It can be a daunting task to decipher the entities responsible for the advertisements that populate the websites we visit, or to understand who is actively harvesting data from the mobile applications we interact with daily. This crucial information, while technically semi-public, has historically been fragmented, difficult to parse, and largely confined within the proprietary ecosystems of major advertising platforms. However, a groundbreaking and entirely free service, aptly named DecryptAds, is set to revolutionize this landscape by meticulously scraping and correlating adtech data, presenting it in an easily digestible format that empowers users to quickly ascertain the entities tracking them.

A Decryptads summary of the advertising partnerships declared by espn.com.

A Decryptads summary of the advertising partnerships declared by espn.com.

The newly launched decryptads.com is designed to continuously scan publicly available files from websites and applications, thereby disclosing the companies authorized to display advertisements or collect user data. These vital disclosure files include:

  • ads.txt: This file enumerates all adtech companies and data brokers that are permitted to serve ads or harvest data from a specific website.
  • app-ads.txt: This file serves a similar purpose for mobile and smart TV applications, identifying entities authorized to collect data or display ads within these platforms.
  • buyers.json/sellers.json: These files detail the entities involved in the buying, selling, or reselling of ad inventory for a given website or app, providing a deeper look into the transaction layers.

Zach Edwards, Chief Research Officer at DecryptAds and a threat researcher at the security firm Infoblox, explained that the impetus for creating this service stemmed from the observation that the adtech data within these files was often siloed and lacked comprehensive cross-referencing. He and his co-founders recognized the critical need for a tool that could aggregate and analyze this data to construct a more complete picture of the adtech ecosystem surrounding each website and application. "It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards stated. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

These specific use cases, as highlighted by Edwards, include the crucial ability to trace the origins of malicious advertisements designed to distribute malware, pinpoint ad networks operating from adversarial nations, and identify the rapidly proliferating network of AI-generated "slop" websites and applications. The limitations of relying on individual ads.txt or app-ads.txt files are evident; DecryptAds demonstrates that a holistic view is essential for detecting these multifaceted threats. The platform’s blog post emphasizes this point: "Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

A comprehensive analysis of espn.com, a highly popular sports network, via DecryptAds reveals a staggering 143 ad partners and 19 registered data broker domains within its ads.txt and app-ads.txt files. This data on data brokers is becoming increasingly accessible due to recent legislation in California, Oregon, Texas, and Vermont, which mandates registration for data brokers operating within those states. DecryptAds reports that nearly half of these identified data brokers are collecting geolocation data from espn.com visitors who are not employing ad blockers. Furthermore, three of these brokers explicitly disclose the collection of device fingerprints and sensitive personal information.

A visual representation of the complex ad supply chain declared by espn.com.

A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.

HIGH-RISK AD PARTNERS

DecryptAds also offers a valuable feature that readily identifies the beneficiaries and national origins of advertising firms operating within applications and websites. It prominently displays warnings for adtech partners located in "geo-risk" zones, such as China and Russia, or countries with significant financial and political ties to these regions, including Cyprus and the United Arab Emirates (UAE).

According to DecryptAds data, espn.com collaborates with four distinct advertising entities that are either based in Russia, China, or the UAE. One such entity is Between Digital, an adtech firm that lists a New York address. However, a detailed dossier on Between Digital from DecryptAds flags them as a Russian firm, revealing that their publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank is among the financial institutions subjected to U.S. sanctions following Russia’s invasion of Ukraine in 2022. KrebsOnSecurity reached out to both Between Digital and its founder for comment and will update this report should a response be received.

A search for several prominent U.S. military news websites, including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com, indicates that all of them permit Between Digital to serve ads and track users. Additionally, they engage with two entities based in the UAE and another operating from Panama, a known haven for ownership secrecy. DecryptAds reports that Between Digital is collecting ad data from approximately 55,000 partner websites.

The “Geo Risk” section of decryptads.com.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The “Geo Risk” section of decryptads.com.

Further investigation into Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games frequently interrupted by advertisements. Edwards noted that Between Digital’s own disclosures indicate the company acts as both a publisher and a reseller on roughly two-thirds of its portfolio. "It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards explained to KrebsOnSecurity. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

The Opera web browser, despite its continued popularity, is majority-owned and controlled by the Chinese company Kunlun Tech since 2016, though its operational headquarters remain in Oslo, Norway. Opera.com’s profile on DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. DecryptAds clarifies that these entities represent only seven percent of the total adtech partners listed in Opera.com’s ads.txt and app-ads.txt files.

LEGAL DOSSIERS

A particularly compelling feature of DecryptAds, one that can lead to hours of engrossing research, is its Legal Dossier lookup. While each search may take several minutes to process, it ultimately generates a wealth of information about domain and app ownership, registration dates, and any associated aliases or relationships with adtech companies and other online entities.

For instance, in a previous report, KrebsOnSecurity detailed findings from Bitsight researchers who discovered that the popular H96 line of TV streaming sticks were surreptitiously renting out users’ internet connections to unknown parties. Bitsight also found that when these devices were not being used for streaming pirated video content, they were masquerading as mobile phones to click on ads on AI-generated "slop" websites. Bitsight concluded that the same Chinese company responsible for many of the malicious apps found on these H96 sticks, the Fengwo Group, was also operating the network of ad and AI slop websites being accessed by tens of thousands of these devices spoofing their device type as mobile phones.

Examples of ad landing pages linked to the Fengwo Group.

Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

A DecryptAds legal dossier for the now-dormant Fengwo Group domain name, medicalbeautyhub.com, which hosted one of the AI slop websites depicted in the screenshot, reveals that it shares a seller ID with a gaming website, giacoloredstones.com. This gaming website, in turn, features a different seller ID. Analyzing this latter seller ID further uncovers hundreds of active websites within Russia’s Yandex ad system, predominantly featuring low-quality games or simple utilities that inundate visitors with advertisements.

QUIET REMOVALS

Edwards explained that when advertising networks suspect an advertiser is engaged in fraudulent activity, such as inauthentic clicks or the distribution of malicious ads, they often discreetly remove the offender from their approved partner lists without alerting other parties to their suspicions. This practice allows unscrupulous adtech firms to evade accountability and continue their deceptive practices. To address this critical gap in transparency, DecryptAds features a "quiet removals feed" that meticulously records and correlates all seller.json removals across ad exchanges for the same seller domain or name.

A screenshot of the Quiet Removals Feed at decryptads.com.

A screenshot of the Quiet Removals Feed at decryptads.com.

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards stated. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

MALVERTISING AND AI SLOP

Malvertising, the insidious practice of embedding malicious advertisements that distribute malware or redirect users to phishing pages, remains a pervasive issue in the modern adtech landscape. However, Edwards observes that these malicious ads are now more frequently encountered on newly generated AI "slop" websites rather than on high-traffic destinations that typically employ robust technologies and third-party tools for rapid detection of problematic ads. "None of these slop AI content farms are paying for that kind of protection," he explained. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search."

Edwards further elaborated that these AI slop websites are populated with machine-generated content, including blog posts and images, covering a wide spectrum of topics such as home improvement, culinary recipes, hunting, automotive, and consumer technology. He noted that organizations encountering malicious ads are often at a loss for how to proceed, unaware that in many instances, the solution lies within the entities listed in the website’s ads.txt or app-ads.txt files. "A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis," he asserted.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

To effectively combat malvertising and the proliferation of AI slop, Edwards advocates for increased data-sharing by major ad networks. Specifically, he emphasizes the importance of sharing what is known as the "supply chain object" (SCO). This structured data, attached to each advertising bid request, provides buyers with a comprehensive view of every seller, reseller, and intermediary involved in the delivery of an ad impression from the publisher to the final buyer. "That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload," Edwards clarified. "You may see the malicious zero-click redirection, but without the supply chain object – which is only served server side – you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad." DecryptAds also offers an application programming interface (API) that enables researchers to automate queries and integrate the platform’s functionalities into popular AI tools.

WHAT CAN YOU DO?

Given the concerning examples detailed above, the most prudent course of action is to implement comprehensive ad blocking across all online activities. This approach is widely endorsed by security experts, as it significantly impedes adtech firms and data brokers from constructing detailed profiles and tracking user movements both online and in the physical world. The most effective strategy often depends on individual browsing habits and the level of trust placed in third-party browser plugins and extensions.

For users primarily browsing on desktop or laptop computers, uBlock Origin Lite stands out as an excellent, free, and well-maintained open-source option. uBlock Origin is also compatible with mobile browsers like Firefox, though it is reportedly only supported on Android devices. For iPhone and iPad users, Adblock Plus offers a solid alternative. Power users of both extensions can leverage custom blocking rules from easylist.to, a regularly updated resource that effectively removes most advertisements from webpages.

The well-established browser extension NoScript excels at blocking all non-approved JavaScript code, thereby preventing the loading of most advertisements. However, script blockers like NoScript may not be ideal for average users who prefer not to constantly manage which scripts are permitted to execute for proper website functionality.

For technically inclined and more adventurous users, a hardware-based approach to ad blocking at the local network level presents the most cost-effective, secure, and scalable solution. A compact, affordable, and widely available computer known as a Raspberry Pi, when equipped with a microSD memory card and the free Pi-hole program, can be transformed into a powerful network-wide ad blocker for all connected devices. Once properly configured, and with the router’s network settings adjusted to utilize Pi-hole’s DNS sinkhole and DHCP servers, it effectively prevents ads from appearing on any device within that network.

It is important to note that ad blockers often have limited efficacy in blocking ads and tracking that originate from within mobile applications installed by users. Many websites now actively encourage users to download their mobile apps, ostensibly to enhance access to services and content. However, my personal experience suggests that this push is not primarily driven by a superior user experience on the app itself (as LinkedIn frequently attempts to persuade non-app users). On the contrary, I find most mobile applications to be poorly designed, intrusive, and often entirely unnecessary. Given the choice, I almost invariably opt to interact with websites and services directly through a web browser.

The underlying reality is that major online destinations often promote their mobile apps because they facilitate greater user engagement and enable the collection of significantly more precise data about users—their demographics, activities, and locations—which can then be resold. Furthermore, companies that aggressively push app installations often automatically opt users into having their data utilized for training large language models. Therefore, exercising caution regarding the apps installed on mobile devices, including smart TVs, is paramount. Utilizing DecryptAds to investigate these applications can provide valuable insights into their privacy practices and any affiliations they may have with adtech firms.