The digital advertising ecosystem, a complex web of entities determining which ads appear on websites and which data is harvested from mobile applications, has long been opaque. While some of this information is publicly available, it has traditionally been fragmented and difficult to interpret, largely residing within the control of major advertising platforms. This landscape is now being illuminated by DecryptAds, a powerful, free service that systematically scrapes and correlates adtech data, making it significantly easier to understand who is tracking your online activities.
Decryptads.com, which recently launched, continuously scans publicly accessible files from websites and mobile applications to identify the companies authorized to display advertisements or collect user data. These crucial files include:
- ads.txt: Lists all adtech companies and data brokers permitted to serve ads or collect data from a website.
- app-ads.txt: Identifies entities authorized to harvest data from or display ads on mobile and smart TV applications.
- buyers.json/sellers.json: Details the entities involved in buying, selling, or reselling advertising inventory for a specific site or app.
Zach Edwards, Chief Research Officer for DecryptAds and a threat researcher at Infoblox, explained that the service was developed out of a necessity to consolidate and cross-reference this adtech data, which is only truly valuable when viewed in a comprehensive manner. "It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards stated. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Edwards highlighted that DecryptAds can be instrumental in tracking the origins of malicious ads designed to distribute malware, identifying ad networks operating in adversarial nations, and detecting the proliferation of AI-generated "slop" websites and applications. The service underscores that these potential security and privacy threats are virtually impossible to discern by examining individual ads.txt or app-ads.txt files in isolation. As the DecryptAds blog notes, "Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."
A deep dive into espn.com via DecryptAds reveals a substantial network of 143 ad partners and 19 registered data broker domains listed in its ads.txt and app-ads.txt files. The increasing availability of data broker information is partly due to recent legislation in California, Oregon, Texas, and Vermont, which mandates data brokers to register if they trade consumer data originating from those states. DecryptAds reports that nearly half of these data brokers are collecting geolocation data from espn.com visitors who are not employing ad blockers, while three others explicitly state their collection of device fingerprints and sensitive personal information.
HIGH-RISK AD PARTNERS
DecryptAds also flags adtech partners located in "geo-risk" regions, such as China and Russia, or countries with significant ties to them, like Cyprus and the United Arab Emirates (UAE). This feature provides a conspicuous warning about potential security risks.
According to DecryptAds, espn.com collaborates with four advertising entities based in Russia, China, or the UAE. One such firm, Between Digital, lists a New York address but is flagged by DecryptAds as a Russian entity. Its publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank, which is under U.S. sanctions. KrebsOnSecurity has reached out to Between Digital for comment.

A review of several prominent U.S. military news websites, including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com, reveals that they all permit Between Digital to serve ads and track users. Additionally, they engage with two entities in the UAE and one in Panama, a known haven for ownership secrecy. DecryptAds indicates that Between Digital collects ad data from approximately 55,000 partner websites.
Between Digital’s app-ads.txt file exposes hundreds of websites featuring simple web-based games heavily interspersed with ads. Edwards noted that Between Digital’s own disclosures indicate they act as both a publisher and reseller for roughly two-thirds of their portfolio. "It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards explained. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."
Opera, a widely used web browser, has been majority-owned by the Chinese company Kunlun Tech since 2016, though its operational headquarters remain in Oslo, Norway. DecryptAds profiles Opera.com as having 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. However, these represent only seven percent of Opera.com’s total adtech partners listed in its ads.txt and app-ads.txt files.
LEGAL DOSSIERS
The Legal Dossier feature on DecryptAds is a deep dive into ownership and relationships. Though searches can take several minutes, they yield extensive information about domain and app ownership, registration dates, and any associated aliases or connections to adtech companies and other digital entities.

This feature proved invaluable when examining the H96 TV streaming sticks, previously reported by Bitsight researchers to be renting out user internet connections and spoofing themselves as mobile phones to click on ads. Bitsight identified the Fengwo Group, a Chinese company responsible for malicious apps on these sticks, as also operating the network of ads and AI "slop" websites being clicked by these devices.
A DecryptAds legal dossier on a Fengwo Group domain, medicalbeautyhub.com, reveals it shares a seller ID with a gaming website, giacoloredstones.com. This latter site features another seller ID that, when explored, links to hundreds of websites within Russia’s Yandex ad system, primarily featuring low-quality games or utilities laden with ads.
QUIET REMOVALS
Edwards described a common practice in the adtech industry where advertising networks discreetly remove advertisers suspected of fraudulent activity or malicious ads without public notification. This lack of transparency allows problematic adtech firms to evade accountability. DecryptAds addresses this by offering a "Quiet Removals Feed," which aggregates and correlates seller.json removals across ad exchanges for the same seller domain or name. "The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards stated. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."
MALVERTISING AND AI SLOP
Malvertising, the distribution of malware or redirection to phishing pages via malicious ads, remains a significant threat. However, Edwards noted that these attacks are increasingly prevalent on newer AI-generated "slop" websites rather than high-traffic destinations, which typically employ robust defenses against malicious ads. "None of these slop AI content farms are paying for that kind of protection," he said. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search."
These AI-generated sites, filled with machine-generated content on diverse topics, often lack the security measures to prevent malvertising. Edwards suggested that organizations targeted by malicious ads often overlook the solution readily available within the website’s ads.txt or app-ads.txt files. "A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis," he asserted.
Edwards advocates for greater data sharing from major ad networks, particularly concerning the "supply chain object" (SCO). This structured data, attached to ad bid requests, details every seller, reseller, and intermediary in the ad impression delivery chain. "That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload," Edwards explained. "You may see the malicious zero-click redirection, but without the supply chain object – which is only served server side – you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad." DecryptAds also offers an API for researchers to automate queries and integrate its functionality into AI platforms.

WHAT CAN YOU DO?
The most effective way to mitigate these tracking and malvertising risks is to block all online ads. Security experts widely endorse this approach as it significantly hinders adtech firms and data brokers from constructing detailed user profiles and tracking online movements.
For desktop and laptop users, uBlock Origin Lite is a highly recommended free, open-source ad blocker. It is also compatible with mobile browsers like Firefox on Android. Adblock Plus is a suitable option for iPhone and iPad users. Both uBlock Origin and Adblock Plus support custom blocking rules from easylist.to, a regularly updated list that effectively removes most advertisements.
NoScript, a browser extension that blocks non-approved JavaScript code, can also be effective, though it may require more user intervention to ensure websites function correctly.
For a more comprehensive, network-wide solution, a Raspberry Pi can be configured with Pi-hole to act as a powerful ad blocker for all devices on a local network. This hardware-based approach is cost-effective and scalable.
It’s important to note that ad blockers often have limited efficacy against ads and tracking within mobile applications. Many websites encourage app downloads for enhanced services, but this often facilitates more extensive data collection and profiling. Users are advised to be cautious about app installations and to utilize services like DecryptAds to investigate their privacy practices and adtech affiliations, including those on smart TVs.

