Cybersecurity

DecryptAds Launches New Transparency Platform to Expose the Opaque Underbelly of the Global Adtech Ecosystem

Determining who is responsible for serving advertisements on your favorite websites or identifying which third-party entities are harvesting your data from mobile applications has long been a daunting task for the average user. While this information is technically public, it has historically remained siloed within complex, non-parsed files buried behind the walls of major advertising platforms. A newly launched service, DecryptAds, aims to dismantle these barriers by scraping, correlating, and simplifying this data, providing a window into the entities tracking users across the digital landscape.

The platform, accessible at decryptads.com, functions by continuously crawling the files that websites and mobile applications are mandated to make public to ensure transparency in the digital advertising supply chain. These critical, yet often ignored, files include ads.txt, which lists authorized adtech companies and data brokers; app-ads.txt, which governs data harvesting and ad delivery on mobile and smart TV applications; and the sellers.json and buyers.json files, which detail the entities buying, selling, or reselling ad inventory.

The Security Perspective on Adtech

Zach Edwards, the Chief Research Officer at DecryptAds and a threat researcher at the security firm Infoblox, spearheaded the project alongside two co-founders. The impetus for the service was the realization that adtech data is only useful when cross-referenced to build a comprehensive picture of the advertising ecosystem.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

“It is an adtech tool, but we are approaching the industry from a security perspective,” Edwards stated. “It is built for privacy and security use cases that have been dramatically underserved.” According to Edwards, the service addresses a critical gap in digital hygiene, allowing security professionals to trace the origins of malicious ads, identify ad networks linked to adversarial nations, and detect the rapid proliferation of AI-generated content farms—often referred to as "slop"—that monetize through low-quality ad traffic.

The complexity of the current digital supply chain is a significant challenge for researchers. As the DecryptAds documentation notes, security issues rarely exist within a single file. They manifest as broken cross-references between disparate files, cloned declarations across unrelated domains, and supply paths that appear in bid logs but remain absent from a publisher’s authorized-seller list.

Investigating the Data Brokerage Landscape

A search for a major entity like espn.com on the platform reveals 143 ad partners and 19 registered data broker domains. This level of granularity has become more accessible recently due to legislative shifts in states like California, Oregon, Texas, and Vermont, which have enacted laws requiring data brokers to register if they handle consumer data. DecryptAds analysis suggests that nearly 50% of the data brokers associated with high-traffic sites like ESPN collect geolocation data from users who do not utilize ad-blocking software, while others focus on device fingerprinting and the collection of sensitive personal information.

The implications for national security are equally pressing. DecryptAds provides a "geo-risk" warning for advertising partners based in nations with significant geopolitical tensions, such as Russia, China, or countries with close financial ties to these regimes, including Cyprus and the United Arab Emirates. For example, the platform flags Between Digital, an adtech firm that lists a New York address but maintains deep financial ties to Russia, including the use of Alfa Bank—a financial institution under U.S. sanctions—to process publisher payments.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Investigations by the platform show that Between Digital is permitted to serve ads on several prominent U.S. military news websites, including Army Times, Air Force Times, and Defense News. This highlights the vulnerability of critical infrastructure and military-linked domains to potentially compromised or foreign-controlled advertising supply chains.

The Intersection of Malvertising and AI Content Farms

The phenomenon of "malvertising"—the insertion of malicious code into advertisements to redirect users to phishing pages or deploy malware—has evolved in tandem with the rise of AI-generated content. Edwards notes that high-traffic, reputable publishers typically employ rigorous security protocols to mitigate these risks. Conversely, the vast ecosystem of AI-generated "slop" websites, which churn out low-quality, machine-written content, often lacks these defenses.

These content farms prioritize monetization through the lowest-cost ad partners, creating a "greased rail" for malicious actors to reach unsuspecting users. A notable example is the H96 streaming stick incident, where researchers at Bitsight discovered that these devices were being used to spoof mobile phone traffic to click on ads hosted on AI-generated websites. DecryptAds’ "Legal Dossier" feature allowed researchers to link these fraudulent websites to specific seller IDs, which ultimately traced back to networks of low-quality gaming and utility sites within the Yandex ad system.

Identifying ‘Quiet Removals’ and Accountability

A significant challenge in the adtech industry is the practice of "quiet removals." When an ad network suspects an advertiser of fraudulent activity, they often remove the offender from their sellers.json file without public disclosure. This lack of transparency allows bad actors to continue their operations across other exchanges unchecked.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

To combat this, DecryptAds has introduced a "quiet removals" feed, which monitors and correlates removals across multiple exchanges. By analyzing these shifts, security researchers can identify clusters of suspicious activity that would otherwise remain hidden in the fragmented data of individual ad networks.

Edwards argues that the industry must move toward greater transparency, specifically by sharing the "supply chain object" (SCO). This structured data, which remains server-side and is rarely exposed, details every intermediary involved in the passage of an ad impression. Without the SCO, victims of malvertising are unable to trace the final entity responsible for delivering a malicious payload, rendering remediation efforts largely ineffective.

Practical Implications for the Modern User

While the launch of DecryptAds provides researchers with unprecedented visibility, it also serves as a stark reminder of the privacy risks inherent in modern digital consumption. Experts suggest that the only definitive way to mitigate these risks is to implement robust ad-blocking solutions at the network or browser level.

For desktop users, open-source extensions like uBlock Origin remain the gold standard for blocking unauthorized tracking and malicious scripts. For mobile and smart home users, the landscape is more complex. Because mobile apps are designed to bypass standard browser-based protections, users are encouraged to interact with services via a web browser whenever possible.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

For the tech-savvy, a hardware-based approach—such as deploying a Pi-hole on a local network—remains the most effective, scalable method for filtering ads and tracking requests across all connected devices, including smart TVs. The shift toward "app-first" ecosystems by major publishers is, according to many security analysts, a deliberate strategy to circumvent privacy protections and gather more granular data for behavioral profiling and AI training models.

As DecryptAds continues to aggregate this data, the platform underscores a fundamental shift in the digital security paradigm: the advertising supply chain is no longer just a marketing concern, but a significant vector for cybersecurity threats. Whether the broader industry will respond by adopting the transparency standards suggested by researchers remains to be seen, but tools like DecryptAds are rapidly narrowing the gap between the hidden mechanics of adtech and the public’s right to understand who is watching them.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button