Unveiling the Adtech Underworld: How DecryptAds Exposes Global Trackers, Sanctioned Entities, and AI-Generated Slop

Main page Cyber Security & Privacy Unveiling the Adtech Underworld: How…
From ZizzMedia, the free news encyclopedia
Unveiling the Adtech Underworld: How DecryptAds Exposes Global Trackers, Sanctioned Entities, and AI-Generated Slop
Unveiling the Adtech Underworld: How DecryptAds Exposes Global Trackers, Sanctioned Entities, and AI-Generated Slop
Published: 23 August 2026
Author: Jia Lissa
Category: Cyber Security & Privacy
Read time: 11 min read
Words: 2,052

Executive Overview

The modern digital landscape is built upon an opaque, sprawling infrastructure of invisible trackers, data brokers, and advertising exchanges. For decades, the companies responsible for serving advertisements and harvesting personal data from websites and mobile apps have operated behind a veil of complex corporate structures and fragmented public files. While information regarding who is tracking users has technically been semi-public, it has historically remained walled off inside massive advertising platforms—virtually unparseable for the average internet user and profoundly difficult to cross-reference even for seasoned security researchers.

This opacity has created a fertile breeding ground for supply-chain vulnerabilities, malicious advertisements, state-sponsored cyber espionage, and an explosion of low-quality, AI-generated content farms commonly referred to as "AI slop."

Enter DecryptAds, a powerful, free-to-use new intelligence service launched at decryptads.com. Created by a team of prominent threat researchers—including Zach Edwards, chief research officer for DecryptAds and a threat researcher at security firm Infoblox—the platform fundamentally transforms how adtech transparency is approached. By continuously scraping, parsing, and cross-referencing public disclosure files such as ads.txt, app-ads.txt, and sellers.json, DecryptAds provides a holistic, security-first lens into the digital advertising ecosystem.

This article explores the mechanics of DecryptAds, examining how it exposes high-risk geopolitical ad partners, tracks down shadow actors operating across sanctioned jurisdictions, links seemingly unrelated AI-generated domains, and outlines actionable defense strategies for individuals navigating an increasingly hostile digital environment.


Detailed Chronology: The Genesis and Mechanics of Adtech Transparency

To understand the revolutionary nature of DecryptAds, one must first understand the fragmented architecture of digital advertising disclosures. Over the years, the Interactive Advertising Bureau (IAB) and other industry bodies introduced transparency files to combat ad fraud. These files include:

  • ads.txt (Authorized Digital Sellers): Text files published by websites that list all authorized adtech companies and data brokers permitted to sell or run advertisements on their properties.
  • app-ads.txt: The mobile and smart TV application equivalent of ads.txt, designed to prevent developer impersonation and inventory spoofing within apps.
  • buyers.json and sellers.json: Structured JSON files maintained by ad exchanges that identify the entities buying, selling, or reselling ad inventory.

While these files are publicly accessible, analyzing them in isolation yields virtually no actionable intelligence. Supply-chain integrity issues rarely manifest within a single, tidy document. Instead, vulnerabilities emerge through broken cross-references, cloned declaration sets across completely unrelated domains, sudden seller removals, and supply paths in server-side bid logs that never appear in a publisher’s authorized list.

Recognizing this critical visibility gap, Zach Edwards and his fellow founders built DecryptAds to aggregate and correlate these disparate data points. Rather than viewing adtech through a purely commercial lens, the founders approached it from an aggressive cybersecurity and threat-intelligence perspective.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The platform’s launch bridges a long-standing gap in digital defense, allowing researchers, journalists, and privacy advocates to query complex relationships between domains, ad networks, and hidden beneficial owners in real time. Through its robust infrastructure, DecryptAds automates the tedious work of pivoting across seller IDs, exposing the intricate, often hazardous supply chains underpinning the internet’s most popular web destinations.


Supporting Context & Metrics: Unpacking High-Risk Partners and Geopolitical Exposure

The diagnostic power of DecryptAds becomes immediately apparent when examining major web properties. For instance, a search for the high-traffic sports network espn.com reveals an astonishing 143 ad partners and 19 registered data broker domains explicitly declared within its ads.txt and app-ads.txt files.

The Data Broker Web and Geolocation Tracking

This granular transparency has been accelerated by recent regulatory frameworks. Four U.S. states—California, Oregon, Texas, and Vermont—have enacted legislation mandating that data brokers register publicly if they buy or sell consumer data originating from those states.

DecryptAds cross-references these state registries with adtech disclosures, revealing that nearly half of ESPN’s listed data brokers collect precise geolocation data from visitors who do not utilize ad blockers. Furthermore, another three entities explicitly disclose the collection of device fingerprints and sensitive personal information, highlighting the pervasive surveillance economy embedded in mainstream media sites.

Geopolitical Risks and Sanctioned Entities

Beyond privacy harvesting, DecryptAds introduces a crucial "Geo-Risk" warning system. The platform flags advertising partners headquartered in high-risk jurisdictions—such as China and Russia—or in strategic financial and political intermediaries with deep ties to both, including Cyprus and the United Arab Emirates (UAE).

A troubling case study surfaced when examining ESPN’s adtech roster, which includes four entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists an official corporate address in New York. However, the DecryptAds dossier on Between Digital exposes its true Russian origins, noting that its publisher payout offers are processed directly through Alfa Bank—Russia’s largest private commercial bank and a primary financial institution placed under heavy U.S. sanctions in 2022 following the invasion of Ukraine.

The reach of such entities extends deeply into sensitive sectors. Searches conducted across prominent U.S. military news portals—including Army Times, Air Force Times, Defense News, Navy Times, Marine Corps Times, and Federal Times—reveal that all of these defense-focused publications authorize Between Digital to serve advertisements and track users. Additional partners include entities based in the UAE and the ownership-secrecy haven of Panama. According to DecryptAds intelligence, Between Digital actively collects advertising data across an estimated 55,000 partner websites globally.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Pivoting further into Between Digital’s app-ads.txt file exposes hundreds of domains tied to basic, web-based mobile games interrupted by constant ad loads. Notably, DecryptAds data shows the firm acts as both a publisher and a reseller on roughly two-thirds of its portfolio. This dual role creates an inherent conflict of interest, allowing the entity to play both sides of the bidding equation and potentially direct client ad spend toward its own infrastructure.

Similar systemic exposure plagues major software utilities. The popular Opera web browser, which has been majority-owned by Chinese firm Kunlun Tech since 2016 (while maintaining operational headquarters in Oslo, Norway), exhibits an extensive foreign adtech footprint. Opera.com’s DecryptAds profile identifies 27 registered data brokers, including 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These actors represent just 7% of the total adtech partners declared across Opera’s official authorization files.


Official Statements & Industry Insights

To contextualize the vast troves of data surfaced by the platform, industry experts and DecryptAds leadership have emphasized the urgent need for structural reform in how ad networks police their ecosystems.

Speaking on the motivations behind the platform, Zach Edwards underscored the historical lack of oversight plaguing programmatic advertising:

"It’s an adtech tool, but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved… The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

Edwards also shed light on the pervasive industry practice of "quiet removals." When ad networks suspect an affiliate of generating fraudulent click traffic or serving malicious payloads, they frequently purge the offender from their sellers.json file silently, offering no public notification or transparency report. This lack of communication allows dodgy operators to simply migrate to other exchanges and continue victimizing users unhindered.

To combat this, DecryptAds features a dedicated Quiet Removals Feed, which aggregates and correlates seller deletions across multiple exchanges to expose suspicious actors attempting to wipe their digital slates clean.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Malvertising, AI Slop, and the Threat to Government Networks

The convergence of fraudulent ad networks and generative artificial intelligence has given rise to a new wave of threats. Malvertising—the injection of malicious code into ad networks to deploy malware or orchestrate phishing attacks—rarely strikes top-tier domains like espn.com or major news outlets, which deploy robust client- and server-side filtering technologies. Instead, threat actors exploit the burgeoning ecosystem of AI-generated content farms.

These "AI slop" websites feature machine-generated blogs and imagery spanning home improvement, recipes, automotive niches, and consumer tech. Operating on shoestring budgets, these content farms onboard the lowest-quality adtech partners, creating greased rails for malware delivery.

Edwards warned of the grave national security implications tied to this unchecked supply chain:

"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis."


Future Outlook: Legal Dossiers, Supply Chain Objects, and Defense Strategies

Looking forward, DecryptAds aims to expand its utility through advanced investigative tools like its Legal Dossier lookup. Although resource-intensive—often taking several minutes to execute—this feature compiles comprehensive ownership histories, domain registration dates, corporate aliases, and structural relationships connecting disparate adtech vendors, applications, and web properties.

Exposing the H96 and Fengwo Group Nexus

The power of this cross-referencing capability was recently demonstrated in investigations involving malicious TV streaming sticks. Security researchers from Bitsight uncovered that popular "H96" Android streaming devices were quietly renting out residential internet connections to strangers as proxy nodes. Furthermore, when idle, these devices spoofed mobile phone user agents to automatically click ads on AI-generated content farms.

Bitsight tied this malicious network to a Chinese entity known as the Fengwo Group, which operated both the malicious mobile applications and the ad landing pages. Using DecryptAds’ legal dossier and pivoting features, researchers traced the dormant domain medicalbeautyhub.com (linked to Fengwo) and discovered it shared a seller ID (1674071) with an unrelated gaming site (giacoloredstones.com). This gaming site, in turn, shared a secondary seller ID (103488000) tied directly to hundreds of active, low-quality Russian web properties operating within Yandex’s advertising system.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The Path Forward: Demanding Transparency

To truly eradicate malvertising and supply-chain obfuscation, Edwards argues that major ad networks must be compelled to share what is known as the Supply Chain Object (SCO). Attached to server-side ad bid requests, the SCO details every intermediary, seller, and buyer involved in a transaction. Without visibility into the SCO, defenders can identify a malicious redirect or payload delivery, but remain utterly blind to the ultimate financial beneficiary who purchased the impression.

Furthermore, DecryptAds offers an Application Programming Interface (API), empowering security researchers to automate large-scale queries and integrate its intelligence feed directly into AI-driven defensive platforms.


What Can You Do? Practical Defense Recommendations

Given the pervasive surveillance and security risks embedded within modern programmatic advertising, security experts universally recommend an aggressive, multi-layered defensive posture.

1. Implement Robust Browser-Based Ad Blocking

For desktop and laptop users, blocking online ads outright remains the single most effective countermeasure against data harvesting and malvertising.

  • uBlock Origin Lite / uBlock Origin: Highly recommended open-source, resource-efficient extensions that block ads, trackers, and malicious scripts effectively. Compatible with major desktop browsers and Firefox on Android.
  • Adblock Plus: A viable alternative for mobile Apple users operating across iOS devices (iPhones and iPads).
  • Advanced Filter Lists: Power users can leverage custom blocking rules via repositories like easylist.to to continuously update ad-blocking definitions.
  • NoScript: For advanced users willing to micro-manage security, NoScript blocks all unapproved JavaScript by default, preventing malicious scripts from executing, though it requires constant tuning for seamless web browsing.

2. Deploy Network-Level Ad Blocking (Pi-hole)

For a comprehensive, network-wide solution, technically inclined users can deploy a hardware-based ad blocker. By utilizing a low-cost microcomputer like a Raspberry Pi running Pi-hole, users can establish a local DNS sinkhole. Configuring your home router to route traffic through the Pi-hole automatically neutralizes ads, trackers, and telemetry across every connected device on the local network—including smart appliances and IoT gear.

3. Exercise Extreme Caution with Mobile Apps and Smart TVs

Mobile applications and smart TV operating systems represent the ultimate frontier of unregulated data extraction. Major publishers heavily incentivize users to download dedicated mobile apps not because of superior user experience, but because apps bypass browser protections, facilitate continuous background tracking, collect hyper-precise location data, and frequently opt users into training data agreements for large language models.

Whenever possible, interact with web services directly within a privacy-respecting mobile browser equipped with content blocking. Before installing any mobile application or smart TV software, run a background check on its parent entity using analytical intelligence platforms like DecryptAds to understand its data-sharing practices, geographical risk profile, and hidden adtech partnerships.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *