Unmasking the Adtech Ecosystem: DecryptAds Service Exposes Hidden Trackers, Sanctioned Entities, and AI-Generated Slop

The labyrinthine digital advertising ecosystem has long operated behind a veil of opaque opacity, leaving everyday internet users and cybersecurity professionals in the dark about who exactly is harvesting their data and serving targeted content. While regulatory disclosures mandate that websites and mobile applications publish machine-readable text files detailing their authorized advertising partners and data brokers, this vast sea of information has traditionally remained walled off within large advertising platforms. Parsing these raw files manually requires specialized data engineering capabilities, rendering the underlying supply chains virtually inscrutable to the average consumer and even to corporate security teams.
This transparency barrier is now being systematically dismantled by DecryptAds, a powerful, newly launched, and free intelligence service designed to scrape, aggregate, and cross-reference adtech metadata. By bridging the gap between public disclosures and actionable analytics, decryptads.com allows researchers, privacy advocates, and enterprise defenders to gain immediate visibility into the hidden networks tracking web traffic across personal computers, mobile applications, and smart television interfaces.
Origins and Architecture of DecryptAds
The development of DecryptAds was spearheaded by a team of three industry veterans, including Zach Edwards, who serves as the service’s chief research officer alongside his primary role as a threat researcher at security firm Infoblox. Recognizing that individual disclosures—such as a website’s ads.txt file—provide little utility in isolation, the founders engineered a platform capable of ingesting and correlating multiple data streams simultaneously.
The underlying architecture of DecryptAds continuously monitors and ingests several key transparency registries mandated by the digital advertising industry:
- ads.txt (Authorized Digital Sellers): Public files published by website operators that list all adtech companies and data brokers permitted to monetize or extract telemetry from a given domain.
- app-ads.txt: The application-equivalent of ads.txt, extending transparency requirements to software environments running on mobile operating systems and smart televisions.
- buyers.json and sellers.json: Cryptographically signed or openly declared directory files detailing the specific corporate entities buying, selling, or reselling advertising inventory across specific exchanges.
According to Edwards, the platform was deliberately built to approach adtech from an adversarial security perspective rather than purely a commercial one. Supply-chain integrity failures, the platform’s documentation notes, rarely manifest neatly within a single isolated file. Instead, vulnerabilities and deceptive practices appear as broken cross-references between sellers.json and ads.txt files, cloned declaration sets across completely unrelated domains, unannounced seller removals across ad exchanges, and hidden supply paths embedded within server-side bid logs.

Deconstructing the Modern Ad Supply Chain: The ESPN Case Study
To understand the sheer scale of the commercial tracking apparatus, security analysts frequently point to high-traffic consumer destinations. A search within DecryptAds for the major sports portal espn.com exposes a complex corporate network consisting of 143 distinct advertising partners and 19 registered data broker domains declared across its web and application infrastructure.
The visibility into these data brokers has been gradually improving due to a wave of state-level privacy legislation. Jurisdictions including California, Oregon, Texas, and Vermont have enacted statutory requirements compelling data brokers to formally register if they acquire, aggregate, or trade consumer personal information originating from residents of those states. DecryptAds cross-references these state registries against publisher disclosures, revealing that nearly half of the data brokers linked to espn.com actively harvest precise geolocation data from visitors who fail to utilize ad-blocking technologies. Furthermore, three of these entities openly disclose that they capture device fingerprints and other sensitive behavioral indicators.
This deep interconnectivity underscores a fundamental reality of the modern web: visiting a mainstream media outlet exposes the user not just to the primary publisher, but to a sprawling auxiliary network of third-party intermediaries capable of tracking user movements across disparate platforms.
Geopolitical Risks and High-Risk Ad Partners
Beyond commercial tracking, DecryptAds introduces automated risk-scoring features that highlight advertising partners domiciled in geopolitical hotspots or jurisdictions under international trade restrictions. The platform’s "Geo-Risk" monitoring flags entities operating out of China, Russia, and intermediary financial hubs with deep political ties to both, such as Cyprus and the United Arab Emirates (UAE).
A prominent example surfaced during initial platform queries regarding espn.com, which was found to maintain commercial relationships with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists an official corporate address in New York City. However, a deep-dive dossier generated by DecryptAds classifies Between Digital as a Russian enterprise, documenting that its publisher payout documentation routes through Alfa Bank—Russia’s largest private commercial bank, which was subjected to severe economic sanctions by the United States government following the 2022 invasion of Ukraine.
Similar risk profiles emerge when examining critical national infrastructure and specialized media. Queries for top U.S. military-focused publications—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveal that all of these properties permit Between Digital to serve advertisements and track their readership. Additional partners identified on these military-adjacent sites include entities based in the UAE and the corporate secrecy haven of Panama. Industry data indicates that Between Digital’s tracking mechanisms are embedded across approximately 55,000 partner websites globally.

Pivoting on Between Digital’s app-ads.txt files exposes hundreds of domains dedicated to lightweight, web-based mobile games designed to interrupt gameplay with frequent ad loads. Analysts note that Between Digital operates as both a publisher and a reseller on roughly two-thirds of its own portfolio, positioning it on both sides of the programmatic bidding equation. This dual-hatted role creates inherent conflicts of interest, allowing intermediaries to direct client advertising spend toward their own owned-and-operated properties with minimal external oversight.
Similar geopolitical entanglements extend to widely used consumer software. The Opera web browser, which maintains an active global user base, has been majority-owned and controlled by the Chinese technology conglomerate Kunlun Tech since 2016, even though its operational headquarters remain in Oslo, Norway. The DecryptAds profile for opera.com catalogs 27 registered data brokers, including 15 adtech partners based in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These foreign entities represent a minor fraction of the total adtech partners declared in Opera’s transparency files, illustrating the immense breadth of international data-sharing inherent in standard browser operations.
Exposing Legal Dossiers and Malicious Infrastructure
One of the platform’s most powerful forensic features is its Legal Dossier lookup tool. Although resource-intensive—often requiring several minutes to compile queries—this function aggregates historical domain registration data, corporate ownership filings, corporate aliases, and structural relationships between ad networks and downstream web properties.
This capability has proven vital in tracking sophisticated cybercrime operations. In prior investigations conducted by security firm Bitsight, researchers uncovered a widespread supply-chain compromise involving popular "H96" Android-based TV streaming sticks. These devices were found to covertly rent out idle residential internet connections to external proxies while simultaneously spoofing mobile device signatures to simulate ad clicks on automated, low-quality websites. Bitsight traced this fraudulent click-generation network back to the Fengwo Group, a Chinese entity responsible for deploying malicious mobile applications across the streaming hardware.
By executing a DecryptAds legal dossier query on a dormant Fengwo Group domain associated with a fake lifestyle blog (medicalbeautyhub.com), researchers discovered that the site shared a specific seller ID (1674071) with an unrelated gaming portal (giacoloredstones.com). Pivoting on a secondary seller ID (103488000) discovered within that network exposed hundreds of active websites operating within the Russian Yandex ad exchange, all churning out low-quality gaming and utility content engineered specifically to bombard users with automated advertising traffic.
Quiet Removals and the Mechanics of Ad Fraud
A persistent challenge in combating ad fraud and malicious monetization has been the opaque manner in which ad networks handle rogue participants. When major ad exchanges suspect an advertiser of generating unauthentic traffic, click fraud, or malicious content, standard industry procedure often involves quietly excising the offender from internal sellers.json files without issuing public disclosures or notifying affected publishers.

This lack of transparency allows compromised or malicious adtech actors to migrate seamlessly to alternative exchanges, continuing their operations under new aliases. To counteract this information vacuum, DecryptAds incorporates a "Quiet Removals Feed." This component continuously monitors and correlates sellers.json updates across multiple ad exchanges, tracking when specific seller names or domain IDs suddenly vanish from authorized lists. By synthesizing these fragmented data points, security analysts can track the real-time blacklisting of fraudulent actors across the global programmatic advertising ecosystem.
Malvertising, AI-Generated Slop, and Supply Chain Objects
The proliferation of artificial intelligence has catalyzed a massive expansion of low-quality, automated content farms—colloquially termed "AI slop." These sites, which churn out machine-generated articles, recipes, and decorating guides, serve as prime breeding grounds for malvertising: malicious ad campaigns designed to redirect unsuspecting visitors to phishing portals or deploy zero-click exploit payloads.
Unlike major publishing platforms that invest heavily in sophisticated brand-safety and ad-verification tools to intercept malicious code, AI content farms operate with minimal overhead. They routinely onboard the lowest-tier advertising partners willing to monetize unvetted traffic, creating a frictionless pathway for threat actors to target casual web surfers.
Security researchers emphasize that addressing malvertising requires a structural shift in how ad exchanges share data. Specifically, experts advocate for the industry-wide exposure of the "Supply Chain Object" (SCO)—structured metadata attached to every programmatic bid request that documents every intermediary, reseller, and buyer involved in a transaction. While server-side bid logs contain the SCO data necessary to trace the exact financial origin of a malicious ad payload, major ad networks generally withhold this information from the public sphere, shielding bad actors and hindering collaborative threat mitigation.
To facilitate automated research and integration into modern defensive workflows, DecryptAds provides a robust application programming interface (API), enabling enterprise security teams and AI systems to query adtech dossiers programmatically.
Mitigation Strategies for Consumers and Organizations
Given the extensive surveillance and security risks inherent in the modern programmatic advertising apparatus, security professionals universally recommend deploying robust countermeasures at both the endpoint and network levels.

Browser-Level Defenses
For traditional desktop and laptop environments, open-source extensions such as uBlock Origin Lite provide efficient, lightweight blocking of ads and tracking scripts. While mobile browser support varies, similar privacy extensions can be deployed on Android-compatible versions of Firefox. For iOS users on iPhones and iPads, applications like Adblock Plus offer baseline protection, while advanced users can configure custom blocking lists sourced from community registries like easylist.to.
Aggressive script-blocking tools such as NoScript offer comprehensive protection by preventing unverified JavaScript from executing, though such tools often degrade the user experience on modern, script-heavy web applications.
Network-Level Defenses
For technically proficient users seeking a scalable, infrastructure-level solution, hardware-based DNS sinkholes represent the gold standard of local network protection. By deploying lightweight, low-cost single-board computers like a Raspberry Pi running open-source software such as Pi-hole, administrators can intercept and block telemetry, ad-serving domains, and tracking requests across every connected device on a local area network.
Mobile App Vigilance
Security experts caution that network-level blockers often fail to intercept tracking telemetry originating from dedicated mobile applications. Many commercial services aggressively pressure users into installing proprietary mobile apps under the guise of an enhanced user experience. In reality, these applications frequently serve as conduits for persistent behavioral tracking, precise geolocation harvesting, and opt-in data collection used to train commercial large language models.
As the digital landscape becomes increasingly saturated with automated content farms and opaque advertising intermediaries, services like DecryptAds provide critical visibility into an otherwise lawless data-broker economy, empowering users and defenders alike to reclaim control over their digital privacy.







