For decades, the multi-billion-dollar digital advertising ecosystem has operated behind a veil of intentional complexity. While everyday internet users navigate commercial websites and mobile applications, a vast, invisible network of data brokers, supply-side platforms (SSPs), demand-side platforms (DSPs), and ad exchanges silently harvest behavioral telemetry, device fingerprints, and precise geolocation coordinates. Although industry-standard declaration files—such as ads.txt, app-ads.txt, and sellers.json—were designed to introduce public transparency, their raw data has historically remained siloed, unparsed, and virtually impossible for the average consumer or security analyst to cross-reference.
This balance of power is beginning to shift with the public launch of DecryptAds (decryptads.com), an open-access cybersecurity and threat intelligence platform designed to systematically scrape, correlate, and index global adtech transparency records. Spearheaded by chief research officer Zach Edwards—a seasoned threat researcher at Infoblox—and two co-founders, DecryptAds approaches advertising infrastructure not merely as a marketing mechanism, but as a critical, highly vulnerable software supply chain.
By parsing millions of complex cross-references, DecryptAds uncovers systemic supply-chain anomalies, unauthorized programmatic resellers, and high-risk ad networks originating from adversarial nations such as Russia and China. The platform’s initial findings expose startling security gaps across top-tier mainstream media platforms like espn.com, major military news publications, popular web browsers, and low-quality artificial intelligence (AI)-generated "slop" websites used to conduct automated ad-fraud schemes.
As malvertising—the injection of malicious, zero-click payloads through legitimate advertising networks—continues to proliferate, DecryptAds provides threat intelligence teams, policy regulators, and privacy-conscious consumers with the visibility required to map, audit, and neutralize hidden adtech threats.
Detailed Chronology: The Evolution of Adtech Transparency and Threat Discovery
┌─────────────────────────────────────────────────────────────────────────────────┐
│ ADTECH TRANSPARENCY & THREAT CHRONOLOGY │
└─────────────────────────────────────────────────────────────────────────────────┘
2017–2019: Declarative File Standards Introduced
│ ├── IAB Tech Lab releases `ads.txt` and `app-ads.txt` standards.
│ └── Aim: Curb unauthorized domain spoofing and publisher impersonation.
│
2020–2022: Introduction of `sellers.json` & Geopolitical Shift
│ ├── `sellers.json` deployed to map supply-chain intermediaries.
│ └── Russia invades Ukraine (2022); Western sanctions hit entities like Alfa Bank.
│
2023–2025: State-Level Privacy Mandates & Botnet Investigations
│ ├── California, Oregon, Texas, and Vermont mandate Data Broker Registries.
│ └── Security researchers map malicious H96 streaming stick ad-fraud networks.
│
2026: Public Launch of DecryptAds
├── Platform correlates millions of programmatic records into threat dossiers.
└── Exposes widespread ad-supply ties to sanctioned banks & foreign actors.
1. The Declarative Era (2017–2020)
In response to widespread domain spoofing and programmatic ad fraud, the Interactive Advertising Bureau (IAB) Tech Lab introduced structured, plain-text declaration standards:
ads.txt (Authorized Digital Sellers): A flat file hosted on publisher root domains listing entities authorized to sell the publisher’s ad inventory.
app-ads.txt: The equivalent standard adapted for mobile applications, connected TVs (CTVs), and smart devices.
sellers.json & buyers.json: Market-facing files published by ad exchanges detailing the identities, seller IDs, and corporate types (publisher, intermediary, or both) of their supply partners.
While these protocols reduced surface-level identity fraud, they simultaneously created massive data volumes that security teams could not manually audit.
2. Regulatory Enforcement and Data Broker Visibility (2023–2025)
A wave of state-level data privacy legislation—notably in California, Oregon, Texas, and Vermont—mandated that entities buying or selling consumer data register publicly as data brokers. These legal registries provided critical corporate identity metrics that, when overlaid against raw ads.txt declarations, revealed the true extent of consumer tracking across commercial websites.
Concurrently, threat research teams identified sophisticated botnets embedded in cheap consumer hardware. Investigations into budget Android streaming devices (such as the H96 TV stick series) revealed pre-installed malware leveraging residential proxies to simulate mobile phone users. These hijacked devices generated millions of illegitimate ad clicks on automated, AI-generated content farms.
3. The Launch of DecryptAds (2026)
Recognizing that individual declaration files are easily manipulated or obscured when viewed in isolation, Zach Edwards and his research team developed DecryptAds to continuously scrape and map global adtech files. By synthesizing ads.txt, app-ads.txt, and sellers.json into relational threat matrices, DecryptAds introduced several novel intelligence feeds, including a Quiet Removals Feed to track silently dropped ad exchanges, a Legal Dossier Lookup for deep organizational footprinting, and a Geo-Risk Engine to identify high-risk jurisdictions.
Supporting Context & Metrics: Deconstructing the Web’s Hidden Supply Chain
Understanding the risks exposed by DecryptAds requires examining how programmatic ad auctions function on modern web platforms. When a user loads a webpage, an automated real-time bidding (RTB) process occurs in milliseconds. Dozens of intermediaries inspect the user’s IP address, device telemetry, browsing history, and geographic location to bid on displaying an advertisement.
Anatomy of Mainstream Exposure: The espn.com Case Study
A baseline query on DecryptAds for sports media giant espn.com illustrates the extreme density of the modern tracking surface:
Declared Ad Partners: 143 distinct advertising technology entities integrated via ads.txt and app-ads.txt.
Registered Data Brokers: 19 distinct broker domains active on the platform.
Geolocation Surveillance: DecryptAds metrics indicate that nearly 50% of these registered data brokers systematically extract granular geographic telemetry from visitors who do not utilize network- or browser-level ad blockers.
Sensitive Telemetry: At least 3 declared data brokers explicitly state in regulatory filings that they collect device fingerprints and sensitive personal information.
Threat Metric / Category
espn.com
Military News Outlets (e.g., ArmyTimes)
Opera Browser Infrastructure
Total Ad Partners
143
100+
300+
Registered Data Brokers
19
Multiple
27
Geo-Risk Entities (RU/CN/UAE/CY)
4
4+
27
Primary Data Collected
Geolocation, Device ID
Geolocation, Behavioral
Telemetry, Device Fingerprints
Sanctioned Financial Ties
Yes (Alfa Bank via Between Digital)
Yes (Alfa Bank via Between Digital)
Indirect ties via foreign parent
High-Risk Entities and Foreign Intelligence Vectors
DecryptAds automatically flags entities incorporated in or routing infrastructure through high-risk geographic regions, including Russia, China, Cyprus, the United Arab Emirates (UAE), and secrecy havens like Panama.
The Between Digital Dossier
DecryptAds highlighted Between Digital, an adtech network displaying a public office address in New York. However, deep cross-referencing of publisher offer documentation revealed that Between Digital processes publisher disbursements through Alfa Bank—Russia’s largest private commercial bank, which was placed under strict U.S. Treasury sanctions in 2022 following Russia’s invasion of Ukraine.
Further analysis via DecryptAds revealed:
Pervasive Footprint: Between Digital actively operates across approximately 55,000 publisher websites.
Defense Sector Infiltration: High-profile U.S. defense news outlets—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—authorize Between Digital to serve ads and collect user data within their public ads.txt declarations.
Double-Sided Bidding Risks: On nearly two-thirds of its declared portfolio, Between Digital operates simultaneously as both a publisher and a reseller. This dual role creates significant conflicts of interest, allowing bad actors to artificially direct corporate ad spend into self-owned properties or redirect traffic to unchecked infrastructure.
+─────────────────────────────────────────────────────────────────────────+
| BETWEEN DIGITAL INFRASTRUCTURE & TIES |
+─────────────────────────────────────────────────────────────────────────+
[ 55,000+ Publisher Websites ] (e.g., ArmyTimes, DefenseNews, ESPN)
│
▼
[ Between Digital Network ] (Acts as both Publisher & Reseller)
│
▼
[ Financial Processing ] ──► [ Alfa Bank (Sanctioned Russian Entity) ]
The Opera Browser Profile
Despite maintaining operational headquarters in Oslo, Norway, the widely used Opera Web Browser has been majority-owned and controlled by the Chinese firm Kunlun Tech since 2016. A DecryptAds scan of opera.com identifies 27 registered data brokers, including 15 adtech entities based in the UAE, six in China, three in Cyprus, two in Russia, and one in Hong Kong. While these foreign entities constitute roughly 7% of Opera’s total declared ad partners, their presence highlights the cross-border risk inherent in modern browser platforms.
Malvertising, AI "Slop" Farms, and Botnet Cross-References
A critical insight provided by DecryptAds is how malicious advertising actors interact with synthetic internet content. Malvertising campaigns rarely target high-tier domains like espn.com directly, as major media outlets invest heavily in third-party verification tools (e.g., Human Security, GeoEdge) to inspect bid payloads.
Instead, bad actors rely on AI slop websites—low-cost, automated content farms publishing AI-generated articles on topics ranging from home repair to hunting. These low-quality sites install low-tier ad partners without verifying their security posture, creating an ideal environment for zero-click malware distribution.
Case Study: The Fengwo Group / H96 Botnet Connection
Initial Malicious Activity: Security researchers at Bitsight identified that cheap H96 Android TV streaming sticks contained firmware-level malware that hijacked home internet connections to run residential proxy networks.
Device Spoofing: When idle, these streaming sticks spoofed their user-agent headers to impersonate mobile phones clicking on ads across AI slop sites like medicalbeautyhub[.]com.
DecryptAds Pivot: Running a DecryptAds Legal Dossier on medicalbeautyhub[.]com revealed a shared Seller ID (1674071) with a gaming domain, giacoloredstones[.]com.
Network Exposure: Pivoting on secondary Seller IDs (103488000) linked the operation directly to hundreds of active, ad-saturated utility websites hosted within Russia’s Yandex advertising ecosystem.
[ Malicious H96 TV Stick ] ──► (Spoofs Mobile Device User-Agent)
│
▼
[ AI Slop Site: medicalbeautyhub.com ] ──► (Seller ID: 1674071)
│
▼
[ Game Site: giacoloredstones.com ] ──► (Seller ID: 10348000)
│
▼
[ Russia Yandex Ad Network ] ◄────────────────────┘
Official Statements & Threat Research Insights
Statements from DecryptAds Leadership
Speaking on the launch of the platform, Zach Edwards, Chief Research Officer at DecryptAds and Threat Researcher at Infoblox, emphasized the platform’s focus on addressing longstanding cybersecurity blind spots:
"It’s an adtech tool, but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved. Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."
Addressing the structural hazards of ad networks playing both sides of the digital auction block, Edwards noted:
"When an adtech firm is listed as both a publisher and a reseller across two-thirds of their portfolio, they are basically playing both sides of the bidding equation. This creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest. The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."
Commenting on the dynamics of malvertising and the rise of automated AI content hubs, Edwards explained:
"None of these slop AI content farms are paying for ad-verification protection. They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on high-traffic mainstream sites, but rather on some lower quality content farm that someone reached via a search query. A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis."
The "Quiet Removals" Problem
Edwards also pointed out a fundamental transparency failure within the digital advertising industry: the reliance on secret bans. When major ad exchanges discover that a reseller is engaging in click fraud or distributing malvertising, they routinely remove the offending entity from their sellers.json file without issuing a public warning or reporting the incident to peer networks.
[ Ad Exchange Detects Malvertising / Ad Fraud ]
│
▼
[ Silent Removal of Seller ID from sellers.json ]
│
▼
[ No Public Disclosure / No Cross-Industry Alert ]
│
▼
[ Offender Migrates to Unaware Secondary Exchange ]
DecryptAds addresses this accountability gap by operating a real-time Quiet Removals Feed, alerting researchers whenever a vendor is silently dropped from an exchange’s programmatic records.
Future Outlook & Consumer/Enterprise Defense Strategies
The Technical Frontier: Mandatory Supply Chain Objects (SCO)
The next battlefield in adtech threat intelligence centers on the Supply Chain Object (SCO). The SCO is a structured data node embedded in OpenRTB bid requests that acts as a cryptographically verifiable manifest, recording every node, reseller, and intermediary involved in passing an ad impression from publisher to buyer.
Currently, major advertising platforms process SCO data server-side and rarely expose it to end users or threat analysts. Security researchers argue that forcing the public disclosure of SCO logs is essential to tracing zero-click exploits back to the precise demand-side entity that funded the malicious bid.
Tactical Defense Matrix: Enterprise and Consumer Guidance
To mitigate the tracking and security risks inherent in the modern web ecosystem, cybersecurity experts strongly advocate for defense-in-depth measures designed to strip advertising code before it executes.
+─────────────────────────────────────────────────────────────────────────+
| DEFENSE-IN-DEPTH MATRIX |
+─────────────────────────────────────────────────────────────────────────+
[ Browser Layer ] ──► uBlock Origin Lite / NoScript (Content Filtering)
[ Network Layer ] ──► Pi-hole / DNS Sinkholing (Hardware Block)
[ Application Layer]──► Mobile Web over Native Apps (Limits Telemetry)
1. Browser-Level Ad Blockers
uBlock Origin Lite: Highly recommended open-source browser extension that efficiently blocks tracking scripts, ad network domains, and malicious redirects without excessive resource consumption.
Adblock Plus: A viable alternative for iOS (iPhone/iPad) ecosystems, supporting custom filtering rules from maintainers like EasyList.
NoScript: Advanced script-blocking extension that prevents all non-whitelisted JavaScript execution. While effective at neutralizing malvertising, it requires active management by technical users to fix broken site functionality.
2. Network-Level Hardware Sinkholing (Pi-hole)
For comprehensive protection across all local network devices—including smart TVs, IoT hardware, and mobile devices—users can deploy a Pi-hole DNS sinkhole:
Hardware: Install a lightweight Linux OS on a low-cost microcomputer, such as a Raspberry Pi, equipped with a microSD card.
Software: Deploy the open-source Pi-hole application suite.
Network Configuration: Update the local router’s DHCP settings to route all DNS queries through the Pi-hole IP address.
Impact: Advertisements, telemetry beacons, and known malvertising domains are dropped at the DNS layer before reaching any end-user device.
3. App Hygiene and Mobile Tracking Hazards
Modern online platforms frequently urge users to download dedicated mobile applications rather than accessing content via standard mobile web browsers. This push is rarely driven by user experience enhancements; instead, native mobile applications allow companies to bypass browser-based privacy controls and collect extensive telemetry, including precise GPS location data, hardware serial numbers, and Bluetooth scanning metrics.
Additionally, many modern mobile applications default users into opt-in data collection programs used to train large language models (LLMs) and telemetry brokers.
+─────────────────────────────────────────────────────────────────────────+
| BROWSER VS. NATIVE APP PRIVACY |
+─────────────────────────────────────────────────────────────────────────+
Mobile Web Browser:
[ Restricted Sandbox ] ──► Blocking Extensions Active ──► Limited Telemetry
Native Mobile App:
[ System-Level Access ] ──► Direct Sensor Access ──► Unchecked Data Harvest
Recommended Practices:
Prioritize accessing services via privacy-hardened mobile browsers over native applications whenever possible.
Frequently audit application permissions on mobile operating systems and connected Smart TVs.
Consult transparency indexing tools like DecryptAds prior to installing novel mobile utilities or connected device software.
As the adtech ecosystem continues to converge with corporate espionage, malvertising delivery networks, and data broker surveillance, platforms like DecryptAds provide essential visibility—giving threat researchers and the public the tools necessary to audit the hidden networks tracking their online activity.