Cybersecurity

DecryptAds Launches Free Intelligence Platform to Decode the Shady Digital Advertising Supply Chain

The rapid evolution of the digital advertising ecosystem has created a labyrinthine market where the identities of entities harvesting user data and distributing advertisements are obscured by layers of obscurity. For years, the foundational architecture governing online tracking—comprising public disclosure files mandated by the Interactive Advertising Bureau (IAB)—has remained walled off behind complex data structures or hoarded by major adtech conglomerates. This structural opacity has severely hampered the ability of independent cybersecurity researchers, privacy advocates, and enterprise security teams to audit who exactly possesses the technical authorization to track users across the web and mobile applications.

To bridge this critical visibility gap, a powerful new, free service named DecryptAds has officially launched at decryptads.com. Designed to ingest, cross-reference, and analyze semi-public advertising technology data, DecryptAds transforms fragmented text files into coherent intelligence dossiers. By systematically scraping digital disclosures, the platform provides deep insights into the corporate networks, data brokers, and supply chain interdependencies underlying popular websites and applications.

The Anatomy of Adtech Disclosures: Decoding ads.txt, app-ads.txt, and Sellers.json

To understand how DecryptAds operates, one must examine the underlying mechanics of modern digital advertising governance. Websites and applications deploy specific text files designed to bring transparency to programmatic ad sales. These include ads.txt (Authorized Digital Sellers) for web properties, app-ads.txt for mobile and smart television applications, and buyers.json/sellers.json registries maintained by ad exchanges.

In theory, these files are meant to prevent domain spoofing and unauthorized ad inventory resale by explicitly listing authorized partners. In practice, however, analyzing a single ads.txt file yields limited context. Supply-chain integrity failures—such as hijacked seller accounts, unauthorized ad network reselling, and malicious redirect chains—rarely manifest within the confines of a single document. Instead, they appear as broken cross-references, cloned declaration sets across unrelated domains, and missing entries in upstream exchange logs.

DecryptAds was developed to automate the laborious process of correlating these disparate data points. Spearheaded by Zach Edwards, chief research officer for DecryptAds and threat researcher at security firm Infoblox, alongside two co-founders, the platform approaches adtech through a rigorous security lens. According to Edwards, the tool was built specifically to address severely underserved privacy and security use cases, ranging from tracking down the sources of malicious ad campaigns to identifying adversarial nation-state ad networks and uncovering burgeoning swarms of AI-generated content farms.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Unmasking the Data Brokers and Complex Supply Chains of Major Publishers

The utility of DecryptAds becomes immediately apparent when examining high-profile web properties. A search for the major sports network espn.com within the platform reveals an expansive network consisting of 143 ad partners and 19 registered data broker domains declared across its ads.txt and app-ads.txt files.

This level of granular disclosure is increasingly accessible due to a wave of state-level privacy legislation. Jurisdictions including California, Oregon, Texas, and Vermont have enacted laws requiring data brokers to formally register if they purchase or sell consumer data originating from within their borders. DecryptAds’ analysis indicates that nearly half of the data brokers linked to espn.com actively collect precise geolocation data from visitors who do not employ ad-blocking software. Furthermore, additional brokers explicitly disclose the collection of device fingerprints and sensitive personal attributes.

Visualizing these ecosystems exposes the staggering complexity of modern ad supply chains, where a single page load triggers dozens of programmatic auctions, bidding intermediaries, and data-harvesting scripts operating simultaneously behind the scenes.

See also  APT TA423 Deploys ScanBox in Sophisticated Watering Hole Attacks Targeting Australian Organizations and South China Sea Energy Firms

Geopolitical Risks and High-Risk Ad Partners

Beyond domestic data collection, DecryptAds features a dedicated "Geo-Risk" monitoring system that flags advertising partners headquartered in adversarial jurisdictions, such as China and Russia, or in regional financial hubs with deep ties to those nations, including Cyprus and the United Arab Emirates (UAE).

For instance, the platform’s dossier on espn.com highlights partnerships with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a primary address in New York. However, DecryptAds traces the company’s operational roots to Russia, noting that its publisher payout offers are processed through Alfa Bank, Russia’s largest private commercial bank, which was subjected to severe United States sanctions following the 2022 invasion of Ukraine.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The reach of such networks extends across critical infrastructure and institutional media. DecryptAds queries targeting prominent United States military-focused news domains—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveal that all of these properties authorize Between Digital to serve advertisements and track readers. Furthermore, these military news sites authorize additional entities operating out of the UAE and the corporate secrecy jurisdiction of Panama. Public tracking metrics indicate that Between Digital actively collects advertising telemetry across approximately 55,000 partner websites globally.

Pivoting further into Between Digital’s app-ads.txt infrastructure exposes hundreds of domains tied to low-complexity web games designed to bombard users with interstitial advertisements. Edwards notes that Between Digital’s internal declarations list the firm as both a publisher and a reseller on roughly two-thirds of its portfolio. This dual positioning creates inherent conflicts of interest, allowing firms to arbitrate bidding transactions where they act as buyer, seller, and exchange simultaneously.

Similar structural entanglements are evident when examining major consumer software. The Opera web browser, which retains a massive global user base, has been majority-owned and controlled by Chinese firm Kunlun Tech since 2016, though its operational headquarters remain in Oslo, Norway. A profile of opera.com on DecryptAds identifies 27 registered data brokers collecting user intelligence, including 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These entities represent merely seven percent of the total adtech partners specified in Opera’s formal disclosure files.

Uncovering Legal Dossiers, AI Content Farms, and Malicious Redirects

One of the platform’s most powerful diagnostic features is its Legal Dossier lookup tool. By aggregating domain registration histories, corporate filings, and infrastructure aliases, the tool traces the real-world ownership and operational lineage of opaque websites and mobile applications.

Recent investigations into malicious hardware ecosystems highlight the efficacy of this approach. Security researchers at Bitsight previously uncovered a widespread supply chain compromise involving popular H96-branded TV streaming sticks. When idle, these devices were found to covertly rent out consumer internet connections as residential proxies while simultaneously spoofing mobile device signatures to simulate ad clicks on automated, AI-generated content farms—colloquially known as "AI slop" websites.

Bitsight tied these operations to the Fengwo Group, a Chinese entity responsible for both the malicious streaming apps and the networks of low-quality ad-landing pages. Utilizing DecryptAds, researchers analyzed a dormant domain associated with the Fengwo Group (medicalbeautyhub.com) and discovered it shared a specific seller ID (1674071) with an unrelated gaming property, giacoloredstones.com. Tracing secondary seller IDs associated with that property mapped out hundreds of active websites integrated into Russia’s Yandex ad network, illustrating how malicious infrastructure weaves across international borders.

See also  7-Zip Releases Version 26.02 to Address Critical Remote Code Execution Vulnerability in XZ Processing
Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Illuminating "Quiet Removals" and the Malvertising Threat

A persistent challenge in combating ad fraud and malicious advertising ("malvertising") is the industry practice of "quiet removals." When ad exchanges or programmatic networks discover that a participating partner is engaged in unauthentic traffic generation or malware distribution, they frequently excise the offender from their sellers.json files without issuing public advisories. This lack of transparency allows rogue operators to seamlessly migrate to alternative exchanges without reputational damage.

To counter this information vacuum, DecryptAds hosts a "Quiet Removals Feed" that continuously monitors and correlates sellers.json deletions across multiple ad exchanges. By tracking when a seller domain abruptly disappears from authorization lists, security analysts gain unprecedented visibility into systemic enforcement actions taken by major platforms.

This visibility is vital for combating malvertising, which increasingly targets low-quality AI-generated content farms rather than high-traffic mainstream destinations. Major publishers invest heavily in third-party brand safety tools and real-time monitoring to intercept malicious creative payloads. Conversely, AI content farms rely on the cheapest available ad networks, creating an unmonitored "greased rail" that delivers exploit payloads and phishing redirects directly to unsuspecting web users.

Edwards emphasizes that truly neutralizing malvertising requires greater data-sharing from major ad networks, specifically concerning the "Supply Chain Object" (SCO). The SCO is a structured data object attached to programmatic bid requests that maps every seller, reseller, and intermediary involved in passing an ad impression from publisher to buyer. Because SCO data is typically processed exclusively on server-side infrastructure, external researchers lack visibility into the final entity that purchased the impression responsible for serving malware payloads. Opening access to these metrics, Edwards argues, is essential for holding bad actors accountable.

Practical Defense Strategies for Users and Enterprises

Given the pervasive tracking, data brokering, and security risks embedded within the modern adtech supply chain, cybersecurity experts universally recommend the deployment of robust local and network-level ad-blocking mechanisms.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

For desktop and laptop users utilizing standard web browsers, open-source extensions such as uBlock Origin Lite offer efficient, lightweight protection against tracking scripts and advertisements. Mobile users on Android can leverage similar browser extensions via Firefox, while iOS users can utilize solutions like Adblock Plus or configure content-blocking rulesets derived from established community repositories like EasyList.

For advanced users seeking network-wide protection, hardware-based solutions offer superior scalability. Deploying a low-cost single-board computer, such as a Raspberry Pi, running Pi-hole transforms a local network into an ad-blocking and domain-sinkholing environment, preventing connected devices from communicating with known tracking and telemetry domains.

Furthermore, security professionals advise caution regarding mobile applications and smart TV software. Publishers frequently pressure users to migrate from mobile web browsers to dedicated native applications not to improve user experience, but to bypass browser-based privacy controls, capture granular location telemetry, and collect comprehensive user behavior profiles for monetization and machine-learning training pipelines. As digital surveillance continues to expand across connected devices, platforms like DecryptAds provide crucial transparency, empowering individuals and organizations to audit the invisible networks tracking their digital lives.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.