The labyrinthine ecosystem responsible for delivering digital advertisements and harvesting user data across websites and mobile applications has long remained shielded behind closed doors. While basic information regarding ad placement and data collection has technically been semi-public, it has traditionally resisted easy parsing, remaining walled off within the infrastructure of major advertising platforms. A powerful and free new service called DecryptAds aims to change that dynamic by systematically scraping, correlating, and simplifying adtech data, enabling security researchers, privacy advocates, and everyday users to quickly understand the vast network of entities tracking their digital footprints.
The newly launched platform, accessible at decryptads.com, operates by continuously scraping publicly available files that publishers and app developers use to disclose authorized advertising partners and data collection entities. These foundational files include ads.txt for desktop and mobile websites, app-ads.txt for mobile and smart TV applications, and buyers.json alongside sellers.json, which document the commercial entities buying, selling, or reselling advertising inventory across specific domains and applications.
Zach Edwards, chief research officer for DecryptAds and a threat researcher at the cybersecurity firm Infoblox, noted that he and his co-founders recognized an urgent need for the service because raw adtech data is rarely illuminating in isolation. It only gains analytical value when cross-referenced to construct a comprehensive picture of the advertising supply chain for any given website or application.
Approaching adtech from an analytical and defensive security perspective, Edwards emphasized that the platform is engineered to serve critical privacy and security use cases that have historically been neglected by mainstream security tools. These vital applications include tracing the origins of malicious advertisements designed to deliver malware payloads, identifying advertising networks operating out of adversarial nations, and detecting the rapidly proliferating ecosystem of AI-generated content farms and low-quality applications. As decryptads.com demonstrates, identifying these structural security and privacy threats is virtually impossible through the manual inspection of isolated configuration files.
Supply-chain integrity vulnerabilities rarely manifest within a single file. Instead, they typically surface as broken cross-references connecting ads.txt, app-ads.txt, and sellers.json documents, as cloned declaration sets deployed across entirely unrelated domains, as sudden seller removals that only become apparent when viewed across multiple exchanges, and as obscure supply paths recorded in server-side bid logs that never materialize within a publisher’s authorized-seller directory.

A preliminary search on DecryptAds regarding the prominent sports network espn.com reveals that its configuration files declare a staggering 143 advertising partners and 19 registered data broker domains. This granular insight into data brokers is increasingly accessible due to legislative frameworks recently enacted in four U.S. states—California, Oregon, Texas, and Vermont—which mandate that data brokers register their operations if they buy or sell consumer data originating from those jurisdictions. DecryptAds reports that nearly half of these disclosed data brokers collect precise geolocation data from visitors who do not employ ad-blocking technology, while another subset discloses the collection of device fingerprints and sensitive personal information.
High-Risk Ad Partners and Geopolitical Exposure
Beyond basic supply chain mapping, DecryptAds simplifies the process of identifying the ultimate beneficiaries and national origins of advertising firms operating within applications and websites. The platform automatically applies a conspicuous warning label when an adtech partner associated with a publisher is headquartered within designated geo-risk regions, such as China and Russia, or in nations maintaining deep financial and political alignments with them, including Cyprus and the United Arab Emirates.
According to DecryptAds data, espn.com maintains commercial relationships with four distinct advertising entities based in Russia, China, or the United Arab Emirates. Among them is Between Digital, an adtech firm that lists an official corporate address in New York. However, the DecryptAds dossier on Between Digital classifies the organization as a Russian enterprise, documenting that its publisher payout offers are processed through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank is among the major financial institutions subjected to sweeping U.S. economic sanctions following the invasion of Ukraine in 2022. Requests for comment sent by security researchers to Between Digital and its founder remained unanswered at the time of publication.
A broader inquiry across prominent U.S. military news properties, including publications covering the Army, Air Force, Defense, Navy, Marine Corps, and federal workforce, indicates that all of these defense-adjacent sites authorize Between Digital to serve advertisements and track users. Additional authorized entities linked to these military portals include firms based in the United Arab Emirates and the ownership secrecy haven of Panama. DecryptAds reports that Between Digital actively collects advertising telemetry across approximately 55,000 partner websites worldwide.
Examining Between Digital’s app-ads.txt file reveals hundreds of domains tied to simple web-based games that frequently interrupt user interaction with advertisements. Edwards pointed out that Between Digital’s own declarations position the company as both a publisher and a reseller across roughly two-thirds of its portfolio. This dual operational role means the firm effectively participates on both sides of the bidding marketplace, creating potential conflicts of interest that could allow an entity to direct client advertising spend toward its own infrastructure or owned properties. For years, the absence of active regulatory oversight for ads.txt and app-ads.txt files has allowed such practices to flourish unchecked.

Similar complexities emerge when examining the infrastructure of widely used software, such as the Opera web browser. Despite maintaining its operational headquarters in Oslo, Norway, Opera has been majority-owned and controlled by the Chinese technology firm Kunlun Tech since 2016. The DecryptAds profile for opera.com identifies 27 registered data brokers collecting information, including 15 adtech partners based in the United Arab Emirates, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These entities account for approximately seven percent of the total adtech partners explicitly declared within Opera’s authorization files.
Investigative Legal Dossiers and Quiet Removals
A standout feature of DecryptAds is its legal dossier lookup capability. While individual queries can take several minutes to process, the tool aggregates extensive intelligence regarding domain ownership history, registration timelines, corporate aliases, and structural relationships connecting adtech intermediaries, websites, and mobile applications.
Recent cybersecurity research from Bitsight highlighted significant supply chain risks associated with popular TV streaming sticks branded as H96, which covertly lease residential internet connections to unknown third parties. Researchers discovered that when these devices are not actively streaming video content, they routinely spoof mobile phone device identifiers to simulate clicks on advertisements hosted across AI-generated content farms. Bitsight linked these activities to a Chinese corporate entity known as the Fengwo Group, which simultaneously operated the network of low-quality websites targeted by the automated click fraud generated by tens of thousands of compromised streaming devices.
A DecryptAds legal dossier search targeting a dormant Fengwo Group domain associated with one of these AI content sites reveals shared seller identifiers with unrelated gaming portals, which in turn connect to extensive networks of active websites operating within Russia’s Yandex advertising ecosystem. These interconnected properties predominantly feature low-quality games and utility applications designed to inundate visitors with automated advertising displays.
To combat visibility gaps in the adtech ecosystem, DecryptAds incorporates a quiet removals feed. Edwards explained that when advertising networks suspect a publisher or partner of generating fraudulent engagement or serving malicious advertisements, they frequently remove the offending entity from their sellers.json files without public disclosure. This secretive practice enables compromised adtech firms to evade accountability and continue operating across other platforms. By aggregating sellers.json changes across multiple exchanges, the DecryptAds removal feed documents when and where suppliers disappear from authorized exchange lists.

Malvertising and Artificial Intelligence Content Farms
Malvertising—the malicious injection of online advertisements designed to distribute malware or direct unsuspecting users toward credential-harvesting phishing pages—remains a persistent threat within the digital advertising supply chain. Edwards observed that contemporary malvertising attacks have largely migrated away from high-traffic mainstream publications, which typically invest in robust third-party security tooling and rapid threat mitigation. Instead, these threats predominantly target newly spawned artificial intelligence content farms.
These automated content generation sites typically feature machine-written articles and imagery covering diverse consumer topics ranging from home improvement and recipes to automotive technology and consumer goods. Lacking the resources or willingness to invest in proper ad verification services, these operations onboard low-quality advertising partners, creating an unmonitored pathway for malicious actors to deliver zero-click payloads to visitors who arrive via search engine results.
Effectively countering malvertising and fraudulent ad injection requires significantly greater transparency and data-sharing from major advertising exchanges. Specifically, industry participants frequently withhold access to the supply chain object, a structured dataset attached to individual bid requests that details every seller, reseller, and intermediary involved in passing an ad impression from the publisher to the final buyer. Without access to server-side supply chain objects, organizations targeted by sophisticated malvertising campaigns struggle to identify the ultimate source of malicious payloads or implement effective preventative measures.
Mitigation and Defense Strategies
Given the structural complexities and security risks inherent in the modern digital advertising ecosystem, security professionals routinely advocate for the deployment of comprehensive ad-blocking technologies. Beyond enhancing user privacy by curtailing the data collection practices of brokers and trackers, robust ad blocking remains an effective defense against malvertising vectors.

For standard desktop and laptop web browsing, open-source extensions such as uBlock Origin Lite offer reliable protection and are compatible with select mobile browsers on Android platforms. Users operating Apple mobile devices frequently rely on established extensions like Adblock Plus, while power users can implement custom filter lists from established curation repositories to refine blocking rules. More advanced script-blocking tools, such as NoScript, prevent unauthorized JavaScript execution but often require significant manual configuration to ensure websites render correctly.
For technically inclined users seeking network-wide protection, hardware-based solutions deployed at the local network level provide an efficient alternative. By configuring low-cost microcomputers such as a Raspberry Pi to run open-source DNS sinkhole software like Pi-hole, households and small organizations can intercept advertising and tracking domains before they reach any connected device on the local network.
Security researchers continually advise caution regarding the installation of standalone mobile applications and smart TV software. Major digital platforms frequently encourage users to download dedicated apps under the guise of an improved user experience, while the underlying motivation often centers on maximizing user retention and harvesting granular telemetry data that exceeds the capabilities of standard web browsers. Reviewing application disclosures and utilizing analytical platforms like DecryptAds can provide vital visibility into the hidden commercial relationships governing modern digital environments.
Leave a Reply