It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:
- ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
- app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
- buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.
Zach Edwards, chief research officer for DecryptAds and a threat researcher at the security company Infoblox, explained the genesis of the service. He and two other founders recognized the critical need for a tool that could cross-reference adtech data from these files to build a more comprehensive understanding of the advertising ecosystem surrounding each website or app. “It’s an adtech tool, but we’re trying to approach adtech from a security perspective,” Edwards stated. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”
These crucial use cases include pinpointing the origins of malicious ads designed to distribute malware, identifying ad networks operating from adversarial nations, and detecting the rapidly proliferating networks of AI-generated "slop" websites and apps. As DecryptAds.com vividly demonstrates, uncovering these potential security and privacy threats is nearly impossible by examining a single ads.txt or app-ads.txt file in isolation.
The DecryptAds platform emphasizes that supply-chain integrity issues rarely manifest within a single file. Instead, they surface as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as identical declaration sets appearing across unrelated domains; as seller removals that only become comprehensible when viewed in the context of multiple exchanges; and even as supply paths in bid logs that are conspicuously absent from any given publisher’s authorized-seller list.
A deep dive into the immensely popular sports network espn.com via DecryptAds reveals a staggering 143 ad partners and 19 registered data broker domains listed within its ads.txt and app-ads.txt files. The increasing availability of data broker information is a direct result of recent legislation in California, Oregon, Texas, and Vermont, which mandate data broker registration for those operating within those states. DecryptAds reports that nearly half of these data brokers are actively collecting geolocation data from espn.com visitors who are not employing ad blockers. Furthermore, three of these entities explicitly state their collection of device fingerprints and sensitive personal information.
HIGH-RISK AD PARTNERS

DecryptAds also facilitates the identification of the beneficiaries and national origins of advertising firms operating within apps and websites. It prominently displays warnings when adtech partners of an app or website are located in "geo-risk" areas, such as China and Russia, or in countries with significant financial and political ties to these nations, like Cyprus and the United Arab Emirates (UAE).
According to DecryptAds, espn.com collaborates with four distinct advertising entities based in Russia, China, or the UAE. Among these is the adtech firm Between Digital, which, despite listing a New York address, is flagged by DecryptAds as a Russian firm. Their publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank and one of several institutions subjected to U.S. sanctions in 2022 following Russia’s invasion of Ukraine. KrebsOnSecurity reached out to Between Digital and its founder for comment and will update this report if a response is received.
Searches for several prominent U.S. military news websites—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveal that they all permit Between Digital to serve ads and track users. Additionally, these sites engage with two entities based in the UAE and one in Panama, a jurisdiction known for its secrecy in business ownership. DecryptAds indicates that Between Digital is collecting ad data on approximately 55,000 partner websites.
The app-ads.txt file of Between Digital further exposes hundreds of domains featuring simple web-based games frequently interrupted by advertisements. Edwards noted that Between Digital’s own declarations indicate the company acts as both a publisher and a reseller on roughly two-thirds of its portfolio. “It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards explained to KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”
The Opera web browser, despite its continued popularity, has been majority-owned and controlled by the Chinese company Kunlun Tech since 2016, though its operational headquarters remain in Oslo, Norway. Opera.com’s profile on DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. DecryptAds clarifies that these companies represent only seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.
LEGAL DOSSIERS
A particularly compelling feature of DecryptAds is its Legal Dossier lookup. While each search can take several minutes, it ultimately provides a wealth of crucial information about domain and app ownership, registration dates, and any disclosed aliases or relationships to adtech companies and other online entities.
For instance, in a recent investigation, researchers from Bitsight discovered that an extremely popular line of TV streaming sticks, known as H96, were covertly renting out users’ internet connections to third parties. Bitsight also found that when these devices were not being used for streaming pirated video content, they were masquerading as mobile phones, generating ad clicks on AI-generated "slop" websites. Bitsight concluded that the same Chinese company responsible for many of the malicious apps found on these H96 streaming sticks—the Fengwo Group—also operated the network of ad and AI slop websites being targeted by tens of thousands of these devices spoofing their device type as mobile phones.

A DecryptAds legal dossier on the now-dormant Fengwo Group domain name for an AI slop website pictured in a related screenshot reveals it shares a seller ID with a gaming website, giacoloredstones[.]com, which in turn features a different seller ID. Pivoting on this latter seller ID uncovers hundreds of active websites within Russia’s Yandex ad system, featuring extremely low-quality games or simple utilities that bombard visitors with advertisements.
QUIET REMOVALS
Edwards highlighted a common practice within the advertising networks: when an advertiser is suspected of engaging in fraudulent clicks or distributing malicious ads, those networks often quietly remove the offender from their approved partner lists without informing other parties of their suspicions. This clandestine practice allows unscrupulous adtech firms to evade accountability and continue their predatory activities. To combat this lack of transparency, DecryptAds offers a quiet removals feed that meticulously records and correlates all sellers.json removals across ad exchanges for the same seller domain or name.
“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards explained. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”
MALVERTISING AND AI SLOP
Malvertising, the practice of embedding malicious advertisements to distribute malware or redirect users to phishing pages, remains a pervasive issue in the contemporary adtech landscape. However, Edwards notes that these malicious ads are now more frequently encountered on newly generated AI slop websites rather than on high-traffic destinations that typically employ a robust suite of technologies and third-party tools for rapid detection of problematic ads.
“None of these slop AI content farms are paying for that kind of protection,” he stated. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”
Edwards elaborated that AI slop websites are populated with machine-generated blog posts and images, covering a broad spectrum of topics from home improvement and decorating to food recipes, hunting, cars, and consumer technology. He observed that organizations affected by malicious ads are often at a loss for how to proceed, unaware that in most cases, the solution lies within the entities listed in the website’s ads.txt or app-ads.txt file.

“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he asserted.
Edwards maintains that effectively addressing the malvertising and AI slop challenges necessitates greater data-sharing from major ad networks. Specifically, he points to the need for broader dissemination of the "supply chain object" (SCO), structured data appended to each advertising bid request that provides buyers with visibility into every seller, reseller, and intermediary involved in the transmission of an ad impression from the publisher to the final buyer.
“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards elaborated. “You may see the malicious zero-click redirection, but without the supply chain object—which is only served server side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”
DecryptAds also offers an application programming interface (API) that empowers researchers to automate queries and integrate the platform’s capabilities into popular AI tools.
WHAT CAN YOU DO?
Given the alarming examples presented, the most prudent course of action is to block all online ads outright. This strategy is widely recommended by security experts, as it significantly impedes adtech firms and data brokers from constructing detailed profiles and tracking your online and offline activities.
However, the effectiveness of this approach depends largely on your browsing habits and your confidence in third-party browser plugins and extensions. For users who primarily browse on a desktop or laptop computer, uBlock Origin Lite is a highly recommended free, well-maintained, and open-source option. uBlock Origin is also compatible with mobile browsers like Firefox, though apparently only on Android devices.
Adblock Plus serves as a viable option for iPhone and iPad users. Power users will appreciate that both Adblock and uBlock Origin support custom blocking rules from easylist.to, a frequently updated resource that effectively removes most advertisements from web pages.

The established browser extension NoScript blocks all non-approved JavaScript code, generally proving effective at preventing most ads from loading. However, script blockers like NoScript may not be ideal for average users who prefer not to constantly manage which scripts should be permitted to execute for proper website functionality.
For technically inclined and adventurous readers, a hardware-based solution for blocking ads at the local network level offers the most cost-effective, secure, and scalable approach. A compact, low-cost, and widely available computer known as a Raspberry Pi can be transformed into a powerful ad blocker for all devices on a local network when equipped with a microSD memory card and the free program called Pi-hole. Once properly configured and with your router’s network settings updated to utilize Pi-hole’s DNS sinkhole and DHCP servers, it will effectively prevent ads from appearing on any devices connected to that network.
It is important to note that ad blockers often have limited efficacy in blocking ads and/or tracking originating from within mobile apps installed on users’ devices. Many websites now encourage users to install a mobile app, ostensibly to enhance access to and enjoyment of the site’s services and content. However, in my experience, this push is not primarily driven by a superior user experience on the app. On the contrary, I find most mobile apps to be poorly designed, intrusive, and/or entirely unnecessary, and I invariably opt to interact with websites or services directly through a web browser whenever possible.
The stark reality is that major web destinations tend to aggressively promote their apps because they facilitate keeping users engaged on their platforms for extended periods and enable the collection (and often resale) of far more precise data about user demographics, activities, and locations. Moreover, companies that most aggressively push for app installations often automatically opt users into having their data used for training large language models. Therefore, exercise caution regarding the apps you install on your mobile devices (including any smart TVs!), and consult their listings on DecryptAds to gain insights into their privacy practices and any affiliations with adtech firms.

