Unveiling the Adtech Underbelly: How DecryptAds Exposes Global Surveillance, Malvertising, and Geopolitical Risks in Digital Advertising

Executive Overview

For decades, the digital advertising ecosystem has operated behind a veil of complex technical jargon and opaque corporate structures. While everyday internet users browse popular news outlets, play mobile games, or stream video content, a vast, automated supply chain silently harvests location data, device fingerprints, and personal browsing habits. This information flow is governed by files that websites and mobile applications publish publicly—such as ads.txt, app-ads.txt, and sellers.json—yet the sheer volume and fragmentation of these data points have rendered them virtually impossible for ordinary consumers or security analysts to parse manually.

That balance of power is shifting with the launch of DecryptAds (decryptads.com), an open-access intelligence platform designed to scrape, aggregate, and cross-reference digital ad supply-chain data. Spearheaded by cybersecurity researcher Zach Edwards, Chief Research Officer at DecryptAds and a threat researcher at Infoblox, the tool approaches advertising technology not as a marketing engine, but as a critical cybersecurity attack surface.

DecryptAds exposes the startling reach of global ad networks, linking mainstream digital properties to high-risk entities operating out of geopolitical hotspots, including Russia, China, Cyprus, and the United Arab Emirates (UAE). By correlating publicly declared ad-partner files with newly mandated state-level data broker registries, the platform reveals how corporate media brands, military publications, and connected consumer devices are unknowingly woven into surveillance mechanisms, malvertising delivery vectors, and ad-fraud schemes.


Detailed Chronology: The Evolution of Adtech Transparency and Threat Intelligence

+-----------------------------------------------------------------------------------+
| CHRONOLOGY OF ADTECH TRANSPARENCY & THREAT DETECTION                              |
+-----------------------------------------------------------------------------------+
| 2017: IAB Tech Lab introduces `ads.txt` to combat domain spoofing.                |
| 2019–2020: Standard expanded to `app-ads.txt` and `sellers.json` for app ecosystems.|
| 2022: U.S. sanctions financial institutions (e.g., Alfa Bank) post-Ukraine invasion.|
| 2023–2024: State laws (CA, OR, TX, VT) mandate public Data Broker Registries.       |
| July 2026: Security researchers expose H96 TV stick botnet and AI slop ad fraud.  |
| August 2026: DecryptAds launches public engine to correlate adtech & security data.|
+-----------------------------------------------------------------------------------+

The Origins of Authorized Supply Standards (2017–2020)

The framework underpinning modern adtech transparency began in 2017 when the Interactive Advertising Bureau (IAB) Tech Lab introduced ads.txt (Authorized Digital Sellers). Created to prevent domain spoofing—a scam where fraudsters falsely claimed to sell ad inventory on high-profile news sites—the initiative required publishers to host a text file listing every authorized seller of their ad space.

This was soon followed by app-ads.txt for mobile and Connected TV (CTV) ecosystems, as well as sellers.json and the SupplyChain object, which allowed programmatic ad buyers to view every intermediary involved in an ad transaction.

The Obfuscation Era and Regulatory Realignment (2021–2024)

While these standards succeeded in creating a public paper trail, the advertising industry quickly expanded into an unmanageable web of resellers, sub-syndicates, and international data brokers. A single popular domain could list hundreds of authorized partners, creating a massive data footprint that allowed bad actors to hide in plain sight.

Concurrently, legislative shifts in the United States—specifically data broker registration laws enacted in California, Oregon, Texas, and Vermont—forced entities buying and selling personal consumer metrics to register publicly. This legislative paper trail created a critical secondary dataset that, if combined with programmatic ad files, could map the precise flow of sensitive consumer data.

The DecryptAds Breakthrough (August 2026)

Recognizing that individual ads.txt files are functionally useless without centralized cross-referencing, Zach Edwards and two co-founders launched DecryptAds. By continuously scraping, indexing, and correlating millions of programmatic records across web domains, smart TVs, and mobile applications, the platform built the first open security-centric map of the global advertising supply chain.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Supporting Context & Metrics: Case Studies in Adtech Exposure

The structural vulnerabilities of the programmatic advertising ecosystem become clear when examining specific entities analyzed by DecryptAds.

                          +-------------------------+
                          |   Publisher Website     |
                          |     (e.g., ESPN.com)    |
                          +------------+------------+
                                       |
              +------------------------+------------------------+
              |                                                 |
    +---------v----------+                            +---------v----------+
    | 143 Adtech Partners|                            |  19 Data Brokers   |
    +---------+----------+                            +---------+----------+
              |                                                 |
   +----------+----------+                         +------------+------------+
   | High-Risk Geo Nodes |                         | Sensitive Telemetry Scraped |
   | (Russia, China, UAE)|                         | (Location, Fingerprints)   |
   +---------------------+                         +-------------------------+

Mainstream Media Vulnerabilities: The ESPN Blueprint

A baseline query of ESPN.com illustrates the density of modern digital advertising infrastructure:

  • Declared Ad Partners: 143 entities operating across web (ads.txt) and mobile/CTV (app-ads.txt) platforms.
  • Registered Data Brokers: 19 distinct data broker domains.
  • Telemetry Harvesting: Nearly 50% of the declared data brokers harvest precise geolocation data from visitors who do not utilize active ad-blocking tools.
  • Fingerprinting: Three data brokers explicitly declare the collection of unique device fingerprints and sensitive personal information.

Geopolitical Risk and Adversarial Entities

DecryptAds incorporates a Geo-Risk framework, flagging adtech operations hosted in or affiliated with nations posing national security concerns—such as Russia and China—or intermediary privacy havens like Cyprus, Panama, and the United Arab Emirates (UAE).

+-----------------------------------------------------------------------------------+
| CASE STUDY: BETWEEN DIGITAL & MILITARY NEWS DOMAINS                              |
+-----------------------------------------------------------------------------------+
| Target Domains: armytimes.com, airforcetimes.com, defensenews.com, navytimes.com |
| Flagged Ad Entity: Between Digital (Claimed HQ: New York, USA)                    |
| Financial Channel: Publisher payouts processed through Alfa Bank (Moscow, Russia) |
| Sanctions Status: Alfa Bank placed under U.S. Blocking Sanctions (2022)           |
| Network Reach: Active on ~55,000 global publisher websites                        |
+-----------------------------------------------------------------------------------+

A critical finding involves Between Digital, an adtech entity that lists a corporate address in New York but maintains deep operational and financial ties to Russia. DecryptAds’ dossier reveals that Between Digital’s publisher financial offers process payouts through Alfa Bank, Russia’s largest private commercial bank, which was placed under strict U.S. sanctions in 2022 following the invasion of Ukraine.

Despite these sanctions and security risks, Between Digital remains listed as an authorized advertising partner across approximately 55,000 websites worldwide. Notably, these include leading U.S. defense and military publications:

  • armytimes.com
  • airforcetimes.com
  • defensenews.com
  • navytimes.com
  • marinecorpstimes.com
  • federaltimes.com

Furthermore, DecryptAds discovered that Between Digital acts as both a publisher and a reseller on roughly two-thirds of its declared portfolio. This dual role creates a severe structural conflict of interest, enabling an entity to manipulate bidding auctions and route client spending toward its own controlled infrastructure.

The Browser Ecosystem: Opera Software

The analysis extends to software platforms. The Opera web browser, which operates out of headquarters in Oslo, Norway, has been majority-owned by the Chinese firm Kunlun Tech since 2016.

An inspection of opera.com reveals 27 registered data brokers embedded in its network. High-risk regional breakdowns include:

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
  • UAE: 15 adtech partners
  • China: 6 adtech partners
  • Cyprus: 3 adtech partners
  • Russia: 2 adtech partners
  • Hong Kong: 1 adtech partner

These foreign-linked networks constitute 7% of the total adtech relationships declared within Opera’s supply files.

+-----------------------------------------------------------------------------------+
| BROWSER DATA BROKER EXPOSURE: OPERA.COM                                           |
+-----------------------------------------------------------------------------------+
| Foreign-Linked Partners: 27 Data Brokers (7% of total declared ad network)       |
| Regional Breakdown: UAE (15) | China (6) | Cyprus (3) | Russia (2) | HK (1)        |
+-----------------------------------------------------------------------------------+

The Malvertising Engine: AI Slop and Hardware Exploitation

The platform’s Legal Dossier feature provides critical cross-investigative capabilities. In mid-2026, threat researchers at Bitsight uncovered a massive ad-fraud network linked to cheap H96 Android TV streaming sticks. These devices silently turned consumer internet connections into residential proxies while running background scripts that mimicked mobile phones clicking on AI-generated content farms ("AI slop").

DecryptAds linked these malicious operations directly to commercial ad networks:

  1. A dormant domain from the fraudulent Fengwo Group (medicalbeautyhub[.]com) was queried via DecryptAds.
  2. The search linked the site to Seller ID 1674071, shared with a low-tier gaming portal (giacoloredstones[.]com).
  3. Pivoting on an interconnected seller ID (103488000) uncovered hundreds of active domains operating within Russia’s Yandex advertising network. These sites were specifically engineered to display low-quality utilities and AI-generated text designed solely to run automated ad impressions.
+-----------------------------------------------------------------------------------+
| FRAUD CHAIN: H96 STREAMING STICKS TO RUSSIAN AD EXCHANGES                         |
+-----------------------------------------------------------------------------------+
| Infected Hardware: H96 TV Sticks (Residential Proxy / Mobile Phone Spoofing)      |
| Target Destination: AI Slop Domain (medicalbeautyhub[.]com)                       |
| Shared Seller ID 1: 1674071 ---> Intermediary Domain (giacoloredstones[.]com)     |
| Shared Seller ID 2: 103488000 ---> Hundreds of Yandex-linked ad-farm domains       |
+-----------------------------------------------------------------------------------+

Official Statements & Threat Research Insights

Zach Edwards on Security vs. Marketing Architecture

Speaking on the launch of the project, Zach Edwards emphasized that the industry’s failure to audit adtech files has allowed security risks to multiply.

"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards stated. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Edwards noted that supply-chain compromises are rarely visible within a single, isolated file:

"Supply-chain integrity issues rarely live in a single file," the DecryptAds analytical methodology explains. "They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

On the Mechanisms of Malvertising and AI Slop

Addressing why malicious advertisements—often delivering zero-click exploits or malware payloads—frequently bypass legacy filters, Edwards pointed to the proliferation of low-quality, machine-generated websites.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"None of these slop AI content farms are paying for protective third-party security verification," Edwards explained. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on high-tier news outlets, but rather on some lower quality content farm that a user reached via a search engine query."

+-----------------------------------------------------------------------------------+
| THE MALVERTISING DELIVERY VECTOR                                                 |
+-----------------------------------------------------------------------------------+
| [User Search Query]                                                               |
|        |                                                                          |
|        v                                                                          |
| [AI Slop Content Farm] ---> (No Third-Party Ad Verification / Low Security Budget)|
|        |                                                                          |
|        v                                                                          |
| [Unvetted Ad Exchange] ---> (Serves Malicious Payload / Zero-Click Exploit)       |
+-----------------------------------------------------------------------------------+

The Industry Blindspot: "Quiet Removals"

A major vulnerability exposed by DecryptAds is the ad industry’s habit of handling fraud silently. When an ad exchange discovers an ad network engaged in invalid traffic or malware injection, it typically removes the entity from its sellers.json file without issuing a public alert.

Edwards noted that this secrecy leaves other exchanges vulnerable:

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients without making it public. The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. DecryptAds features a Quiet Removals Feed to log these removals in real-time so security analysts can track malicious actors hopping between exchanges."


Future Outlook & Strategic Defenses

The Imperative for Supply Chain Objects (SCO)

Looking ahead, cybersecurity researchers argue that fully securing the adtech supply chain will require mandatory public exposure of the Supply Chain Object (SCO). The SCO is a piece of structured data attached to real-time bidding requests that records every intermediary handling an ad impression.

Currently, major ad exchanges restrict access to SCO data, reserving it for server-side transactions. Edwards contends that opening SCO data to security researchers is necessary to stop high-level cyber threats:

"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government personnel with zero-click payloads on an almost daily basis. The SCO tells you who sold it, who resold it, and who was the final entity that bought the impression that served that malware payload. If we can encourage the adtech industry to expose that SCO, identifying the source of malicious ads will become far easier."


Comprehensive Defensive Recommendations

To mitigate privacy risks and shrink the attack surface exposed by adtech networks, security professionals advise a defense-in-depth strategy covering software, network, and device hygiene.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
+-----------------------------------------------------------------------------------+
| MULTI-LAYERED ADTECH DEFENSE MATRIX                                              |
+-----------------------------------------------------------------------------------+
| LAYER 1: Browser Extension Level                                                  |
|   • uBlock Origin Lite (Content Filtering & Tracking Protection)                  |
|   • NoScript (Selective JavaScript Execution Control)                             |
|                                                                                   |
| LAYER 2: Local Network Sinkholing                                                 |
|   • Pi-hole DNS Sinkhole (Raspberry Pi/Local Server)                              |
|   • Global Blocklists (EasyList / EasyPrivacy Domain Filters)                     |
|                                                                                   |
| LAYER 3: Application Hygiene & Device Isolation                                   |
|   • Reject redundant mobile app conversions; use privacy-focused mobile web.      |
|   • Audit Smart TV, CTV, and IoT device app permissions and network outbound DNS. |
+-----------------------------------------------------------------------------------+

1. Browser-Level Filtering

For desktop and mobile environments, content blockers significantly diminish telemetry harvesting:

  • uBlock Origin Lite: An efficient, open-source content blocker designed for modern browser extension architectures. It systematically prevents tracking scripts and unauthorized ad networks from executing.
  • NoScript: A high-security browser extension that blocks all unapproved JavaScript execution. While effective against malvertising payloads, it requires active management by the user to ensure legitimate site functionality.
  • Custom Filter Lists: Implementing rulesets from repositories like easylist.to helps maintain up-to-date domain blocklists.

2. Network-Wide DNS Sinkholing

To protect smart TVs, IoT hardware, and mobile devices that do not support browser extensions, network-level ad blocking offers a robust hardware-based defense:

  • Pi-hole Deployment: Installing Pi-hole on a low-cost computer (such as a Raspberry Pi) creates a centralized DNS sinkhole.
  • Router Configuration: Routing all local network DNS queries through the Pi-hole automatically drops outbound requests to known ad servers, data brokers, and tracking domains across every device on the network.

3. Mobile and Smart Device Hygiene

The adtech ecosystem aggressively encourages users to transition from traditional web browsers to standalone mobile and Smart TV apps. Native apps bypass browser-based blocking tools, giving operators access to raw device identifiers, precise geolocation data, and local hardware state metrics.

Security best practices for application management include:

  • Prefer Mobile Web: Access online services through a privacy-focused browser rather than installing single-purpose native mobile applications.
  • Audit Smart TV Firmware: Restrict internet access for Smart TVs and streaming boxes that run unverified software or bundled free streaming apps.
  • Pre-Install Vetting: Use platforms like DecryptAds to inspect the app-ads.txt declarations of mobile and connected apps before installation to audit their underlying data-sharing pipelines.

Leave a Reply

Your email address will not be published. Required fields are marked *