Unmasking the Adtech Underground: How DecryptAds Exposes Global Tracking, Geopolitical Risk, and Malvertising

Share
Unmasking the Adtech Underground: How DecryptAds Exposes Global Tracking, Geopolitical Risk, and Malvertising

Executive Overview

For years, the multi-billion-dollar advertising technology (adtech) ecosystem has operated behind a dense fog of technical obfuscation. While the mechanism for displaying digital advertisements on websites and mobile applications relies on semi-public disclosure files, this data has traditionally remained siloed, fragmented, and virtually indecipherable to the average internet user. Large ad platforms and data brokers have long profited from this lack of transparency, quietly harvesting precise user data, facilitating cross-device tracking, and occasionally acting as conduits for sophisticated malvertising campaigns.

Enter DecryptAds (decryptads.com), a powerful, free, and newly launched service designed to demystify the adtech supply chain. By continuously scraping, indexing, and cross-referencing public declarations—including ads.txt, app-ads.txt, and sellers.json files—DecryptAds translates raw, unstructured data into actionable intelligence. Spearheaded by chief research officer Zach Edwards alongside a team of cybersecurity veterans, the platform approaches adtech through an uncompromising security lens.

This investigative report examines how DecryptAds exposes hidden data brokers, flags high-risk ad networks tied to sanctioned nations, uncovers the mechanics of AI-generated "slop" websites, and provides actionable countermeasures for individuals looking to reclaim their digital privacy.


Detailed Chronology: The Evolution of Adtech Opacity and the Birth of DecryptAds

The Fragmented Origins of Ad Disclosure

To understand why DecryptAds is a watershed development in cybersecurity, one must examine how the modern ad ecosystem attempted—and largely failed—to police itself. In the mid-2010s, digital publishing was plagued by domain spoofing and ad fraud, where malicious actors pretended to represent legitimate websites to siphon ad revenue. To combat this, the Interactive Advertising Bureau (IAB) introduced ads.txt (Authorized Digital Sellers) in 2017, followed by app-ads.txt for mobile and smart TV applications, and sellers.json to map out the intermediary buyers and sellers of ad inventory.

While these files were technically public, they were never designed with user privacy or threat intelligence in mind. They were created as transactional ledgers for programmatic advertisers. Consequently, a typical major publisher might list thousands of authorized entities across multiple files. Analyzing a single file in isolation reveals almost nothing about the underlying supply chain integrity.

The Conceptualization of DecryptAds

Recognizing a severe blind spot in the cybersecurity landscape, Zach Edwards—a threat researcher at security firm Infoblox—teamed up with two other founders to build a system that could aggregate and correlate these disjointed files. Their goal was simple yet ambitious: build a centralized engine that treats adtech supply chains as interconnected networks rather than isolated text documents.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Launched recently, DecryptAds automates the collection of these transparency files across millions of domains and apps. By cross-referencing seller IDs, domain aliases, and bidding logs, the platform allows security researchers, journalists, and privacy advocates to trace the lineage of an ad impression from a publisher all the way to its ultimate financial beneficiary.


Supporting Context & Metrics: Unpacking the Data

The analytical capabilities of DecryptAds reveal startling insights into how major digital properties manage their ad partnerships and data-sharing agreements.

Case Study: ESPN’s Complex Ecosystem

A search for the high-traffic sports network espn.com on DecryptAds yields a striking revelation: its ads.txt and app-ads.txt files declare partnerships with 143 ad partners and 19 registered data broker domains.

This level of disclosure has been slowly forced into the open due to recent legislative milestones. Four U.S. states—California, Oregon, Texas, and Vermont—have enacted laws requiring data brokers to officially register if they buy or sell consumer data originating from within their borders. DecryptAds’ analysis of ESPN’s ecosystem indicates that nearly half of these listed data brokers are actively collecting precise geolocation data from visitors who do not employ ad blockers. Furthermore, three of these entities openly disclose that they harvest device fingerprints and sensitive personal attributes.

Geopolitical Risk and Sanctioned Entities

Beyond data collection, DecryptAds introduces a critical "Geo-Risk" metric, flagging adtech partners operating out of adversarial nations—such as Russia and China—or jurisdictions with deep financial and political ties to them, including Cyprus and the United Arab Emirates (UAE).

For example, DecryptAds flags that espn.com collaborates with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a corporate address in New York. However, DecryptAds’ dossier reveals that Between Digital is fundamentally a Russian enterprise whose publisher financial transactions are routed through Alfa Bank—Russia’s largest private commercial bank, which was placed under strict U.S. sanctions following the 2022 invasion of Ukraine.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The reach of such entities extends deeply into sensitive infrastructure. A DecryptAds search across major U.S. military news properties—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveals that all of them permit Between Digital to serve advertisements and track users. Additional partners include firms based in the UAE and the corporate secrecy haven of Panama. According to DecryptAds tracking metrics, Between Digital currently collects advertising and user data across approximately 55,000 partner websites.

Pivoting further into Between Digital’s app-ads.txt files exposes hundreds of simple, web-based mobile games whose user experiences are repeatedly interrupted by programmatic ads. Edwards points out that Between Digital is listed as both a publisher and a reseller on roughly two-thirds of its portfolio. This dual-role dynamic creates inherent conflicts of interest, allowing firms to direct client ad spend toward their own properties with virtually zero external oversight.

The Opera Browser Footprint

A similar pattern emerges when examining the popular Opera web browser. While Opera’s operational headquarters remain in Oslo, Norway, the browser has been majority-owned and controlled by the Chinese firm Kunlun Tech since 2016.

DecryptAds’ profile for opera.com identifies 27 registered data brokers collecting user information. This breakdown includes 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. Notably, DecryptAds highlights that these flagged entities represent a mere 7 percent of the total adtech partners specified in Opera’s comprehensive transparency declarations.


Official Statements and Analytical Frameworks

The Danger of "Quiet Removals"

One of the most innovative features integrated into DecryptAds is its Quiet Removals Feed. In the standard adtech lifecycle, when an ad network suspects that a partner is engaging in fraudulent click-generation or distributing malicious payloads, the network will frequently purge the offender from its sellers.json file silently, without issuing a public warning or notifying other exchanges.

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Zach Edwards explained to KrebsOnSecurity. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

By aggregating these changes across multiple exchanges, DecryptAds bridges this visibility gap, providing an auditable feed of entities that have been quietly dropped by major industry players.

Malvertising and AI-Generated "Slop"

The convergence of programmatic advertising and generative artificial intelligence has birthed a massive new threat vector: AI-generated "slop" websites and mobile applications. These content farms churn out low-quality, machine-generated blog posts, recipes, and decorating guides designed solely to capture search engine traffic.

According to Edwards, these low-tier content farms rarely invest in brand-safety or ad-verification tools. Instead, they serve as "greased rails" for cybercriminals looking to launch malvertising campaigns—ads engineered to redirect users to phishing sites or drop malware payload zero-clicks.

Recent investigations highlight this operational nexus. Security researchers at Bitsight uncovered a popular line of H96 TV streaming sticks that quietly rented out user internet bandwidth to strangers while spoofing mobile device user-agents to click on ads hosted on AI-generated content farms. DecryptAds’ Legal Dossier and seller ID tracking tied these slop sites (such as medicalbeautyhub.com) to shared seller infrastructures that interface directly with ad systems like Russia’s Yandex, demonstrating an international web of low-quality sites monetizing fraudulent traffic.


Future Outlook: Securing the Adtech Supply Chain

As cyber threats evolve, the tools used to defend against them must adapt. DecryptAds is not merely a static database; it features an application programming interface (API) that enables security researchers to automate queries and integrate adtech intelligence directly into artificial intelligence platforms and threat-hunting workflows.

However, Edwards emphasizes that solving systemic ad fraud and malvertising will ultimately require broader industry reform—specifically, the mandatory exposure of the Supply Chain Object (SCO). The SCO is structured data attached server-side to programmatic bid requests, detailing every intermediary, reseller, and ultimate buyer involved in an ad transaction. Without access to these server-side logs, security teams can observe a malicious redirect or a malware payload, but they remain functionally blind to the financial pipeline that funded the attack.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

What Users Can Do Right Now

Given the pervasive surveillance and security risks inherent in modern adtech, digital security experts universally recommend proactive defense measures:

  1. Deploy Network-Level Ad Blocking: For a comprehensive, hardware-based solution, technical users can configure a Raspberry Pi running Pi-hole. Operating as a local DNS sinkhole, Pi-hole blocks ads and trackers across every connected device on a home network.
  2. Utilize Modern Browser Extensions: Desktop users should leverage robust, open-source tools like uBlock Origin Lite. Mobile users on Android can pair Firefox with similar extensions, while iOS users can rely on utilities like Adblock Plus alongside rulesets from easylist.to.
  3. Exercise Extreme Caution with Mobile Apps: Major digital platforms frequently pressure users to install dedicated mobile apps under the guise of an "enhanced experience." In reality, mobile apps allow corporations to bypass browser-level protections, collect highly granular geolocation and behavioral data, and automatically opt users into training large language models. Whenever possible, interact with services via a secured web browser rather than a dedicated application—and treat smart TV apps with equal skepticism.

Services like DecryptAds prove that while the adtech underworld is vast and intentionally opaque, radical transparency is finally within reach. By shining a light on the hidden plumbing of the internet, researchers are equipping everyday users and enterprise defenders alike with the data needed to push back against unchecked digital surveillance.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *