DecryptAds Service Unveils Hidden AdTech Supply Chains to Combat Malvertising, Data Harvesting, and Geopolitical Privacy Risks

Navigating the modern digital landscape often feels like stepping into a labyrinth of invisible trackers, data brokers, and automated advertising exchanges. For years, the mechanisms governing how advertisements appear on websites or how mobile applications harvest user data have remained opaque. While much of this foundational data is technically semi-public, it has traditionally stayed walled inside massive advertising platforms, formatted in ways that defy easy human analysis.
The launch of a powerful, free public utility named DecryptAds (decryptads.com) aims to change that dynamic entirely. By continuously scraping, indexing, and cross-referencing public-facing compliance files from millions of websites and mobile applications, DecryptAds strips away the obscurity of the adtech ecosystem. The platform provides a streamlined interface for researchers, privacy advocates, and security professionals to examine the sprawling web of entities tracking everyday internet users.
The Mechanics of AdTech Transparency
At its core, DecryptAds operates by aggregating three primary compliance files that modern publishers and app developers are standardly required to publish:
- ads.txt (Authorized Digital Sellers): A public text file that lists all authorized ad tech vendors and data brokers permitted to buy, sell, or run advertisements on a specific website.
- app-ads.txt: The mobile and smart-TV ecosystem equivalent of ads.txt, detailing the third-party entities authorized to monetize or harvest data from application environments.
- buyers.json / sellers.json: Cryptographic registry files provided by ad exchanges that identify the ultimate entities buying, selling, or reselling digital ad inventory.
Zach Edwards, chief research officer for DecryptAds and a threat researcher at the security firm Infoblox, explains that the platform was conceived by a team of three founders who recognized a glaring gap in the market. While raw data files have existed for years, they are virtually useless in isolation. True visibility requires deep cross-referencing to construct an accurate map of a publisher’s entire advertising supply chain.
"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards noted. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Among these underserved use cases are tracing the origins of malvertising campaigns designed to distribute malware, identifying ad networks anchored in adversarial nation-states, and flagging the exponential growth of artificial intelligence-generated content farms—colloquially known as "AI slop" websites.
Unraveling Complex Supply Chains: The ESPN Case Study
To understand the complexity of modern digital advertising, one need only look at how prominent web properties declare their monetization partners. A search on DecryptAds for the widely visited sports network ESPN (espn.com) reveals 143 distinct advertising partners alongside 19 registered data brokers declared within its ads.txt and app-ads.txt files.
The visibility into these data brokers is becoming increasingly accessible thanks to recent legislative shifts. Four U.S. states—California, Oregon, Texas, and Vermont—have enacted legislation requiring data brokers to formally register if they purchase or sell consumer data originating within their borders. According to DecryptAds, nearly half of the data brokers linked to ESPN are actively collecting geolocation data from site visitors who do not employ ad-blocking software, while others routinely harvest device fingerprints and sensitive personal identifiers.
Furthermore, supply-chain vulnerabilities rarely manifest in a single, isolated file. Analysts examining the platform note that systemic risks typically surface through broken cross-references between ads.txt and sellers.json files, cloned declarations across unrelated domains, or supply paths logged during real-time bidding wars that never formally appear on a publisher’s authorized seller list.
High-Risk Ad Partners and Geopolitical Exposure
One of DecryptAds’ most critical features is its automated "Geo-Risk" analysis, which flags advertising partners operating out of high-risk jurisdictions—primarily China and Russia—as well as intermediary financial hubs with deep political ties to those nations, such as the United Arab Emirates and Cyprus.
The platform’s inspection of ESPN’s supply chain, for instance, highlights business relationships with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a corporate address in New York City. However, the DecryptAds dossier on Between Digital classifies it as a Russian enterprise, noting that its financial transactions are processed through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank has been subject to sweeping U.S. economic sanctions since 2022 following the escalation of the Russia-Ukraine conflict.

This exposure is not unique to mainstream entertainment media. A parallel search across prominent U.S. military news properties—including Army Times, Air Force Times, Defense News, Navy Times, Marine Corps Times, and Federal Times—reveals that all of these platforms maintain monetization relationships allowing Between Digital to serve advertisements and track users. Additional partners tied to the UAE and the corporate secrecy jurisdiction of Panama were also identified across these defense-focused publications. Public records indicate that Between Digital collects ad telemetry across roughly 55,000 partner websites globally.
Deep-dive analyses into Between Digital’s app-ads.txt configurations uncover hundreds of domains dedicated to lightweight, web-based mobile games interrupted frequently by commercial breaks. Edwards points out that Between Digital is listed as both a publisher and a reseller across approximately two-thirds of its portfolio, creating inherent conflicts of interest where an entity plays both sides of the programmatic bidding equation.
Similar scrutiny applies to major consumer software. The Opera web browser, which maintains its operational headquarters in Oslo, Norway, has been majority-owned by the Chinese firm Kunlun Tech since 2016. A DecryptAds profile of opera.com reveals 27 registered data brokers, including 15 entities based in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These specific regional actors represent just seven percent of the total adtech partners declared in Opera’s compliance documentation.
Legal Dossiers and the Threat of AI Slop Networks
Another powerful utility provided by DecryptAds is its Legal Dossier lookup tool. Although queries can take several minutes to process as the system aggregates historical registration records, aliases, and ownership structures, the resulting intelligence maps out corporate networks with remarkable clarity.
Recent investigations into malicious hardware supply chains underscore the value of this feature. Security researchers from Bitsight previously uncovered an extensive line of residential TV streaming sticks—marketed under brand names such as H96—that covertly rented out the internet bandwidth of unsuspecting consumers to third parties. When not utilized for unauthorized video streaming relays, these devices spoofed mobile phone identifiers to continuously click on advertisements hosted across automated, AI-generated content farms.
Bitsight attributed this infrastructure to the Fengwo Group, a Chinese entity operating both the malicious applications embedded within the hardware and the network of low-quality advertising landing pages. A DecryptAds legal dossier query into a now-dormant Fengwo Group domain (medicalbeautyhub.com) revealed shared seller IDs with unrelated gaming sites, which in turn tied back to hundreds of low-tier gaming and utility properties operating within Russia’s Yandex ad system.

Exposing Quiet Removals and Malvertising Vectors
Within the programmatic advertising industry, ad networks frequently discover that specific publishers or partners are generating fraudulent, unauthentic clicks or serving malicious code. Rather than issuing public warnings, networks often quietly purge the offending party from their sellers.json files without notification. This opacity allows malicious actors to migrate seamlessly to other exchanges.
To counter this information vacuum, DecryptAds features a "Quiet Removals Feed" that tracks and correlates sellers.json deletions across multiple ad exchanges in real-time. By aggregating these hidden bans, security researchers can identify compromised or suspicious seller domains that would otherwise evade detection.
The convergence of unvetted ad networks and generative artificial intelligence has supercharged the threat of "malvertising"—the injection of malicious code into ad delivery networks to drive drive-by downloads or phishing campaigns. According to Edwards, sophisticated threat actors rarely target high-traffic, heavily monitored destinations like major news outlets, which employ dedicated security teams and strict vetting protocols. Instead, they exploit the unpoliced expanses of AI-generated content farms.
These content farms, populated by automated blog posts spanning home improvement, culinary recipes, automotive topics, and consumer technology, monetize rapidly by onboarding the lowest-tier programmatic ad partners.
"None of these slop AI content farms are paying for that kind of protection," Edwards emphasized. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads."
Mitigating this threat requires greater data transparency from dominant ad networks, particularly regarding the sharing of Supply Chain Objects (SCO)—structured data attached to real-time bid requests that trace every intermediary handling an ad impression from publisher to buyer. Without server-side visibility into SCO data, defending organizations struggle to identify the exact vectors used to target high-value personnel with advanced exploits.

Proactive Defense and Mitigation Strategies
Given the expansive telemetry collection inherent in modern digital advertising, cybersecurity experts universally recommend a multi-layered approach to blocking online ads and network trackers.
For desktop and laptop users, open-source browser extensions such as uBlock Origin Lite offer robust, well-maintained filtering capabilities. Mobile users operating within Android environments can similarly utilize Firefox paired with comprehensive content blockers, while iOS users on iPhones and iPads can leverage established extensions like Adblock Plus combined with community-maintained filter lists from sources like EasyList.
For advanced users seeking network-wide protection, hardware-level solutions provide an effective, scalable defense. Installing free software such as Pi-hole on a low-cost, dedicated microcomputer like a Raspberry Pi creates a local DNS sinkhole. When integrated into home router configurations, a Pi-hole automatically blocks known ad-serving and tracking domains across every connected device on the local network—including smart home appliances and connected televisions.
Security professionals also advise caution regarding the proliferation of standalone mobile applications. Many commercial services aggressively push consumers to install dedicated apps under the guise of an enhanced user experience, when the primary underlying motivation is often the unfettered collection of granular user telemetry and device metadata. By interacting with services directly through web browsers equipped with robust content blockers, and utilizing tools like DecryptAds to audit corporate compliance disclosures, users can significantly curtail their digital exposure and mitigate systemic cybersecurity risks.







