Unmasking the Shadow Ecosystem: How DecryptAds Exposes Malvertising, Foreign Surveillance, and Adtech Supply-Chain Risks

Executive Overview: Unveiling the Opaque Adtech Supply Chain

For over two decades, the digital advertising ecosystem has operated behind a veil of intentional complexity. While millions of web pages and mobile applications harvest user telemetry, serve display ads, and process real-time bidding requests every second, the underlying network of data brokers, ad exchanges, and monetization intermediaries has remained largely inscrutable to the average consumer—and frequently obfuscated even from corporate cybersecurity teams.

This status quo is shifting with the launch of DecryptAds (decryptads.com), a specialized security-focused intelligence platform designed to scrape, aggregate, and correlate public adtech compliance metadata. Developed by threat researcher Zach Edwards—Chief Research Officer for DecryptAds and threat researcher at cybersecurity firm Infoblox—alongside two co-founders, the service translates raw, fragmented advertising manifests into actionable threat intelligence.

+-----------------------------------------------------------------------------------+
|                                DECRYPTADS ENGINE                                  |
+-----------------------------------------------------------------------------------+
       |                                |                               |
       v                                v                               v
+--------------+                +---------------+               +---------------+
|   ads.txt    |                |  app-ads.txt  |               | sellers.json  |
|  (Websites)  |                | (Mobile & TV) |               |  (Exchanges)  |
+--------------+                +---------------+               +---------------+
       |                                |                               |
       +-----------------------+--------+-------------------------------+
                               |
                               v
+-----------------------------------------------------------------------------------+
|                           CORRELATION & GRAPH ANALYSIS                            |
+-----------------------------------------------------------------------------------+
       |                                |                               |
       v                                v                               v
[ Foreign Geo-Risk ]           [ Quiet Removals ]             [ Legal Dossiers ]
  (RU, CN, UAE, CY)             (Hidden Ad Bans)              (Infrastructure)

By cross-referencing standard industry transparency files—such as ads.txt, app-ads.txt, buyers.json, and sellers.json—DecryptAds exposes the entities authorized to display content or collect telemetry from specific digital properties. The platform illuminates critical security risks, including:

  • Malvertising supply-chain vectors used to deliver zero-click exploits;
  • The silent proliferation of state-linked adtech networks originating from adversarial nations;
  • Fast-growing swarms of machine-generated AI content farms ("slop sites") built to siphon advertising revenue and distribute malware.

Detailed Chronology & Technical Deep Dive: Deconstructing the Web of Tracking

The Genesis of Adtech Transparency Files

The framework analyzed by DecryptAds relies on industry-standard transparency specifications introduced over the past decade by the IAB Tech Lab to combat inventory fraud:

  • ads.txt (Authorized Digital Sellers): Text files hosted at a domain’s root directory, declaring which entities are authorized to sell the publisher’s digital inventory.
  • app-ads.txt: An extension of ads.txt tailored for mobile applications and Connected TV (CTV) environments.
  • sellers.json and buyers.json: Files hosted by ad exchanges and supply-side platforms (SSPs) listing the intermediate entities, resellers, and direct publishers involved in buying and selling ad inventory.

While these manifests were created to assure advertisers that their inventory was legitimate, they simultaneously created a massive public repository of structural mapping data. However, analyzing these files individually yields minimal visibility. Supply-chain manipulation, unauthorized reselling, and identity spoofing routinely span hundreds of mismatched cross-references across multiple infrastructure nodes. DecryptAds unifies these disparate datasets into a searchable graph database.

       [ Publisher Web/App Property ]
                     |
        +------------+------------+
        |                         |
        v                         v
  [ ads.txt ]               [ app-ads.txt ]
        |                         |
        +------------+------------+
                     |
                     v
   [ Intermediate Ad Exchanges / SSPs ]
                     |
             [ sellers.json ]
                     |
                     v
   [ Buyer / Demand-Side Platform (DSP) ]

Case Study 1: Mainstream Media & Data Broker Mapping (espn.com)

An analysis of sports broadcasting portal espn.com using DecryptAds highlights the density of modern web tracking networks:

  • Declared Partners: 143 explicit ad partners and 19 registered data broker domains embedded within its ads.txt and app-ads.txt files.
  • Regulatory Context: The categorization of data brokers is enabled by recent consumer privacy laws passed in California, Oregon, Texas, and Vermont, which mandate public registration for entities trading consumer personal information.
  • Data Collection Metrics: DecryptAds reveals that nearly half of the registered data brokers operating across espn.com extract precise geolocation data from visitors who do not utilize ad-blocking controls. Furthermore, three registered brokers explicitly disclose the collection of unique device fingerprints and sensitive personal information.
+-----------------------------------------------------------------------+
|                       ESPN.COM ADTECH METRICS                         |
+-----------------------------------------------------------------------+
| Metric                                   | Value                      |
+------------------------------------------+----------------------------+
| Total Declared Ad Partners               | 143                        |
| Registered Data Broker Domains           | 19                         |
| Brokers Collecting Geolocation Data      | ~50%                       |
| Brokers Harvesting Sensitive Telemetry   | 3                          |
| Geo-Risk Partners (Russia, China, UAE)   | 4                          |
+------------------------------------------+----------------------------+

Case Study 2: Geopolitical Risk and Military Media Exposure

DecryptAds flags high-risk advertising partners by evaluating their registration data, corporate structures, and server locations against geographic threat matrices. Entities located in or routed through jurisdictions such as China, Russia, Cyprus, the United Arab Emirates (UAE), and Panama trigger automated "Geo-Risk" alerts.

+-----------------------------------------------------------------------------------+
|                        BETWEEN DIGITAL SUPPLY-CHAIN MATRIX                        |
+-----------------------------------------------------------------------------------+
| Registered Entity Location | New York Address (Operational Hub: Russia)           |
| Financial Clearinghouse    | Alfa Bank (Sanctioned Russian Commercial Institution)|
| Active Partner Domains     | ~55,000 Global Domains                               |
| Key Targeted Defense Media | ArmyTimes, AirForceTimes, DefenseNews,               |
|                            | NavyTimes, MarineCorpsTimes, FederalTimes             |
| Structural Anomaly         | Acts as Publisher AND Reseller on 2/3 of Portfolio   |
+-----------------------------------------------------------------------------------+

A prominent example identified by the platform is Between Digital. Although maintaining a business address in New York, Between Digital’s underlying operational dossiers classify it as a Russian enterprise. Financial disclosures in the firm’s publisher documentation specify that payout processing is routed through Alfa Bank—Russia’s largest private commercial bank, which was placed under strict United States financial sanctions in 2022 following the invasion of Ukraine.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Despite these sanctions and geographic indicators, DecryptAds data confirms that Between Digital is integrated into approximately 55,000 partner websites worldwide. Most notably, the ad network is authorized to serve advertisements and track users across key U.S. defense publications, including:

  • armytimes.com
  • airforcetimes.com
  • defensenews.com
  • navytimes.com
  • marinecorpstimes.com
  • federaltimes.com

Furthermore, pivoting on Between Digital’s app-ads.txt manifest exposes hundreds of domains serving low-tier browser games heavily saturated with ad placements. Crucially, Between Digital acts as both the publisher and the reseller on roughly two-thirds of its declared portfolio. This structural setup enables self-dealing—allowing an entity to manipulate supply bids, route capital into self-owned infrastructure, and bypass external security oversight.


Case Study 3: Browser Infrastructure Analysis (Opera.com)

The desktop and mobile Web browser Opera provides another case study in geopolitical cross-ownership and adtech integration. Operated out of Oslo, Norway, Opera has been majority-owned and controlled by the Chinese technology conglomerate Kunlun Tech since 2016.

DecryptAds parsing of opera.com identifies 27 registered data brokers harvesting information from browser ecosystem traffic, including:

  • 15 adtech partners based in the United Arab Emirates;
  • 6 entities based in mainland China;
  • 3 operating out of Cyprus;
  • 2 situated within the Russian Federation;
  • 1 in Hong Kong and 1 in Ukraine.

These foreign-jurisdiction operations account for only 7 percent of the overall adtech relationships declared within opera.com‘s public authorization manifests, underscoring the massive global distribution of modern tracking infrastructure.


Case Study 4: AI "Slop" Networks and Malicious Device Hijacking

The integration of DecryptAds’ deep infrastructure lookup tools—specifically its Legal Dossier engine—helps researchers map criminal ad-fraud rings and malicious device manipulation schemes back to their origin infrastructure.

Recent security disclosures from telemetry firm Bitsight revealed that budget-tier H96 Android TV streaming sticks were distributed with pre-installed firmware backdoors. When idle, these devices hijacked domestic internet connections, operating as residential proxies while spoofing their hardware signatures to impersonate mobile phones. These fake mobile clients were programmed to systematically load AI-generated "slop" websites and trigger automated ad clicks.

[ Infected H96 Android TV Stick ] 
               |
               | (Spoofs identity as Mobile Phone)
               v
 [ AI Content Farm: medicalbeautyhub[.]com ] 
               |
               | (Shares Seller ID: 1674071)
               v
 [ Gaming Site: giacoloredstones[.]com ] 
               |
               | (Shares Seller ID: 103488000)
               v
[ Russian Yandex Ad Exchange Network ] (Automated Fraud Cash-Out)

Bitsight linked this activity to a Chinese entity known as the Fengwo Group. Querying DecryptAds’ Legal Dossier system for domain infrastructure linked to the network (e.g., medicalbeautyhub[.]com) revealed key forensic markers:

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
  1. medicalbeautyhub[.]com shared a primary seller identifier (1674071) with an obscure online gaming site, giacoloredstones[.]com.
  2. giacoloredstones[.]com declared a secondary seller identifier (103488000).
  3. Cross-referencing seller ID 103488000 exposed hundreds of active domains linked to Russia’s Yandex ad network. These domains hosted low-quality browser utilities and automated gaming portals optimized for ad injection and click fraud.

Supporting Context & Metrics: Structural Vulnerabilities and Hidden Mechanics

The "Quiet Removals" Paradigm

A structural vulnerability within programmatic ad markets is the lack of public reporting when ad exchanges drop malicious or fraudulent actors. When an ad exchange discovers that an intermediary is delivering malvertising payloads, spoofing metrics, or facilitating click fraud, standard industry protocol is to remove the vendor from its sellers.json manifest without issuing a public disclosure.

                       [ AD EXCHANGE SYSTEM ]
                                 |
           +---------------------+---------------------+
           |                                           |
           v                                           v
[ Malicious Vendor Identified ]             [ Action Taken ]
           |                                           |
           v                                           v
[ NO Public Disclosure Issued ]      [ Silent Removal from sellers.json ]
           |                                           |
           +---------------------+---------------------+
                                 |
                                 v
                [ VENDOR SURVIVES ON OTHER EXCHANGES ]
                                 |
                                 v
              [ Tracked by DecryptAds Removals Feed ]

This dynamic allows rogue operators to maintain active monetized connections across dozen of other exchanges that remain unaware of the threat. To eliminate this blind spot, DecryptAds operates a Quiet Removals Feed. By continuously monitoring global sellers.json snapshots, the service tracks when a seller domain or account ID is silently revoked across major ad exchanges, providing security teams with an early warning system for compromised ad vendors.


Malvertising Shifts to Low-Tier Content Farms

Historically, threat actors relied on compromising major ad networks to push drive-by downloads and phishing campaigns directly to high-traffic destinations like mainstream news platforms. Modern publishing platforms, however, utilize automated real-time verification mechanisms to block malicious ad tags.

Consequently, malvertising threat groups have shifted their focus to AI-generated content farms.

+-----------------------------------------------------------------------------------+
|                    ENTERPRISE VS. AI SLOP AD SECURITY COMPARISON                  |
+-----------------------------------------------------------------------------------+
| Security Vector          | Mainstream Publisher (e.g., ESPN) | AI Content Farm     |
+--------------------------+----------------------------------+---------------------+
| Real-time Ad Scanning    | Active (Third-party verification)| None                |
| Vendor Vetting           | Strict compliance checks         | Unvetted / Low-tier |
| Malvertising Exposure    | Low (Mitigated rapidly)          | High (Greased rail) |
| Dominant Monetization    | Direct deal / Tier-1 Exchanges   | Arbitrage / Fraud   |
+-----------------------------------------------------------------------------------+

Because AI-generated "slop" platforms operate without real-time ad vetting tools, they become direct distribution channels for malicious code. When users land on these pages via search engine queries, they are exposed to unvetted advertising tags capable of launching zero-click browser exploits, redirecting to phishing portals, or pushing malware installers.


The Missing Telemetry: Supply Chain Objects (SCO)

A key limitation in countering programmatic ad threats is the restriction of internal transaction data. When an advertisement is served, the ad platform generates a Supply Chain Object (SCO)—a structured record embedded within the OpenRTB bid request that traces every exchange, reseller, and intermediate broker handling that specific ad impression.

Currently, major ad exchanges restrict access to SCO telemetry, making it available only to server-side participants within the transaction path. Without access to the SCO, security analysts investigating a zero-click browser exploit can see the malicious payload delivered to the client, but cannot trace the specific path of intermediaries responsible for selling and delivering the ad impression.

[ Ad Impression Requested ] 
          |
          v
[ Supply Chain Object (SCO) Generated ] 
  ├── Node 1: Origin Publisher
  ├── Node 2: Intermediate Reseller (SSP)
  ├── Node 3: Ad Exchange Proxy
  └── Node 4: Winning Bidder / DSP (Payload Source)
          |
          +---> Server-Side Access Only (Hidden from End-User & Security Analysts)
          +---> DecryptAds Advocates Opening SCO for Forensic Traceability

Official Statements & Key Expert Insights

Highlighting the scope of these blind spots, Zach Edwards, Chief Research Officer for DecryptAds and security researcher at Infoblox, emphasized the platform’s security-first design:

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"It’s an adtech tool, but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Addressing the vulnerability of isolated compliance records, Edwards noted:

"Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."

Edwards also highlighted the structural risks of ad networks operating as both seller and marketplace:

"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest. The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

Regarding the role of AI-generated content farms in spreading malvertising, Edwards explained:

"None of these slop AI content farms are paying for that kind of protection. They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather on some lower quality content farm and someone just went there because it came up in a search."

On the necessity of opening internal adtech metrics for defensive cyber operations, he added:

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis.

That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload. You may see the malicious zero-click redirection, but without the supply chain object—which is only served server side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly."


Future Outlook & Actionable Defense Strategies

Industry Trajectory

As data broker registries expand under state-level regulatory frameworks and tools like DecryptAds automate supply-chain mapping, the programmatic advertising market faces increasing pressure to standardize security practices. However, as long as real-time bidding infrastructure permits anonymous intermediate reselling, malvertising operators will continue utilizing obscure ad exchanges to run zero-click exploit campaigns.

Security teams and enterprise network administrators must shift from treating digital ad infrastructure merely as a privacy nuisance to recognizing it as an active cyberattack vector.

+-----------------------------------------------------------------------------------+
|                      MULTI-TIERED ADTECH DEFENSE BLUEPRINT                        |
+-----------------------------------------------------------------------------------+
| Level              | Tool / Mechanism         | Primary Function                  |
+--------------------+--------------------------+-----------------------------------+
| Endpoint Browser   | uBlock Origin Lite       | Block ad scripts, trackers, frames|
| Advanced Endpoint  | NoScript                 | Block unauthorized JavaScript execution|
| Network / DNS      | Pi-hole (Raspberry Pi)   | Local network sinkholing of ad domains|
| Hardware / Mobile  | Mobile App Minimization  | Prevent native OS telemetry collection|
+-----------------------------------------------------------------------------------+

Technical Mitigation Blueprint

1. Endpoint-Level Content Filtering

Blocking ad rendering at the client browser remains the most effective defense against malvertising payloads and telemetry extraction:

  • uBlock Origin Lite: An open-source content blocker designed to efficiently restrict tracking scripts, ad frames, and known malicious domains.
  • Script Management (NoScript): Blocking unauthorized JavaScript execution prevents complex drive-by download vectors and zero-click browser exploit scripts from executing.
  • Custom Filter Rules: Integrating community-maintained rule lists, such as those provided by easylist.to, ensures protection databases remain updated against newly registered ad domains.

2. Network-Wide DNS Sinkholing

For organizations, remote networks, and home lab environments, deploying network-level domain blocking neutralizes tracking telemetry across all connected hardware simultaneously:

  • Hardware Setup: Deploying software like Pi-hole on a local network node (such as a Raspberry Pi) acts as an internal DNS sinkhole.
  • Router Integration: Reconfiguring default gateway DNS settings to route through a local sinkhole ensures that telemetry collection, background ad requests, and programmatic bidding scripts are dropped at the DNS layer before reaching smart devices, IoT endpoints, or desktop browsers.

3. Mobile and Smart TV Application Governance

Mobile applications and Connected TV (CTV) firmware present elevated data-harvesting risks compared to desktop web browsers. Native mobile apps routinely bypass standard browser extensions, enabling direct extraction of precise device telemetry, location histories, and network identity data—information that is frequently monetized or used to train commercial AI models.

To minimize this attack surface:

  • Prioritize accessing digital services through secure web browsers configured with content-blocking extensions, rather than installing dedicated mobile or Smart TV applications.
  • Audit installed mobile and CTV applications against platforms like DecryptAds to evaluate hidden adtech dependencies, data broker declarations, and structural links to foreign infrastructure.

Leave a Reply

Your email address will not be published. Required fields are marked *