Deciphering the Adtech Shadow Supply Chain: How DecryptAds Exposes Foreign Surveillance, Malvertising, and Data Exploitation

Executive Overview

In the modern programmatic advertising landscape, the infrastructure powering web and mobile banner ads has evolved into a vast, opaque network of real-time bidding platforms, data brokers, and intermediary resellers. While designed to automate online ad sales, this complex web quietly harvest personal data, tracks user movements, and facilitates cyber threats. Determining which foreign or domestic entities collect location data from a smartphone app or serve code to a desktop browser has historically required navigating fragmented, semi-public declaration files accessible almost exclusively to adtech insiders.

That visibility gap is now closing. A cybersecurity and adtech threat intelligence platform, DecryptAds (decryptads.com), has launched a free public portal designed to continuously scrape, correlate, and index these declaration files. Founded by Zach Edwards—chief research officer at DecryptAds and threat researcher at security firm Infoblox—alongside two co-founders, the platform transforms raw adtech disclosures into structured, actionable threat intelligence.

By cross-referencing public compliance declarations, DecryptAds exposes systemic vulnerabilities across the programmatic ad ecosystem. Its findings reveal high-risk ad networks based in adversarial nations operating on sensitive U.S. defense news outlets, widespread data collection on mainstream sports networks, and complex click-fraud pipelines linked to cheap smart TV streaming hardware and AI-generated content farms.


The Technical Architecture of Adtech Transparency

To understand how DecryptAds uncovers illicit activity, one must first examine the public file protocols established by the Interactive Advertising Bureau (IAB) to establish authorized sales channels:

  • ads.txt (Authorized Digital Sellers): A plain-text file hosted at the root domain of a website listing all ad networks, supply-side platforms (SSPs), and data brokers legally permitted to sell or monetize the publisher’s ad inventory.
  • app-ads.txt: The mobile, connected TV (CTV), and smart TV counterpart to ads.txt, detailing authorized entities permitted to serve ads or collect data within mobile and smart TV applications.
  • sellers.json / buyers.json: Files published by ad exchanges, supply-side platforms, and demand-side platforms (DSPs) identifying the intermediate entities, resellers, and direct publishers involved in buying and selling ad inventory.
[Publisher Domain] 
       │
       ├─► ads.txt / app-ads.txt  (Declares authorized sellers)
       │
[Ad Exchange / SSP]
       │
       └─► sellers.json / buyers.json  (Identifies intermediaries & buyers)

While these files are technically public, analyzing them individually offers limited insight. A single ads.txt file might contain thousands of alphanumeric publisher IDs, obscure vendor names, and reseller declarations.

"Supply-chain integrity issues rarely live in a single file," the DecryptAds analytical team notes. "They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

DecryptAds systematically ingests these files, mapping cross-references to expose supply-chain anomalies, hidden corporate structures, and undisclosed data brokers. "It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards explained. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."


Geopolitical Risks and High-Risk Ad Networks

One of the platform’s core capabilities is identifying advertising entities based in geopolitical "geo-risk" zones—specifically nations like China and Russia, or offshore financial and secrecy havens such as Cyprus, Panama, and the United Arab Emirates (UAE).

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Case Study 1: ESPN.com and State Privacy Mandates

An analysis of espn.com demonstrates the scale of mainstream ad tracking. Searching the domain on DecryptAds reveals 143 ad partners and 19 registered data broker domains explicitly listed in its ads.txt and app-ads.txt disclosures.

ESPN.com Public Declarations
├── Total Ad Partners: 143
├── Registered Data Brokers: 19
│   ├── Geolocation Harvesters: ~50%
│   └── Device Fingerprinting/Sensitive Personal Data: ~15%
└── Foreign "Geo-Risk" Partners: 4 (Russia, China, UAE)

This visibility into data broker activity is fueled by recent privacy legislation in four U.S. states—California, Oregon, Texas, and Vermont—which mandate that third-party data brokers register publicly if they collect, process, or sell consumer data originating from residents in those jurisdictions.

DecryptAds’ correlation engine reveals that nearly half of the registered data brokers operating on espn.com actively collect real-time geolocation telemetry from unblocked users, while three others explicitly disclose harvesting unique device fingerprints and sensitive personal information. Furthermore, espn.com lists four separate advertising entities operating out of Russia, China, or the UAE.

Case Study 2: U.S. Military Publications and Sanctioned Entities

The security implications of these ad networks become clearer when evaluating specialized news outlets. Domain audits for major military news organizations—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveal that every single one permits an adtech firm called Between Digital to track users and serve programmatic ad content, alongside additional entities registered in the UAE and Panama.

While Between Digital maintains a listed corporate address in New York, DecryptAds’ dossier classifies the business as a Russian firm. Corporate filings disclose that Between Digital processes its publisher transactions through Alfa-Bank, Russia’s largest private commercial bank. Alfa-Bank was placed under severe U.S. Department of the Treasury sanctions in 2022 following Russia’s full-scale invasion of Ukraine.

Across the web, Between Digital collects advertising and user telemetry across an estimated 55,000 partner websites.

U.S. Military News Outlets (Army Times, Defense News, etc.)
       │
       ▼
   [ads.txt] ──► Authorized Partner: Between Digital
                       │
                       ├─► Corporate Base: Russian Federation
                       ├─► Financial Clearinghouse: Alfa-Bank (U.S. Sanctioned)
                       └─► Global Tracking Footprint: ~55,000 Websites

Dual-Role Conflicts of Interest

Investigating Between Digital’s app-ads.txt file exposes hundreds of domains hosting simple browser-based games filled with aggressive ad units. Edwards pointed out that Between Digital’s self-declared records list the firm as both a publisher and a reseller across roughly two-thirds of its ad portfolio.

"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards noted. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Case Study 3: Opera Browser Ecosystem

Similarly, the Opera desktop and mobile web browser—which maintains operational headquarters in Oslo, Norway, but has been majority-owned and controlled by Chinese technology firm Kunlun Tech since 2016—presents a complex web of tracking partnerships.

DecryptAds’ profile of opera.com identifies 27 registered data brokers collecting user information, including:

  • 15 adtech partners based in the UAE
  • 6 in China
  • 3 in Cyprus
  • 2 in Russia
  • 1 in Hong Kong
  • 1 in Ukraine

These foreign entities represent only 7% of the total adtech ecosystem specified within Opera’s declared compliance files, demonstrating how deeply third-party trackers are integrated into modern browser infrastructure.


Malvertising, AI Slop, and Botnet Monetization

Beyond geopolitical surveillance and telemetry gathering, programmatic ad networks are frequently exploited for fraud and malware delivery.

The Fengwo Group and H96 Streaming Devices

DecryptAds’ Legal Dossier lookup feature helps researchers uncover hidden infrastructure used by threat actors to connect disparate domains, app networks, and seller accounts.

A recent investigation by cybersecurity firm Bitsight uncovered an ad fraud scheme involving budget H96 Android TV streaming sticks. These devices contained hidden malware that quietly turned users’ home internet connections into residential proxies rented out to cybercriminals. When idle, the TV sticks spoofed mobile device signatures to automatically generate fake ad clicks on low-quality, AI-generated content websites.

[Infected H96 TV Stick] ──(Rents IP Proxy)──► [Proxy Network]
        │
        ▼ (Spoofs Mobile Device Signature)
[AI "Slop" Website] (e.g., medicalbeautyhub[.]com)
        │
        ▼ (Triggers Fake Ad Clicks)
[Ad Networks / Yandex Ecosystem] ──► Fraudulent Ad Revenue Stream

Bitsight tied these malicious applications to a Chinese entity known as the Fengwo Group, which operated both the device malware and the network of AI "slop" domains receiving fake ad traffic.

DecryptAds’ intelligence engine adds critical detail to this case. Performing a legal dossier query on one of Fengwo’s dormant slop sites, medicalbeautyhub[.]com, reveals that it shared a unique seller ID (1674071) with an online gaming site, giacoloredstones[.]com.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Pivoting further on a second seller ID (103488000) linked to that gaming hub reveals hundreds of active, low-quality utility and gaming domains embedded directly within Russia’s Yandex ad network—demonstrating how ad-fraud infrastructure spans multiple jurisdictions and ad networks.

The "Quiet Removals" Intelligence Gap

When major ad platforms spot an enterprise engaged in click fraud or malvertising, they rarely issue public warnings. Instead, they drop the offending domain from their sellers.json files—a tactic Edwards calls "quiet removals."

[Ad Exchange Identifies Malicious/Fraudulent Seller]
                       │
                       ▼
           [Quiet Removal Practice]
   (No Public Warning / No Shared Intelligence)
                       │
                       ▼
  [Offender Secretly Dropped from sellers.json]
                       │
                       ▼
[Threat Actor Pivots to Unaware Secondary Ad Exchanges]

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards explained. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

To fix this visibility gap, DecryptAds provides a real-time Quiet Removals Feed. By indexing when an ad platform drops a seller, the tool gives defenders early warning signs that a vendor may be involved in fraud or malicious behavior.

Malvertising Vectors: Mainstream vs. AI Slop

While high-traffic news platforms employ continuous monitoring software to block malicious ad redirects, AI content farms rarely invest in basic ad verification tools. As a result, these low-tier sites become frictionless pathways for malvertising operations, zero-click drive-by downloads, and phishing schemes.

"None of these slop AI content farms are paying for that kind of protection," Edwards said. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search."


Missing Technical Protocols: The Supply Chain Object (SCO)

To effectively trace malvertising, cybersecurity teams need access to full bidstream telemetry. When an ad server receives an impression request, structured data known as the Supply Chain Object (SCO) is generated server-side. The SCO records every intermediary, reseller, and ultimate purchaser involved in handling the ad slot.

[Publisher Webpage]
       │
       ▼
   [Ad Exchange]
       │
       ▼  ◄─── Supply Chain Object (SCO) Payload
  [Reseller / SSP]      (Contains server-side records of all 
       │                 intermediaries, resellers, & ultimate buyers)
       ▼
  [Malicious Buyer] ──► (Serves Zero-Click Malvertising Payload)

However, major ad exchanges rarely share SCO records publicly. Without this data, security teams investigating targeted zero-click malware campaigns can see that a malicious ad landed on an endpoint, but cannot identify which specific adtech intermediary sold the ad space.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload," Edwards noted. "A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis… If we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad."

To help security teams integrate this data into their workflows, DecryptAds offers an API that allows analysts to automate adtech queries and ingest threat data directly into custom security tools and AI analysis platforms.


Defensive Countermeasures and Practical Remediation

Given the pervasive privacy and security risks built into programmatic advertising, enterprise security administrators and everyday web users should adopt aggressive ad-blocking and network hygiene strategies.

+-------------------------------------------------------------------------+
|                  RECOMMENDED AD-BLOCKING TAXONOMY                        |
+-------------------+-----------------------------------------------------+
| Protection Layer  | Tooling & Implementation Recommendations            |
+-------------------+-----------------------------------------------------+
| Desktop Browsers  | uBlock Origin Lite (Chromium) / uBlock Origin       |
|                   | NoScript (Advanced JavaScript control)              |
|                   | EasyList custom rule additions                      |
+-------------------+-----------------------------------------------------+
| Mobile Platforms  | iOS: Adblock Plus                                   |
|                   | Android: Firefox + uBlock Origin                    |
+-------------------+-----------------------------------------------------+
| Local Network     | Pi-hole (Raspberry Pi DNS Sinkhole)                 |
|                   | Router-level DHCP/DNS redirection                   |
+-------------------+-----------------------------------------------------+
| Device Hygiene    | Reject forced app installations; use web versions   |
|                   | Restrict smart TV / CTV internet access & telemetry |
+-------------------+-----------------------------------------------------+

1. Endpoint Ad-Blocking Tools

  • Desktop Browsers: Installing light, open-source ad-blocking extensions like uBlock Origin Lite blocks third-party tracking domains before they execute. For technical users, NoScript stops unauthorized JavaScript altogether, preventing malicious code execution from unverified ad networks. Adding custom blocklists from sources like EasyList further improves blocking coverage.
  • Mobile Devices: Android users can run full-featured ad blockers like uBlock Origin within mobile Firefox. For iOS (iPhone/iPad) users, native Content Blockers such as Adblock Plus help reduce exposure to web trackers.

2. Network-Level DNS Sinkholing

Hardware-based DNS sinkholes offer the most effective, scalable defense across local networks. Using low-cost hardware like a Raspberry Pi running Pi-hole, users can intercept and drop DNS queries directed at known ad servers, data brokers, and telemetry endpoints. Once configured as the primary DNS server on a local router, a Pi-hole blocks ad traffic for every connected endpoint—including smart TVs, IoT appliances, and mobile devices—without needing software plugins on each device.

3. Native App Hygiene

Security analysts urge caution when platforms push users to download native mobile or smart TV applications instead of using standard web browsers. Mobile apps routinely bypass browser security controls, accessing granular device identifiers, location APIs, and background processes that are far harder to block.

"The cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are," Edwards warned.

Furthermore, many application developers quietly reserve the right in their privacy policies to train large language models (LLMs) on user data. Restricting native app installations—particularly on Smart TVs and mobile devices—remains an effective way to minimize personal telemetry exposure.


Summary of Key Takeaways

  1. DecryptAds aggregates and cross-references public ads.txt, app-ads.txt, and sellers.json files to expose adtech tracking, malvertising networks, and geo-risk entities.
  2. High-Risk Ad Networks: Major mainstream news and sports sites embed ad partners headquartered in geopolitical risk zones (e.g., Russia, China, UAE). Notably, U.S. military news sites permit Russian-linked Between Digital—which clears funds through sanctioned Alfa-Bank—to track readers.
  3. Malvertising Pipelines: Threat actors exploit low-tier AI content farms to host malvertising and zero-click exploits, while ad fraud campaigns use compromised IoT devices (like H96 streaming sticks) to generate fake ad views.
  4. Adtech Opacity: Ad networks frequently perform "quiet removals" of fraudulent sellers without sharing intelligence across the industry, enabling threat actors to pivot between exchanges.
  5. Defensive Action: Implementing endpoint blocklists (uBlock Origin Lite), network-wide DNS sinkholes (Pi-hole), and minimizing unnecessary native app downloads are vital steps to safeguard digital privacy and network security.

Leave a Reply

Your email address will not be published. Required fields are marked *