The Adtech Shadow: Unmasking the Surveillance Ecosystem with DecryptAds

For the average internet user, the digital advertising ecosystem is a black box. We visit a website or launch a mobile application, and within milliseconds, a complex, automated auction occurs behind the scenes. This auction determines which ads are displayed, which data brokers receive your information, and which tracking pixels are embedded in your session. Until now, this information—while technically public—was locked away in fragmented, non-standardized files, accessible only to industry insiders and sophisticated data scrapers.

A new, free service called DecryptAds aims to shatter this opacity. By scraping and correlating the files that websites and apps are required to publish to disclose their advertising partners, the platform provides a clear window into the entities harvesting your data. As digital privacy concerns reach a fever pitch, DecryptAds offers a critical tool for researchers, security professionals, and privacy-conscious citizens to map the sprawling, often hidden, supply chains of the adtech industry.

The Anatomy of Digital Transparency

At the heart of the advertising internet lie three essential files: ads.txt, app-ads.txt, and the sellers.json / buyers.json specifications. These files were originally designed by the Interactive Advertising Bureau (IAB) to prevent ad fraud by allowing publishers to declare which companies are authorized to sell their ad inventory.

DecryptAds, led by Chief Research Officer Zach Edwards—a veteran threat researcher at the security firm Infoblox—has taken these disparate, cryptic files and transformed them into a searchable, analytical database.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards explains. "The industry has historically treated these files as compliance checklists. We treat them as a map of the threat landscape. These are the building blocks for privacy and security use cases that have been dramatically underserved."

The service excels at identifying the "broken cross-references" that signal supply-chain integrity issues. These include cloned declaration sets across unrelated domains, suspicious seller removals, and supply paths that appear in bid logs but never in a publisher’s authorized-seller list. By aggregating this data, DecryptAds allows users to see the entire web of partnerships that a single website maintains, rather than viewing each file in isolation.

Chronology of a Data-Driven Revolution

The launch of DecryptAds comes at a pivotal moment in the history of digital privacy regulation. For years, the adtech industry operated with minimal oversight, relying on the assumption that the average user would never possess the technical capacity to audit an ads.txt file.

However, the tide began to turn with the passage of state-level data broker registration laws in California, Oregon, Texas, and Vermont. These mandates forced companies to disclose their data-buying and selling activities, providing a new layer of raw data that DecryptAds has successfully ingested.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The service has already begun to uncover startling patterns. By analyzing the ads.txt and app-ads.txt files of major digital entities, DecryptAds has revealed that some of the world’s most popular platforms maintain dozens, sometimes hundreds, of data broker relationships. For example, a recent scan of the sports network espn.com identified 143 ad partners and 19 registered data brokers. Nearly half of these brokers are actively collecting geolocation data from visitors, while others are harvesting device fingerprints—a technique used to uniquely identify and track users even when cookies are blocked.

Supporting Data: Risks Across Borders

One of the most concerning features of DecryptAds is its "Geo-Risk" indicator. This feature flags advertising partners based in high-risk jurisdictions, including Russia, China, and countries with deep financial ties to these nations, such as the United Arab Emirates (UAE) and Cyprus.

The implications for national security and corporate privacy are profound. Consider the case of Between Digital, an adtech firm that lists a New York address but is revealed by DecryptAds to be a Russian-based entity. The dossier shows that their publisher payouts are processed through Alfa Bank, Russia’s largest private commercial bank, which has been under U.S. sanctions since 2022.

Despite these red flags, DecryptAds reports that Between Digital is permitted to serve ads and track users on approximately 55,000 websites, including several prominent U.S. military news outlets such as armytimes.com and defensenews.com. When a company acts as both a publisher and a reseller—a practice noted by Edwards—they essentially play both sides of the bidding equation, creating clear conflicts of interest and avenues for data exploitation.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Furthermore, the popular Opera browser illustrates the global scale of this issue. While its operational headquarters are in Norway, it is majority-owned by the Chinese firm Kunlun Tech. DecryptAds identifies 27 data brokers collecting information through Opera.com, including numerous partners in China, Russia, and the UAE.

The "Legal Dossier" and the Rise of AI Slop

The platform’s "Legal Dossier" feature has become an essential resource for investigative journalists. It allows users to trace the ownership of domains and apps, often revealing the true actors behind "AI-generated slop"—a growing phenomenon where low-quality, machine-generated websites are used as vehicles for aggressive ad-tracking and malvertising.

Recent investigations into H96 streaming sticks revealed that these devices were not just streaming pirated content; they were surreptitiously spoofing mobile phone traffic to click on ads hosted by the Fengwo Group, a Chinese entity. DecryptAds was able to confirm that these malicious websites shared seller IDs with other low-quality gaming and utility sites, effectively mapping the entire infrastructure used to commit large-scale ad fraud.

Edwards notes that this "malvertising" is rarely directed at high-traffic, well-protected sites like ESPN. Instead, the primary targets are low-quality content farms that prioritize ad revenue over user security. "Most malvertising attacks don’t happen on espn.com," Edwards notes. "They happen on some lower-quality content farm that a user stumbled upon via a search engine. These sites don’t pay for protection; they sign up the lowest-quality ad partners, creating a greased rail for zero-click payloads."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Official Responses and Industry Accountability

To date, the adtech industry has maintained a "quiet removals" policy. When an ad network suspects an advertiser of fraud or malware, they often remove the offender from their sellers.json file without public notice. This lack of transparency allows malicious actors to simply pivot to a different, less-scrutinized network.

DecryptAds’ "Quiet Removals Feed" provides the first public-facing accountability for these actions, tracking these hidden deletions across exchanges. Edwards argues that the only way to truly solve the malvertising crisis is for major ad networks to share the "Supply Chain Object" (SCO). This structured data, currently kept server-side, would allow researchers to see every intermediary involved in an ad impression. "If we can encourage the industry to expose the SCO, it will finally be possible to hold the culprits behind bad ads accountable," says Edwards.

Implications for the Modern Web User

For the end user, the findings from DecryptAds serve as a stark reminder: the digital environment is not neutral. Every ad impression is a potential data point, and every "free" app or website may be extracting far more value from your data than you realize.

Practical Steps for Enhanced Privacy:

  1. Block Ads at the Source: Using tools like uBlock Origin Lite in desktop browsers is a baseline necessity. For mobile, while options are more limited, Adblock Plus remains functional on iOS, and Firefox with content blocking provides a stronger defense on Android.
  2. Network-Level Blocking: For those seeking the highest level of security, a Raspberry Pi running Pi-hole acts as a network-wide DNS sinkhole, stripping ads and trackers before they ever reach your devices.
  3. Avoid Unnecessary Apps: The push toward proprietary mobile apps is often a strategic move to facilitate deeper data collection. Where possible, interact with services via a browser rather than a dedicated app.
  4. Audit Your Tools: If you are a power user, consider using the DecryptAds API to monitor the trackers associated with the apps you use daily.

The work of Zach Edwards and the team at DecryptAds marks the end of the "trust us" era of digital advertising. By making the invisible visible, they have provided the public with the tools necessary to demand accountability from an industry that has long thrived in the shadows. As we look toward the future, the ability to map these supply chains will be the difference between a web that serves the user and a web that treats the user as the product.

Leave a Reply

Your email address will not be published. Required fields are marked *