Unveiling the Shadow Economy: How DecryptAds Exposes Global Adtech Supply Chain Risks, Malvertising, and AI Slop Operations

Executive Overview

For over two decades, the global programmatic advertising ecosystem has functioned as a hyper-complex, opaque marketplace. Every millisecond, billions of automated auctions dictate which advertisements appear on mobile screens, desktop browsers, and smart televisions across the globe. Concurrently, an sprawling network of data brokers, supply-side platforms (SSPs), demand-side platforms (DSPs), and obscure intermediaries harvest granular telemetry on user behavior, physical locations, and device profiles.

While much of the foundational structural data governing these ad networks is technically public—embedded within standardized root-directory files on web servers—it has historically remained effectively inaccessible to journalists, cybersecurity researchers, and privacy regulators due to its vast scale and fragmented distribution.

This paradigm of structural opacity has shifted with the launch of DecryptAds (decryptads.com), a free intelligence platform designed to scrape, cross-reference, and analyze adtech disclosures at scale. Spearheaded by Zach Edwards, Chief Research Officer at DecryptAds and threat researcher at Infoblox, along with two co-founders, the platform transforms disconnected web manifest files into dynamic threat intelligence dossiers.

By applying cybersecurity methodologies to digital supply chain data, DecryptAds exposes systemic vulnerabilities in online advertising. The platform’s disclosures highlight severe security risks, including:

  • Top-tier news sites maintaining advertising pipelines linked to sanctioned foreign financial institutions.
  • Widespread surveillance by unregistered data brokers.
  • The rapid monetization of artificial intelligence "slop" websites used as engines for fraud and malvertising.

Detailed Chronology: The Evolution of Adtech Transparency

Understanding the modern adtech attack surface requires tracing how programmatic declaration standards evolved from digital anti-fraud measures into complex, unpoliced data silos.

+-----------------------------------------------------------------------------------+
|                            EVOLUTION OF ADTECH TRANSPARENCY                       |
+-----------------------------------------------------------------------------------+
|                                                                                   |
|  2017: IAB Releases ads.txt                                                       |
|  * Designed to curb domain spoofing by declaring authorized ad sellers.            |
|                                                                                   |
|  2019: IAB Expands Standards (app-ads.txt & sellers.json)                         |
|  * Extends publisher declarations to mobile apps, Smart TVs, and supply chains.   |
|                                                                                   |
|  2022–2024: State Data Broker Mandates Take Effect                                |
|  * Laws in CA, OR, TX, and VT force data brokers to publicly register.            |
|                                                                                   |
|  2026: Launch of DecryptAds & Emergence of AI Slop Networks                       |
|  * Centralizes fragmented manifest files to detect malvertising and geo-risks.   |
|                                                                                   |
+-----------------------------------------------------------------------------------+

Phase 1: The Pre-Declaration Era and Domain Spoofing (Pre-2017)

In the early days of real-time bidding (RTB), malicious actors routinely impersonated high-profile news outlets to divert advertising budgets into rogue websites. Advertisers believed they were buying ad space on premium publications when, in reality, their campaigns were serving on hidden or fraud-ridden web pages.

Phase 2: The Push for Standardized Declarations (2017–2019)

To combat domain spoofing, the Interactive Advertising Bureau (IAB) Tech Lab introduced ads.txt (Authorized Digital Sellers) in 2017, followed by app-ads.txt for mobile and Connected TV (CTV) environments in 2019. These flat text files, hosted publicly at the root of a publisher’s domain, explicitly list the entities authorized to sell or resell the site’s digital inventory. To increase transparency further down the transaction chain, the IAB subsequently introduced sellers.json and buyers.json, requiring ad exchanges to declare the operational identity and domain names of their platform participants.

Phase 3: The Assembly of Unpoliced Data Silos (2020–2025)

While these declarations were meant to clean up the ad supply chain, they quickly spiraled out of control. Large publishers routinely added hundreds of reseller IDs to avoid missing out on ad revenue, creating dense networks that nobody audited. Weaponized by malicious actors, these bloated manifests turned into vectors for malvertising, data harvesting, and arbitrage. During this era, four U.S. states—California, Oregon, Texas, and Vermont—enacted pioneer data broker registration laws, forcing entities trading consumer data to disclose their operational domains publicly.

Phase 4: Aggregation and Threat Intelligence (2026)

Despite state-level disclosures and public manifest files, tracking ad-network relationships across millions of domains remained nearly impossible without enterprise infrastructure. The launch of DecryptAds addresses this gap by continuously ingesting, parsing, and linking ads.txt, app-ads.txt, sellers.json, and state data broker registries. The platform elevates adtech auditing from a passive administrative task to an active cyber threat hunting discipline.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Supporting Context & Technical Metrics

The structural architecture of modern digital advertising relies on a delicate network of text-based declarations. When analyzed individually, a single file provides negligible visibility. When correlated across millions of domains, it exposes systematic abuses of supply-chain integrity.

       +-------------------------------------------------------------+
       |                  Publisher Domain (e.g., website)           |
       +------------------------------+------------------------------+
                                      |
                                      v
       +-------------------------------------------------------------+
       |                    Root Declaration Files                   |
       |  - ads.txt / app-ads.txt: Authorized sellers & brokers      |
       +------------------------------+------------------------------+
                                      |
                                      v
       +-------------------------------------------------------------+
       |                      Adtech Exchanges                       |
       |  - sellers.json / buyers.json: Intermediary supply pathways   |
       +------------------------------+------------------------------+
                                      |
                                      v
       +-------------------------------------------------------------+
       |                   DecryptAds Ingestion Engine               |
       |  - Cross-references declarations, data broker registries,    |
       |    and geographic risk profiles to surface threats          |
       +-------------------------------------------------------------+

The Ingestion Framework: Key Adtech File Mechanics

  • ads.txt / app-ads.txt: Served directly from a domain’s root folder (e.g., example.com/ads.txt), these documents explicitly define which exchange accounts are authorized to sell a publisher’s ad inventory.
  • sellers.json: Maintained by ad exchanges and supply-side platforms, this JSON file identifies the owners of the seller IDs listed in ads.txt files, categorizing them as direct publishers, intermediaries, or tech vendors.
  • Supply Chain Object (SCO): A structured metadata payload embedded server-side within OpenRTB bid requests. The SCO traces the exact step-by-step path an impression takes from the publisher through every reseller to the winning bidder.

Case Study: High-Volume Publishers and Geopolitical Exposure

To demonstrate how easily tracking and advertising networks expand without oversight, DecryptAds indexed the public manifest files of top-tier media properties. The findings illustrate a stark contrast between user interface simplicity and back-end supply-chain complexity.

Target Entity / Publisher Total Ad Partners Declared Registered Data Brokers High-Risk Geographic Links Notable Supply Chain Anomalies
espn.com 143 19 4 entities (Russia, China, UAE) 50% harvest location data; 3 collect device fingerprints; partnerships with Between Digital.
U.S. Defense News Sector (ArmyTimes, DefenseNews, NavyTimes, etc.) Variable (100+) Multiple Russia, China, UAE, Panama Between Digital permitted to serve ads across 6 military news domains targeting defense personnel.
Opera.com Hundreds 27 UAE (15), China (6), Cyprus (3), Russia (2) Foreign entities make up ~7% of its total footprint; parent ownership via China’s Kunlun Tech.
                              ESPN.COM ADTECH EXTRACT
                                143 Ad Partners
                                      |
         +----------------------------+----------------------------+
         |                                                         |
 19 Data Brokers                                            4 Geo-Risk Partners
         |                                                         |
         +--> 50% Harvest Geolocation                              +--> Russia (Between Digital)
         +--> 3 Collect Device Fingerprints                        +--> China
         +--> Sensitive Personal Info                              +--> United Arab Emirates

The presence of Between Digital across both mainstream outlets like ESPN and specialized military journalism hubs (e.g., Army Times, Air Force Times, Navy Times, Marine Corps Times, Defense News, and Federal Times) underscores a key geopolitical risk.

While Between Digital lists a business address in New York, DecryptAds’ deep-dive intelligence dossiers reveal that the firm’s publisher payouts are routed through Alfa Bank—Russia’s largest private commercial bank. Alfa Bank was placed under strict U.S. sanctions in 2022 following Russia’s invasion of Ukraine. Consequently, ad inventory serving across critical military news portals directly interfaces with financial pipelines bound to a sanctioned state-backed banking ecosystem.

The Problem of Dual-Role Arbitrage

Pivoting on Between Digital’s app-ads.txt mapping reveals hundreds of simple web-based gaming domains that frequently interrupt gameplay with advertisements. Crucially, Between Digital appears as both a publisher and a reseller on roughly two-thirds of its declared portfolio.

This dual designation allows a single adtech company to operate on both sides of an automated ad auction. By functioning simultaneously as the buyer’s agent and the seller’s agent, the entity can redirect client ad budgets toward its own owned-and-operated inventory. This creates structural conflicts of interest and facilitates untraceable ad-budget diversion.

High-Risk Entities and Geographic Profiling

DecryptAds actively categorizes ad networks operating out of regions flagged for geopolitical and financial secrecy risk, designated as "geo-risk" zones. Key focal points include:

  1. Russian Federation: Associated with high-volume malvertising vectors, state-aligned data harvesting, and financial settlement channels operating under international sanctions.
  2. People’s Republic of China: High concern regarding software development kits (SDKs) and browser platforms capable of exfiltrating telemetry to foreign jurisdictions.
  3. Cyprus and the United Arab Emirates (UAE): Strategic financial hubs used to obscure ultimate beneficial ownership (UBO) while operating intermediaries inside Western ad exchanges.
  4. Panama: A preferred secrecy regime for shell companies registering domain networks designed to bypass traditional legal discovery.
       +-------------------------------------------------------------+
       |                      GEO-RISK PROFILES                      |
       +-------------------------------------------------------------+
       |  Jurisdiction   |  Primary Threat Vectors                   |
       +-----------------+-------------------------------------------+
       |  Russia         |  Sanction evasion, malvertising, state    |
       |                 |  data harvesting (e.g., Alfa Bank links)  |
       +-----------------+-------------------------------------------+
       |  China          |  Mobile SDK exfiltration, device profiling|
       |                 |  corporate control (e.g., Kunlun/Opera)   |
       +-----------------+-------------------------------------------+
       |  UAE / Cyprus   |  UBO masking, intermediary shell layers,  |
       |                 |  financial obfuscation                    |
       +-----------------+-------------------------------------------+
       |  Panama         |  Anonymized domain ownership, untraceable  |
       |                 |  ad-fraud operations                      |
       +-------------------------------------------------------------+

Unmasking "Quiet Removals"

When an ad exchange discovers an intermediary or reseller engaging in click fraud, domain spoofing, or malvertising, standard procedure rarely involves public notification or coordination with law enforcement. Instead, the exchange simply removes the offending entity’s ID from its sellers.json file.

  [Fraudulent Entity Detected] 
              |
              v
  [Exchange Silently Deletes ID from sellers.json]
              |
              +--> NO Public Warning Issued
              +--> NO Security Advisories
              |
              v
  [Entity Continues Operating on Other Unaware Networks]

This practice of Quiet Removals leaves other ad exchanges completely in the dark. The dropped actor can seamlessly continue funneling malicious ad inventory through competing networks that haven’t discovered the abuse yet.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

To bridge this information gap, DecryptAds maintains a real-time Quiet Removals Feed. By indexing snapshot changes across global sellers.json manifests, the platform highlights when a seller domain is quietly dropped by an exchange, surfacing early warning signals of ad fraud long before public disclosures occur.

The Mechanics of AI Slop Networks and Device Spoofing

The proliferation of generative AI tools has enabled a new class of ad fraud: low-cost, automated "AI slop" websites. These platforms publish thousands of synthetic, low-quality articles—covering topics from home improvement to niche hobbies—solely to host ad blocks hooked into low-tier ad exchanges.

Because these sites rarely invest in third-party malvertising defense or content moderation tools, they act as unmonitored backdoors into the ad ecosystem. Malicious actors use them to serve zero-click malware payloads and phishing redirects to unsuspecting visitors arriving via search engine results.

+-----------------------------------------------------------------------------------+
|                        BOTNET AD-FRAUD PIPELINE (FENGWO CASE)                     |
+-----------------------------------------------------------------------------------+
|                                                                                   |
|  1. Infected Streaming Hardware (e.g., H96 TV Sticks)                             |
|     * Silently monetized via residential proxy networks.                         |
|     * Spoofs user-agent to pretend to be a mobile device.                         |
|                                                                                   |
|  2. Automated Traffic Generation                                                  |
|     * Botnet routes fake clicks to targeted AI-generated slop domains             |
|       (e.g., medicalbeautyhub[.]com).                                              |
|                                                                                   |
|  3. Shared Ad Network Infrastructure                                              |
|     * DecryptAds traces shared Seller ID (1674071) to secondary sites             |
|       (e.g., giacoloredstones[.]com).                                              |
|     * Links directly to Russian Yandex ad platforms (Seller ID 103488000).        |
|                                                                                   |
+-----------------------------------------------------------------------------------+

This dynamic was highlighted in an investigation by Bitsight involving H96 TV streaming sticks. Millions of these budget Android devices were pre-loaded with firmware that quietly turned them into residential proxies. When idle, the streaming devices spoofed mobile phone identifiers and generated automated ad clicks on a cluster of AI-generated slop websites run by the Fengwo Group.

Using the DecryptAds Legal Dossier tool to trace one of these now-dormant sites—medicalbeautyhub[.]com—revealed that the domain shared a single ad exchange Seller ID (1674071) with an obscure gaming portal, giacoloredstones[.]com. Pivoting on a secondary Seller ID (103488000) found within that second site uncovered hundreds of active, low-quality web utilities and gaming sites operating inside Russia’s Yandex ad system. All of these properties shared identical infrastructure designed to farm fake clicks and deliver fraudulent ad impressions.


Official Statements and Industry Insights

Speaking on the operational vision driving DecryptAds, Zach Edwards emphasized that the platform was designed from the ground up to repurpose adtech infrastructure data for threat hunting and cyber defense.

"It’s an adtech tool but we’re trying to approach adtech from a security perspective," Edwards stated. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Edwards pointed out that the core challenge of securing ad networks lies in how fragmented raw manifest files are. Evaluating a single domain’s disclosures in isolation offers almost no actionable security value.

"Supply-chain integrity issues rarely live in a single file," Edwards explained. "They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Addressing the financial structural issues within high-risk ad networks—such as firms operating as both sellers and resellers simultaneously—Edwards cautioned that unmonitored file declarations create systemic conflicts of interest.

"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards said. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

               +---------------------------------------------+
               |         THE ADTECH CONFLICT OF INTEREST     |
               +---------------------------------------------+
               |                                             |
               |             +-----------------+             |
               |             | Adtech Company  |             |
               |             +--------+--------+             |
               |                      |                      |
               |          +-----------+-----------+          |
               |          |                       |          |
               |          v                       v          |
               |   +--------------+       +--------------+   |
               |   |  Publisher   |       |   Reseller   |   |
               |   +------+-------+       +------+-------+   |
               |          |                       |          |
               |          +-----------+-----------+          |
               |                      |                      |
               |                      v                      |
               |       [Controls Auction & Directs Spend]    |
               |       [Self-Dealing / Conflict Interest]    |
               |                                             |
               +---------------------------------------------+

When discussing the mechanics of quiet removals and the lack of industry-wide reporting standards, Edwards noted that corporate siloing actively works against broader threat mitigation efforts.

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards observed. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

Regarding malvertising vectors on low-grade websites, Edwards underscored that major destination sites are rarely the primary breach origin points for broad corporate networks.

"None of these slop AI content farms are paying for that kind of protection," he remarked. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search."

To effectively combat these zero-click vulnerabilities and hidden supply-chain attacks, Edwards called for global ad networks to expose and standardize the Supply Chain Object (SCO).

"That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload," Edwards stated. "You may see the malicious zero-click redirection, but without the supply chain object—which is only served server side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad."

KrebsOnSecurity requested comment from Between Digital and its executive leadership regarding their publisher payouts via sanctioned financial institutions; no responses were received prior to publication.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Future Outlook & Actionable Defense Strategies

As malvertising networks rely increasingly on automated AI-generated slop sites and hidden supply paths, security operations centers (SOCs) are beginning to treat adtech data as an essential component of threat intelligence. Integrating DecryptAds’ query API into automated security platforms enables enterprise threat hunters to dynamically correlate suspicious web traffic with declared ad infrastructure.

+-----------------------------------------------------------------------------------+
|                        ENTERPRISE & CONSUMER DEFENSE MATRIX                       |
+-----------------------------------------------------------------------------------+
|  Target Layer      |  Recommended Countermeasure                                 |
+--------------------+--------------------------------------------------------------+
|  Desktop Browser   |  Deploy open-source script & ad blockers                     |
|                    |  (e.g., uBlock Origin Lite, EasyList rulesets).              |
+--------------------+--------------------------------------------------------------+
|  Mobile Devices    |  Avoid unnecessary native apps; interact via mobile browser. |
|                    |  Use platform-native blocklists (e.g., Adblock Plus).        |
+--------------------+--------------------------------------------------------------+
|  Network Level     |  Implement DNS-sinkhole infrastructure (e.g., Pi-hole) to    |
|                    |  drop ad-server resolutions at the local gateway.             |
+--------------------+--------------------------------------------------------------+
|  Enterprise SOC    |  Ingest DecryptAds API data to identify high-risk bid paths   |
|                    |  and flag unauthorized geographic ad networks.              |
+-----------------------------------------------------------------------------------+

Strategic Countermeasures for Consumers and Enterprises

Given the pervasive nature of real-time ad tracking and malvertising, cybersecurity experts universally recommend a defense-in-depth approach to manage digital ad exposure.

1. Endpoint & Browser Defense

  • uBlock Origin Lite: Recognized as a gold standard for lightweight, open-source ad blocking, uBlock Origin Lite effectively strips advertising code, tracking scripts, and malicious redirects before they can render in desktop browsers (and Firefox on Android).
  • Adblock Plus: A robust alternative for iOS and iPadOS environments that supports custom rulesets maintained by open-source communities like EasyList (easylist.to).
  • NoScript: For high-security environments, script-blocking extensions prevent any unauthorized JavaScript from executing. While highly effective against zero-click malvertising, NoScript requires active management and rule configuration to avoid breaking standard site functionality.

2. Network-Level DNS Sinkholing

For home networks and enterprise environments, blocking ad infrastructure at the network layer offers scalable protection across all connected devices—including smart TVs, mobile phones, and IoT hardware.

Using low-cost hardware like a Raspberry Pi, administrators can install Pi-hole, an open-source DNS sinkhole. Once configured as the network’s primary DNS and DHCP server, the Pi-hole intercepts lookups for known ad-serving domains and data brokers, silently dropping the requests before they reach local devices.

[ Connected Device ] ---> [ Request: bad-ad-server.com ]
                                     |
                                     v
                       [ Pi-hole DNS Sinkhole ]
                                     |
                         ( Matches Blocklist )
                                     |
                                     v
                       [ Request Dropped / Null IP ]

3. Mobile App Minimization and Privacy Hygiene

A growing strategy among large web platforms involves aggressively steering users away from web browsers toward native mobile applications. While marketed as convenience features, mobile apps circumvent browser-level ad blockers, granting companies direct access to precise location data, Bluetooth telemetry, device fingerprints, and persistent hardware identifiers.

Security professionals recommend interacting with services through privacy-focused web browsers rather than dedicated mobile applications whenever possible. Furthermore, consumers should audit smart TV apps and streaming hardware, consulting platforms like DecryptAds to evaluate the background data-sharing practices and geographic links of their software vendors.

By transforming raw ads.txt and sellers.json manifests into actionable threat intelligence, platforms like DecryptAds are shedding light on a historically opaque sector. As awareness grows around how commercial ad networks can be leveraged for malvertising, data harvesting, and nation-state reconnaissance, enforcing adtech supply-chain integrity is rapidly becoming a fundamental pillar of modern cybersecurity.

Leave a Reply

Your email address will not be published. Required fields are marked *