecryptAds point to one inescapable conclusion: aggressive, multi-layered ad blocking is no longer optional.

Practical Steps for Complete Mitigation

  1. Browser-Level Ad Blocking:

    Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
    • For desktop and laptop users utilizing mainstream browsers, open-source extensions like uBlock Origin Lite offer robust, resource-efficient protection against trackers and malicious domains.
    • On mobile operating systems like Android, Firefox paired with uBlock Origin provides comprehensive blocking. For Apple users on iPhones and iPads, Adblock Plus serves as a viable alternative. Advanced users can subscribe to dynamic blocklists maintained by communities like easylist.to.
    • While script-blockers like NoScript offer extreme granularity by disabling unauthorized JavaScript, they require constant manual maintenance and may break modern web applications for casual users.
  2. Network-Level Defense (Pi-hole):

    • Technically inclined users can implement a hardware-based DNS sinkhole using a low-cost Raspberry Pi running Pi-hole. Configured at the local router level, a Pi-hole intercepts DNS requests for known ad-tech domains and data brokers, blocking telemetry and advertisements across every connected device on a local network—including IoT appliances—before they ever load.
  3. Treating Mobile Apps with Extreme Caution:

    • Many digital services aggressively push users toward dedicated mobile apps under the guise of an "optimized user experience." In reality, mobile apps allow corporations to bypass browser protections, harvest granular device telemetry, track physical locations, and quietly enroll consumer data into large language model training pipelines. Whenever possible, users should interact with services strictly through a secured web browser rather than installing proprietary native applications—and exercise extreme vetting regarding the smart TV apps and mobile utilities they permit onto their hardware.

By democratizing access to data that was once locked away in corporate silos, tools like DecryptAds empower everyday users and security researchers alike to shine a bright light into the darkest corners of the digital advertising machine.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *