It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include: ads.txt, which lists all adtech companies and data brokers that may run ads or harvest data from a site; app-ads.txt, which identifies entities that can harvest data from or display ads on mobile and smart TV apps; and buyers.json/sellers.json, which detail the entities buying, selling, or reselling ad inventory for a given site or app.

Zach Edwards, chief research officer for DecryptAds and a threat researcher at Infoblox, explained that he and two other founders recognized the need for such a service because the adtech data within these files is most valuable when cross-referenced to construct a comprehensive view of the advertising ecosystem for each website or app. "It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards stated. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved." These use cases include tracing the origins of malicious ads designed to distribute malware, identifying ad networks operating in adversarial nations, and detecting the proliferation of AI-generated "slop" websites and apps. Edwards emphasized that the complexities and interconnectedness of these issues make them nearly impossible to discern by examining a single ads.txt or app-ads.txt file. "Supply-chain integrity issues rarely live in a single file," the DecryptAds website elaborates. "They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

A search on DecryptAds for the popular sports network espn.com revealed 143 ad partners and 19 registered data broker domains listed in its ads.txt and app-ads.txt files. This data on data brokers is becoming more accessible due to recent legislation in California, Oregon, Texas, and Vermont, which mandates data brokers to register if they trade consumer data from those states. DecryptAds reports that nearly half of these data brokers collect geolocation data from ESPN.com visitors who are not blocking ads, while three others admit to collecting device fingerprints and sensitive personal information.

DecryptAds also facilitates the identification of advertising firms operating within apps and websites, flagging those based in "geo-risk" areas like China and Russia, or in countries with strong ties to both, such as Cyprus and the United Arab Emirates (UAE). According to DecryptAds, espn.com collaborates with four advertising entities based in Russia, China, or the UAE. One such entity is Between Digital, an adtech firm that lists a New York address but is flagged by DecryptAds as a Russian firm. Their publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank and a sanctioned institution following Russia’s invasion of Ukraine. KrebsOnSecurity reached out to Between Digital and its founder for comment, and will update the story if a response is received.

Searches for several prominent U.S. military news websites, including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com, show they all permit Between Digital to serve ads and track users. Additionally, they partner with two entities in the UAE and one in Panama, a jurisdiction known for its secrecy. DecryptAds reports that Between Digital collects ad data from approximately 55,000 partner websites.

Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games often interrupted by ads. Edwards noted that Between Digital’s own declarations indicate the company acts as both a publisher and a reseller on roughly two-thirds of its portfolio. "It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards explained. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The Opera web browser, still widely used, has been majority-owned and controlled by the Chinese company Kunlun Tech since 2016, although its operational headquarters remain in Oslo, Norway. Opera.com’s profile on DecryptAds lists 27 registered data brokers and 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. DecryptAds clarifies that these represent only seven percent of Opera.com’s total adtech partners.

A particularly insightful feature of DecryptAds is its Legal Dossier lookup. While each search takes several minutes, it provides extensive information about domain and app ownership, registration details, and any affiliations with adtech companies and other online entities. For instance, DecryptAds’ legal dossier on a now-dormant Fengwo Group domain name (medicalbeautyhub.com), previously linked to AI-generated content sites and implicated in renting out user internet connections and spoofing devices to click on ads, shows a shared seller ID with a gaming website (giacoloredstones.com). This gaming website, in turn, uses another seller ID that links to hundreds of websites within Russia’s Yandex ad system, primarily featuring low-quality games or utilities laden with ads.

Edwards highlighted a concerning practice in the adtech industry where advertising networks, upon suspecting an advertiser of fraudulent activity or malicious ads, often quietly remove them from their approved partner lists without notifying others. This lack of transparency allows unscrupulous adtech firms to evade accountability. To address this "visibility gap," DecryptAds features a "quiet removals feed" that tracks and correlates seller.json removals across ad exchanges for the same seller domain or name. "The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards stated. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

Malvertising, the distribution of malware or redirection to phishing pages through malicious ads, remains a significant threat. Edwards notes that these malicious ads are increasingly prevalent on newly generated AI-generated "slop" websites rather than on high-traffic destinations, which typically employ robust defenses against bad ads. "None of these slop AI content farms are paying for that kind of protection," he said. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search." These AI slop websites, populated with machine-generated content across various themes, often leave organizations targeted by malicious ads unsure of their next steps. Edwards advises that the solution often lies within the website’s ads.txt or app-ads.txt file. "A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis," he asserted.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Edwards believes that effectively combating malvertising and AI slop requires greater data-sharing from major ad networks, particularly regarding the "supply chain object" (SCO). SCO is structured data attached to advertising bid requests that reveals every seller, reseller, and intermediary involved in delivering an ad impression. "That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload," Edwards explained. "You may see the malicious zero-click redirection, but without the supply chain object—which is only served server side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad." DecryptAds also offers an API for researchers to automate queries and integrate its functionality into AI platforms.

The most straightforward approach to mitigating these tracking and malvertising risks is to block all online ads. Security experts widely endorse this strategy as it significantly hinders adtech firms and data brokers from constructing detailed user profiles and tracking online activity. For users browsing on desktop or laptop computers, uBlock Origin Lite is a highly recommended free, open-source ad blocker. It is also compatible with mobile browsers like Firefox on Android devices. Adblock Plus is a suitable option for iPhone and iPad users. Both uBlock Origin and Adblock Plus support custom blocking rules from easylist.to, a frequently updated list that effectively removes most advertisements. For users comfortable with managing JavaScript, the NoScript browser extension blocks all non-approved JavaScript code, which can effectively prevent many ads from loading, though it requires user intervention to permit necessary scripts for website functionality.

For more technically inclined users, a hardware-based ad-blocking solution at the local network level offers the most cost-effective, secure, and scalable approach. A Raspberry Pi, a small, inexpensive computer, can be transformed into a powerful network-wide ad blocker by installing Pi-hole. After proper setup and configuring router settings to utilize Pi-hole’s DNS sinkhole and DHCP servers, ads will be blocked on all devices connected to that network.

It’s important to note that ad blockers often have limited effectiveness against ads and tracking within mobile apps. Many websites encourage users to download their mobile apps, ostensibly for a better experience, but often to facilitate more extensive data collection and longer user engagement. These apps can also contribute to the training of large language models with user data. Therefore, caution is advised regarding app installations, and users are encouraged to investigate their privacy practices and adtech affiliations through services like DecryptAds.