The modern digital ecosystem relies heavily on programmatic advertising to monetize web traffic, mobile applications, and connected devices. However, behind the seamless presentation of online content lies a vast, highly opaque web of adtech intermediaries, data brokers, real-time bidding (RTB) exchanges, and tracking networks. For over a decade, determining which corporate entities are permitted to run scripts, display advertisements, or harvest user data on any given website or application has remained a formidable challenge for privacy advocates and cybersecurity researchers alike.
While publishers are legally and contractually required to publish semi-public manifest files—such as ads.txt and app-ads.txt—to declare their authorized advertising partners, this raw data has historically remained fragmented, difficult to parse, and siloed within proprietary adtech platforms. This lack of transparency has allowed bad actors to exploit the digital advertising supply chain for malicious purposes, ranging from zero-click malware distribution and ad fraud to foreign intelligence gathering.
To address this systemic vulnerability, threat researcher Zach Edwards—Chief Research Officer at DecryptAds and Threat Researcher at Infoblox—alongside two co-founders, launched DecryptAds (decryptads.com). The free public platform continually scrapes, correlates, and analyzes semi-public declaration files and transaction logs across the global adtech landscape. By transforming disaggregated, unparsed raw data into actionable intelligence, DecryptAds exposes high-risk ad networks, uncovers conflicts of interest among programmatic exchanges, tracks AI-generated "slop" content farms, and provides unprecedented visibility into the entity networks tracking daily internet users.
Detailed Chronology: The Evolution of AdTech Transparency and the Rise of DecryptAds
+---------------------------------------------------------------------------------+
| PROGRAMMATIC ADTECH TIMELINE |
+---------------------------------------------------------------------------------+
| 2017–2019 : IAB Tech Lab introduces `ads.txt`, `app-ads.txt`, and `sellers.json` |
| standards to curb domain spoofing and publisher fraud. |
| |
| 2022 : U.S. sanctions major Russian financial institutions (including |
| Alfa-Bank) following the invasion of Ukraine. |
| |
| 2023–2024 : U.S. states (CA, OR, TX, VT) enact data broker registration laws, |
| forcing increased public disclosures of consumer data buyers. |
| |
| July 2026 : Threat researchers reveal H96 streaming sticks spoofing mobile |
| devices to click ads on AI-generated "slop" websites. |
| |
| Aug 2026 : Launch of DecryptAds.com to correlate cross-file adtech data and |
| expose geopolitical risk networks and silent adtech removals. |
+---------------------------------------------------------------------------------+
The Origins of Standardized Ad Manifests
Between 2017 and 2019, the Interactive Advertising Bureau (IAB) Tech Lab launched several initiatives aimed at reducing ad fraud, specifically domain spoofing and illicit arbitrage. The resulting standards included:
ads.txt (Authorized Digital Sellers): A plain-text file hosted at the root domain of a website listing all entities authorized to sell or resell the site’s ad inventory.
app-ads.txt: An extension of ads.txt designed for mobile applications and Connected TV (CTV) platforms.
sellers.json & buyers.json: Files published by ad exchanges and Supply-Side Platforms (SSPs) identifying the direct sellers, intermediaries, and buyers participating in bid streams.
Although these files were intended to provide supply-chain clarity, they quickly became unmanageable. Large publishers routinely added thousands of lines of declarations without auditing downstream relationships. Consequently, security teams were left without an effective mechanism to cross-reference ads.txt entries against exchange-level sellers.json declarations or evaluate geographic and security risks.
The Emergence of Cross-File Correlation
Recognizing that security threats operate across multiple disjointed data streams rather than isolated files, Zach Edwards and his team developed a multi-stage ingestion engine for DecryptAds. By continually harvesting millions of web and mobile manifests, the platform reconstructs supply paths and identifies structural anomalies.
Supply-chain integrity issues rarely present themselves in a single file; instead, they surface as broken cross-references between web and mobile declarations, cloned declaration sets deployed across unrelated domain clusters, and discrepancies between authorized-seller lists and actual real-time bid logs.
Supporting Context & Technical Case Studies
DecryptAds provides threat intelligence by cross-referencing disparate data streams to highlight critical vulnerabilities across mainstream media, national security news portals, web browsers, and consumer hardware.
+---------------------------------------------------------------------+
| DECRYPTADS CORRELATION PIPELINE |
+---------------------------------------------------------------------+
| [ Website/App Manifests ] [ Exchange Data ] [ State Registries ] |
| ads.txt / app-ads.txt sellers.json CA, OR, TX, VT Data |
| | | Broker Filings |
| +-------------------+----+------------------+ |
| | |
| v |
| [ DecryptAds Data Engine ] |
| | |
| +-----------------------+-----------------------+ |
| | | | |
| v v v |
| [ Geo-Risk Flags ] [ Quiet Removals Feed ] [ Legal Dossier ] |
| Russia/China/UAE Silent delistings across Correlation & seller |
| financial paths ad exchanges ID pivoting |
+---------------------------------------------------------------------+
Case Study 1: Mainstream Media & High-Risk Geopolitical Connections
A query for major sports entertainment network espn.com reveals the sheer scale of modern programmatic tracking:
143 Ad Partners and 19 Registered Data Broker Domains declared within its ads.txt and app-ads.txt files.
Data Broker Disclosures: Benefiting from data broker registration mandates in California, Oregon, Texas, and Vermont, DecryptAds correlates filings showing that nearly half of these registered brokers collect precise geolocation data from unblocked visitors. Three brokers explicitly collect device fingerprints and sensitive personal information.
Geopolitical Risk ("Geo-Risk"): DecryptAds automatically flags entities originating in or maintaining financial ties to high-risk jurisdictions, including China, Russia, Cyprus, and the United Arab Emirates (UAE). espn.com declares four advertising entities associated with these areas.
+------------------------------------------------------------------------------------+
| ESPN.COM ADTECH SUPPLY CHAIN ANALYSIS |
+------------------------------------------------------------------------------------+
| Total Declared Ad Partners : 143 |
| Registered Data Brokers : 19 |
| Geolocation Data Collectors : ~50% of declared brokers |
| Geo-Risk Entities Identified: 4 (Russia, China, UAE) |
+------------------------------------------------------------------------------------+
| Highlighted High-Risk Partner: Between Digital |
| - Claimed Location : New York, USA |
| - Financial Infrastructure : Publisher offers routed via Alfa-Bank (Russia) |
| - Regulatory Status : Alfa-Bank placed under U.S. sanctions in 2022 |
| - Partner Site Footprint : Serves ad data across ~55,000 domains |
+------------------------------------------------------------------------------------+
A prominent example is Between Digital. Although the firm lists a New York business address, DecryptAds’ legal dossier flags it as a Russian enterprise. Its publisher documentation indicates that financial settlements are processed through Alfa-Bank—Russia’s largest private commercial bank, which was placed under strict U.S. sanctions in 2022 following the invasion of Ukraine.
Case Study 2: National Security Exposures Across Defense Outlets
The potential intelligence value of adtech telemetry becomes particularly sensitive when applied to specialized reader populations. Audit queries across leading U.S. military news portals reveal widespread adoption of high-risk adtech vendors:
+------------------------------------------------------------------------------------+
| DEFENSE PUBLISHER MAP & BETWEEN DIGITAL INTEGRATION |
+------------------------------------------------------------------------------------+
| Targeted Defense Outlets: |
| - armytimes.com - airforcetimes.com - defensenews.com |
| - navytimes.com - marinecorpstimes.com - federaltimes.com |
+------------------------------------------------------------------------------------+
| Common Threat Profile: |
| - Authorized Vendor : Between Digital (Sanctions-linked financial pipeline) |
| - Offshore Intermediaries: 2 UAE entities, 1 Panama secrecy-haven entity |
| - Implication : Telemetry from military & defense personnel accessible |
| by entities operating in foreign jurisdictions |
+------------------------------------------------------------------------------------+
Between Digital maintains ad-serving and tracking authorization across all six military outlets while collecting telemetry from roughly 55,000 partner websites globally. Pivoting on Between Digital’s app-ads.txt file reveals a vast ecosystem of hundreds of basic web-based gaming sites designed to trigger frequent ad impressions.
Furthermore, Between Digital acts as both a publisher and a reseller across roughly two-thirds of its declared portfolio. This dual role allows an adtech vendor to operate on both sides of the programmatic transaction, creating opportunities for self-dealing, artificial price inflation, and opaque traffic routing.
Case Study 3: Browser Ecosystem Telemetry (Opera)
The operational footprint of web browsers presents additional supply-chain considerations. Although Opera maintains its operational headquarters in Oslo, Norway, it has been majority-owned and controlled by the Chinese firm Kunlun Tech since 2016.
+------------------------------------------------------------------------------------+
| OPERA.COM ADTECH TRACKING BREAKDOWN |
+------------------------------------------------------------------------------------+
| Total Data Brokers Identified : 27 Registered Brokers |
+------------------------------------------------------------------------------------+
| Geographic Breakdown of Foreign AdTech Partners: |
| [UAE] : 15 partners |
| [China] : 6 partners |
| [Cyprus] : 3 partners |
| [Russia] : 2 partners |
| [HK/UA] : 2 partners (1 Hong Kong, 1 Ukraine) |
+------------------------------------------------------------------------------------+
| Operational Note: Foreign risk entities represent 7% of total declared adtech |
| partners, demonstrating the density of cross-border data routing. |
+------------------------------------------------------------------------------------+
Case Study 4: Botnets, Cheap Consumer Hardware, and AI "Slop" Networks
DecryptAds’ Legal Dossier feature automates cross-file correlation to expose broader threat infrastructure. Recent investigations by security firm Bitsight demonstrated how cheap, unbranded Android TV streaming sticks (such as the H96 series) were pre-loaded with malware. When idle, these devices silently proxied internet traffic, spoofed mobile phone identifiers, and generated fake ad clicks on networks of AI-generated content hubs ("AI slop sites").
Investigations into the malicious app developers linked to these devices—specifically the Fengwo Group—demonstrate how DecryptAds traces ad fraud infrastructure:
+------------------------------------------------------------------------------------+
| FENGWO GROUP AD FRAUD & SLOP NETWORK CORRELATION |
+------------------------------------------------------------------------------------+
| [ Malicious H96 TV Sticks ] ---> Spoofs Mobile Identifiers |
| | |
| v |
| [ AI Slop Target Site ] ---> medicalbeautyhub[.]com |
| | |
| v (Shares Seller ID: 1674071) |
| [ Linked Gaming Portal ] ---> giacoloredstones[.]com |
| | |
| v (Pivots to Seller ID: 103488000) |
| [ Yandex Ad System ] ---> Hundreds of low-quality Russian utility sites |
| monetized via programmatic ad injection |
+------------------------------------------------------------------------------------+
Querying an AI slop domain like medicalbeautyhub[.]com reveals Seller ID 1674071.
This Seller ID bridges directly to another gaming domain, giacoloredstones[.]com.
Analyzing secondary declarations reveals Seller ID 103488000.
Pivoting on this ID uncovers hundreds of low-quality utility and gaming domains embedded within Russia’s Yandex ad network, illustrating how automated ad platforms can be leveraged to monetize illicit device networks.
The "Quiet Removals" Vulnerability
A major structural issue identified by DecryptAds is the adtech industry’s reliance on undocumented ban lists. When an ad exchange detects fraudulent traffic or malvertising from a vendor, it rarely publishes a public security report. Instead, the exchange quietly removes the offender from its sellers.json manifest.
+------------------------------------------------------------------------------------+
| TRADITIONAL vs. TRANSPARENT REMOVAL WORKFLOW |
+------------------------------------------------------------------------------------+
| TRADITIONAL INDUSTRY PRACTICE (Opaque): |
| [ Ad Fraud Detected ] -> [ Silent Deletion from sellers.json ] -> [ No Alert ] |
| Outcome: Threat actor retains active connections on dozens of other exchanges. |
+------------------------------------------------------------------------------------+
| DECRYPTADS QUIET REMOVALS ENGINE (Transparent): |
| [ Constant Scrape Engine ] -> [ Diff Exchange Manifests ] -> [ Public Logging ] |
| Outcome: Instant notification of delta removals, exposing bad actors systemically. |
+------------------------------------------------------------------------------------+
This silence allows bad actors to continue operating across other platforms that have not yet detected the abuse. To resolve this, DecryptAds introduced the Quiet Removals Feed, which continuously tracks delta changes across major exchange manifests to log and highlight silent vendor removals in real time.
Official Statements & Expert Insights
Highlighting the vision behind the platform, Zach Edwards, Chief Research Officer at DecryptAds and Threat Researcher at Infoblox, emphasized that DecryptAds was built to reframe adtech analysis through a cybersecurity lens:
"It’s an adtech tool, but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved."
Addressing the inherent flaws of evaluating manifest files in isolation, Edwards noted:
"Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list."
Discussing the operational risks associated with programmatic arbitrage and self-dealing, Edwards observed:
"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest. The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."
On the Mechanics of Malvertising Delivery via AI Slop Sites:
"None of these slop AI content farms are paying for ad verification protection. They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather on some lower quality content farm that someone reached via a search query."
On the Strategic Necessity of Ad Supply-Chain Visibility:
"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis."
To effectively combat malvertising, Edwards advocates for the broad adoption and server-side exposure of the Supply Chain Object (SCO) within bid requests:
"That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload. You may see the malicious zero-click redirection, but without the supply chain object—which is only served server-side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad."
Future Outlook & Consumer Defense Protocols
The launch of DecryptAds highlights a broader shift toward treating online advertising networks as critical digital supply chains. However, enterprise defenders and everyday consumers face immediate privacy and security risks from persistent tracking and malvertising.
+------------------------------------------------------------------------------------+
| RECOMMENDED DEFENSE MATRIX & TAXONOMY |
+------------------------------------------------------------------------------------+
| DEPLOYMENT LEVEL | PRIMARY TOOL / TECHNIQUE | TARGET BENEFIT |
+---------------------+---------------------------------+----------------------------+
| Desktop Browser | uBlock Origin Lite | Content & Script Blocking |
| iOS / iPadOS | Adblock Plus / Safari Content | Mobile Web Tracking Limit |
| Advanced Scripting | NoScript | JS Execution Restriction |
| Local Network (Home)| Raspberry Pi + Pi-hole | Network-Wide DNS Sinkhole |
| Application Policy | Prefer Web Browser over Apps | Limits Hardware Telemetry |
+---------------------+---------------------------------+----------------------------+
Comprehensive Defensive Recommendations
Browser-Level Filtering:
uBlock Origin Lite: Recommended for desktop and Android-based browsers (e.g., Firefox for Android). It blocks third-party trackers, scripts, and ad vectors efficiently without heavy resource consumption.
Adblock Plus: Provides an accessible defense layer for iOS and iPadOS Safari users.
Custom Rule Integration: Power users can import maintained blocklists from communities like EasyList (easylist.to) to strip tracking parameters and ad containers.
Script Execution Control: Extensions like NoScript block untrusted JavaScript execution by default, preventing drive-by downloads and malicious redirects, though they require manual site configuration.
Network-Wide Hardware Sinkholing:
Deploying a Raspberry Pi configured with Pi-hole creates a centralized DNS sinkhole for local area networks (LANs).
By altering router settings to route all DNS queries through Pi-hole, network administrators can intercept and drop known tracking, telemetry, and ad-serving domain requests across all connected devices, including Smart TVs, mobile phones, and IoT appliances.
App Minimization Strategy:
Security researchers strongly caution against installing dedicated mobile or Smart TV applications when web-based equivalents exist.
Mobile applications operate outside the protective boundary of browser content blockers, allowing them to gather precise location telemetry, device identifiers, and network metrics that are frequently resold or used to train artificial intelligence models.
As programmatic advertising becomes increasingly complex, public platforms like DecryptAds provide necessary transparency—giving threat intelligence analysts, enterprise defenders, and privacy advocates the tools required to audit, map, and secure the modern web ecosystem.