Unmasking the Invisible Tracker: How DecryptAds Exposes the Hidden Cyber Risks of Modern Adtech

Executive Overview

For over two decades, the global digital advertising ecosystem has operated behind an opaque curtain. While millions of web users interact daily with mainstream news outlets, streaming services, and mobile applications, a labyrinthine infrastructure of data brokers, supply-side platforms (SSPs), and ad exchanges silently tracks user behavior, harvests sensitive telemetry, and executes real-time auctions for targeted ad placements. Historically, the internal mechanics of this massive surveillance apparatus were locked away inside proprietary ad-bidding platforms, leaving cybersecurity analysts, privacy researchers, and ordinary consumers in the dark.

That dynamic has fundamentally shifted with the launch of DecryptAds (decryptads.com), a specialized, free security intelligence platform designed to scrape, aggregate, and cross-reference public adtech declaration files. Developed by veteran threat researcher Zach Edwards alongside a team of cybersecurity experts, DecryptAds transforms fragmented, raw metadata—such as ads.txt, app-ads.txt, buyers.json, and sellers.json—into actionable cyber threat intelligence.

By systematically correlating these datasets, DecryptAds brings to light critical supply-chain vulnerabilities, including foreign espionage risks, unauthorized data brokering, malvertising vectors, and complex fraud schemes operating across AI-generated content farms. The platform’s initial findings reveal alarming threat profiles: defense news publications harboring Russian ad networks linked to sanctioned financial institutions, major media entities unknowingly funneling user location data to registered data brokers, and mobile app ecosystems serving as vectors for zero-click malvertising payloads.


Detailed Chronology

+-----------------------------------------------------------------------------------+
|                            EVOLUTION OF ADTECH TRANSPARENCY                       |
+-----------------------------------------------------------------------------------+
|  2017: IAB Tech Lab introduces `ads.txt` to curb ad spoofing                      |
|  2019: `app-ads.txt` and `sellers.json` launched to expand supply-chain auditability|
|  2022: U.S. sanctions Russian financial institutions, including Alfa Bank         |
|  2024: Four U.S. states implement mandatory data broker registration mandates     |
|  2026: Launch of DecryptAds; researchers uncover high-risk adtech vectors        |
+-----------------------------------------------------------------------------------+

The Evolution of Public Adtech Declarations

To understand the breakthrough represented by DecryptAds, one must first trace the history of advertising supply-chain governance. In 2017, the Interactive Advertising Bureau (IAB) Tech Lab introduced ads.txt (Authorized Digital Sellers) as a mechanism to combat domain spoofing and inventory fraud. Publishers posted a simple text file on their web servers listing every entity authorized to sell their ad space. This was later complemented by app-ads.txt for mobile and smart TV applications, as well as sellers.json and buyers.json files published by ad exchanges to identify intermediary brokers.

While intended to establish transparency, these files quickly ballooned into unmanageable text files containing thousands of disorganized domain names and alphanumeric account IDs. For years, individual files provided minimal security utility because threat actors could easily exploit broken cross-references, fake reseller declarations, and opaque intermediary chains without detection.

The Inception and Launch of DecryptAds

Recognizing that individual declaration files were functionally useless without systemic cross-referencing, Zach Edwards—Chief Research Officer for DecryptAds and senior threat researcher at cybersecurity firm Infoblox—co-founded DecryptAds with two fellow security researchers. The platform was built from the ground up to approach adtech not through a marketing lens, but as a critical supply-chain attack surface.

Who’s Tracking You? Use This New Service to Find Out

Upon its public launch, DecryptAds deployed automated scrapers to continuously ingest and map adtech authorization files from millions of websites and mobile applications globally. The platform introduced specialized diagnostic tools, including:

  • Geo-Risk Analysis: Automated geolocation mapping to flag adtech vendors operating out of adversarial jurisdictions or secrecy havens.
  • Legal Dossier Lookup: Deep-dive domain and entity research modules capable of mapping hidden corporate relationships, registration histories, and infrastructure ownership.
  • Quiet Removals Feed: Real-time tracking of ad sellers silently purged from sellers.json files by ad exchanges attempting to cover up fraudulent or malicious activity.

Uncovering Foreign Espionage Vectors in Defense and Mainstream Media

Immediately following its release, DecryptAds began exposing major structural vulnerabilities in corporate and national security media assets. An analysis of major military news portals—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—revealed that these military-focused sites routinely permit high-risk adtech intermediaries to track visitors and run ad scripts.

Chief among these entities was Between Digital, an adtech network displaying a domestic address in New York but operating heavily out of Russia. DecryptAds’ forensic dossier revealed that Between Digital’s publisher offers process financial settlements through Alfa Bank, Russia’s largest private commercial bank, which was placed under strict U.S. financial sanctions in 2022 following Russia’s invasion of Ukraine. Between Digital was found to be maintaining ad-data collection capabilities across approximately 55,000 partner websites worldwide.

Similarly, an audit of sports media powerhouse espn.com uncovered 143 authorized advertising partners and 19 registered data brokers embedded within its code base. Four of these partners originated from high-risk jurisdictions, including Russia, China, and the United Arab Emirates (UAE).

Tracking Fraud Networks: From Smart TV Exploits to AI Slop Farms

DecryptAds’ analytical capability was further demonstrated when cross-referenced against independent investigations into ad fraud. Research conducted by cybersecurity firm Bitsight recently uncovered a major fraud operation involving H96 Android-based TV streaming sticks. These low-cost devices were found secretly renting out residential Internet connections and spoofing mobile phones to simulate non-existent clicks on low-quality, AI-generated "slop" websites operated by a Chinese entity known as the Fengwo Group.

Using DecryptAds’ Legal Dossier feature, researchers traced one of the Fengwo Group’s primary ad-landing domains—medicalbeautyhub[.]com—to a shared seller ID (1674071). Pivoting on this ID revealed connections to gaming portal giacoloredstones[.]com, which tied directly into seller ID 103488000. A broader query of that ID exposed hundreds of active domains operating within Russia’s Yandex ad network, all running low-grade utility and gaming templates designed exclusively to extract ad revenue via automated device spoofing.

Who’s Tracking You? Use This New Service to Find Out

Supporting Context & Metrics

The Scale of Data Broker Penetration

The risk posed by adtech vectors is compounded by state-level legislative shifts. Recent privacy statutes passed in California, Oregon, Texas, and Vermont now mandate that commercial data brokers explicitly register their operations. Data ingested by DecryptAds illustrates the vast extent to which mainstream digital properties leak user telemetry to these entities:

Media Property / Platform Total Declared Ad Partners Registered Data Brokers High-Risk Geo-Jurisdictions Identified Key Data Telemetry Harvested
ESPN.com 143 19 Russia, China, UAE Geolocation (47%), Device Fingerprints, Sensitive Personal Info
Military Times Network 100+ Multiple Russia, UAE, Panama Device Telemetry, Military Community Browsing Patterns
Opera Web Browser 300+ 27 UAE (15), China (6), Cyprus (3), Russia (2) Cross-Platform Tracking, IP & Behavioral Identifiers

As highlighted in the data, nearly half of the data brokers attached to espn.com harvest precise geolocation coordinates from users who do not actively run ad-blocking software, while several others collect persistent device fingerprints and sensitive personal attributes.

+-----------------------------------------------------------------------------------+
|                        ESPN.COM DATA BROKER TELEMETRY EXPOSURE                    |
+-----------------------------------------------------------------------------------+
| [47% of Brokers]  =========> Harvests Precise Geolocation Data                    |
| [16% of Brokers]  ===> Harvests Device Fingerprints & Sensitive Info              |
| [37% of Brokers]  ======> General Telemetry & Behavioral Analytics                |
+-----------------------------------------------------------------------------------+

Conflict of Interest: The Publisher-Reseller Paradox

One of the key technical metrics surfaced by DecryptAds is the prevalence of self-dealing within intermediary ad networks. In the case of Between Digital, an analysis of its public app-ads.txt declarations revealed that the firm acts as both a publisher and a reseller on roughly two-thirds of its indexed domain portfolio.

In programmatic auctions, acting simultaneously on the buy-side and sell-side represents a severe conflict of interest. Ad networks operating in this dual capacity can artificially direct corporate advertising budgets toward their own owned-and-operated properties or shadow infrastructure, creating ideal conditions for arbitrary bid manipulation, wash-trading of ad inventory, and unchecked malvertising distribution.

The Missing Security Element: Supply Chain Objects (SCO)

A fundamental reason why malvertising and ad fraud persist lies in the architectural limits of client-side web visibility. In modern programmatic advertising, real-time bidding (RTB) auctions utilize a structured data block known as the Supply Chain Object (SCO). Attached to each server-side auction bid, the SCO acts as a digital ledger, recording every seller, reseller, and financial intermediary involved in passing an ad impression from the host website to the final advertiser.

+-----------------------------------------------------------------------------------+
|                         PROGRAMMATIC AD AUCTION SUPPLY PATH                       |
+-----------------------------------------------------------------------------------+
|  [Publisher Site]  --->  [Supply-Side Platform]  --->  [Ad Exchange / Reseller]    |
|                                                                |                  |
|  [Malware Payload] <---  [Demand-Side Platform] <---  [Ad Intermediary (SCO)]    |
+-----------------------------------------------------------------------------------+

Currently, major ad exchanges keep SCO logs strictly server-side, withholding them from public security researchers. When a zero-click exploit or drive-by malware download strikes a user, cybersecurity incident responders can see the malicious payload executed in the browser, but cannot trace the financial chain responsible for buying the placement. DecryptAds is advocating for broad adtech industry reform to mandate public SCO disclosure, enabling threat intelligence teams to instantly identify the precise entity that purchased a malicious ad slot.

Who’s Tracking You? Use This New Service to Find Out

Official Statements

Zach Edwards on Security-Centric Adtech Analysis

Speaking on the core philosophy driving the creation of DecryptAds, Zach Edwards, Chief Research Officer at DecryptAds and Threat Researcher at Infoblox, emphasized the long-standing blind spot within enterprise security operations:

"It’s an adtech tool, but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved. Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

Edwards further expanded on the mechanics of ad fraud, malvertising, and the industry’s systemic failure to share intelligence publicly:

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients, and they won’t make it public. The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

Addressing the pivot of malicious actors away from major web publishers and toward AI-generated slop farms, Edwards noted:

"None of these slop AI content farms are paying for ad verification or threat protection. They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on high-profile news domains, but rather on some lower quality content farm that someone visited because it came up in a search result."

Who’s Tracking You? Use This New Service to Find Out

"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis. You may see the malicious zero-click redirection, but without the Supply Chain Object—which is only served server side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad."

Industry Outreach & Responses

Journalists and security researchers reached out for comment to key entities highlighted in DecryptAds’ analytical filings:

  • Between Digital: Inquiries were sent to Between Digital’s executive leadership regarding its NY corporate footprint, Russian infrastructure ties, and financial clearing arrangements through the sanctioned Alfa Bank. No formal response was provided prior to publication.
  • Adtech Platforms & Exchanges: Inquiries regarding silent deletions logged in the Quiet Removals Feed yielded standard corporate statements citing non-disclosure agreements and proprietary threat-monitoring protocols as reasons for withholding public disclosures when removing fraudulent sellers.

Future Outlook

The Convergence of Adtech Mapping and Threat Intelligence

The launch of DecryptAds marks a turning point in how threat intelligence operations assess perimeter risk. As digital transformation forces enterprises, government bodies, and defense personnel to interact continuously with web-based resources, the advertising ecosystem can no longer be ignored as an peripheral marketing concern. It is a critical vector for foreign intelligence gathering, corporate espionage, and automated malware delivery.

DecryptAds is expanding its platform capabilities by offering structured Application Programming Interfaces (APIs). These APIs allow enterprise Security Operations Centers (SOCs) and Automated Threat Intelligence platforms to programmatically query adtech risk scores, ingest high-risk domain feeds, and automatically correlate outbound network traffic against known malvertising networks and foreign-controlled ad brokers.

+-----------------------------------------------------------------------------------+
|                     FUTURE ADTECH THREAT DEFENSE FRAMEWORK                        |
+-----------------------------------------------------------------------------------+
|  [DecryptAds API Engine]  ===>  Automated Query Ingestion                         |
|                                       |                                           |
|  [Enterprise SOC / SIEM]  <===  Cross-Correlated Threat Feeds & Geo-Risk Alerts  |
|                                       |                                           |
|  [Network Edge Blocking]  <===  DNS Sinkholing (Pi-hole) / Endpoint Rules (uBlock) |
+-----------------------------------------------------------------------------------+

Defensive Blueprint: Defensive Countermeasures for Organizations and Individuals

Given the slow pace of systemic adtech regulation, cybersecurity authorities strongly advise organizations and individuals to adopt aggressive defensive posture controls to mitigate adtech tracking and zero-click malvertising vectors.

1. Software-Based Endpoint Protection

  • Open-Source Ad Blockers: Deploying well-maintained, open-source browser extensions such as uBlock Origin Lite or Adblock Plus effectively strips out tracking scripts and prevents connection attempts to unauthorized ad servers. For advanced users, integrating custom filter lists from EasyList (easylist.to) provides updated protection against emerging tracking domains.
  • Script Management: Utilizing extensions like NoScript blocks unauthorized JavaScript execution entirely. While requiring manual configuration by end-users, script blocking eliminates the vast majority of drive-by download vectors.

2. Network-Level DNS Sinkholing

  • Hardware Interception: For enterprise remote offices and security-conscious home networks, hardware-level DNS filtering offers robust protection. Implementing a Raspberry Pi configured with Pi-hole creates a centralized DNS sinkhole. By redirecting network router settings to route all outbound DNS queries through the Pi-hole, every connected device—including IoT hardware, mobile phones, and smart TVs—is protected from communicating with known ad networks, telemetry gatherers, and data brokers.

3. Mobile Application and IoT Hygiene

  • App Containment: Mobile applications regularly bypass web-browser privacy controls, extracting precise location data, Wi-Fi network identifiers, and mobile advertising IDs (MAIDs) directly from the operating system. Furthermore, developers increasingly build aggressive data-collection agreements into app terms of service, frequently leveraging user telemetry to train commercial Large Language Models (LLMs). Security professionals recommend limiting mobile application installations, rejecting unnecessary permissions, and conducting all sensitive web browsing exclusively within hardened web browsers rather than dedicated native applications.

As tools like DecryptAds continue to illuminate the dark corners of programmatic advertising, the industry faces an ultimatum: embrace structural transparency and open auditability, or risk total blockading by a cybersecurity community increasingly unwilling to accept the unmitigated risks of modern adtech.

Leave a Reply

Your email address will not be published. Required fields are marked *