Cybersecurity & Privacy

DecryptAds Launches Transparency Platform to Unmask the Complex and Often Opaque World of Digital Advertising Supply Chains

Determining who is responsible for the advertisements appearing on websites or identifying the entities harvesting granular data from mobile applications has long been a daunting task for both casual users and cybersecurity professionals. While this information is technically public, it has historically remained siloed within large advertising platforms, obscured by technical complexity and a lack of user-friendly interfaces. A new service, DecryptAds, has emerged to address this, offering a free, powerful tool that scrapes, correlates, and simplifies adtech data, allowing users to rapidly investigate the entities tracking their digital footprints.

The landscape of online advertising is built upon a series of public-facing files designed to facilitate transparency in the ad supply chain. These include ads.txt, which lists authorized digital sellers for websites; app-ads.txt, which performs a similar function for mobile and smart TV applications; and buyers.json/sellers.json files, which detail the entities buying, selling, or reselling ad inventory. Until now, these files were rarely scrutinized outside of industry specialists, leaving a significant gap in public awareness regarding the tracking mechanisms embedded in everyday browsing.

The Origins of DecryptAds and the Security Perspective

DecryptAds, spearheaded by Chief Research Officer Zach Edwards—a seasoned threat researcher at the security firm Infoblox—was born out of a perceived necessity to treat adtech not merely as a marketing concern, but as a critical security issue. Edwards and his co-founders recognized that the true danger of the modern ad ecosystem lies in the cross-referencing of these files, which reveals a much broader, often unsettling picture of how data is funneled between brokers.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

From a security standpoint, the tool aims to serve as a watchdog for several critical threats: the delivery of malvertising that embeds malware into legitimate-looking ads, the identification of ad networks operating from adversarial nations, and the proliferation of low-quality, AI-generated content farms. As the platform notes, supply-chain integrity issues are rarely contained within a single file. Instead, they manifest as broken cross-references between different standards, cloned declarations across unrelated domains, and supply paths in bid logs that appear nowhere on a publisher’s authorized list.

A Case Study in Supply Chain Complexity: ESPN.com

To demonstrate the efficacy of the tool, one need only look at the profile of a major destination like espn.com. A search on the platform reveals 143 distinct advertising partners and 19 registered data broker domains listed within its authorization files. This level of transparency is aided by recent legislation in states like California, Oregon, Texas, and Vermont, which now require data brokers to register if they buy or sell consumer information.

The data gathered by DecryptAds suggests that nearly half of these brokers are collecting geolocation data from visitors who do not employ ad-blocking software, while others openly admit to harvesting device fingerprints and sensitive personal identifiers. This ecosystem represents a complex web of intermediaries that most users are entirely unaware of when they navigate to a sports news page.

Geopolitical Risks and Financial Entanglements

One of the most concerning features of DecryptAds is its "geo-risk" flag, which highlights adtech partners based in jurisdictions that present elevated political or financial risks, such as Russia, China, or countries with significant ties to them, including Cyprus and the United Arab Emirates.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The platform’s analysis of espn.com identified four advertising entities with ties to these regions. Among them is the adtech firm Between Digital. While the company lists a New York address, DecryptAds flags it as a Russian entity, noting that its publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank was heavily sanctioned by the United States in 2022 following the Russian invasion of Ukraine.

The implications of this are significant. When U.S. military news websites—such as armytimes.com, defensenews.com, and others—allow such entities to serve ads, it creates a potential channel for foreign data collection. DecryptAds reports that Between Digital currently operates on approximately 55,000 partner websites, raising questions about the oversight of the adtech supply chain. Furthermore, an investigation into the company’s own app-ads.txt files suggests that it acts as both a publisher and a reseller on two-thirds of its portfolio, creating clear conflicts of interest that remain largely unpoliced.

The Challenge of Malvertising and AI-Generated Slop

The rise of AI-generated content—often referred to as "AI slop"—has exacerbated the malvertising threat. These websites, which consist of machine-generated text and images, prioritize volume over quality and rarely implement the robust security measures found on high-traffic, reputable news sites.

Edwards argues that these sites have become "greased rails" for malicious actors to deliver zero-click payloads. Because these platforms operate on thin margins and low-quality ad partners, they are prime targets for redirection to phishing pages or malware downloads. Recent research, including findings from the security firm Bitsight regarding the H96 streaming stick scandal, corroborates this. Bitsight discovered that the Fengwo Group, a Chinese entity, was not only producing malicious apps but also operating the network of AI-generated websites that those devices were "clicking" on to commit ad fraud. DecryptAds serves as a vital tool for investigators to trace these seller IDs back to the same parent networks, revealing the interconnected nature of modern digital fraud.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Addressing the Visibility Gap: Quiet Removals

A critical, often overlooked aspect of the industry is the "quiet removal" of fraudulent partners. When an ad exchange suspects a participant of unauthentic behavior, they often remove them from the sellers.json file without public disclosure. This lack of transparency allows malicious actors to migrate to other platforms undetected.

To combat this, DecryptAds has implemented a "quiet removals feed." This tool allows researchers to track when a seller is removed from multiple exchanges simultaneously. By correlating these removals, analysts can identify patterns of fraud that would otherwise remain hidden behind corporate silence. Edwards emphasizes that the industry is in desperate need of shared data, specifically the "supply chain object" (SCO). This structured data, if exposed, would allow buyers to see every intermediary involved in an ad impression, effectively unmasking the culprits behind malicious redirects.

Practical Steps for Users: Blocking the Trackers

For the average user, the findings presented by platforms like DecryptAds underscore the necessity of proactive defense. Security experts broadly recommend the use of robust ad-blocking solutions to mitigate tracking and minimize exposure to malicious advertisements.

For desktop users, open-source browser extensions such as uBlock Origin Lite remain the gold standard. These tools do not merely block ads; they prevent the loading of scripts that allow data brokers to build persistent profiles of users. For mobile devices, where ad blocking is often more difficult, users should be wary of apps that push for excessive permissions or rely heavily on third-party ad networks.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Technically inclined users are encouraged to explore network-level blocking. A Raspberry Pi running Pi-hole, for instance, provides a centralized, hardware-based solution that filters traffic for every device on a home network. By changing DNS settings to point to a "sinkhole," users can prevent ads and tracking requests from reaching their devices entirely.

Broader Implications and Future Outlook

The launch of DecryptAds marks a turning point in the movement for digital transparency. As the adtech industry continues to grow in complexity, the potential for abuse—from data privacy violations to national security risks—will only increase. The ability to pull back the curtain on these supply chains is essential for both the protection of individual privacy and the integrity of the internet as a whole.

While the adtech industry has historically resisted calls for increased oversight, the availability of granular, cross-referenced data may force a shift in behavior. By making the "black box" of advertising supply chains accessible to journalists, security researchers, and the general public, DecryptAds is establishing a new standard of accountability. The era of silent data harvesting and unchecked malvertising distribution may be nearing an end, provided that the tools for exposure remain open, free, and widely utilized. As more organizations begin to analyze their own exposure to these risks, the pressure on major ad networks to provide more comprehensive data, such as the elusive supply chain object, will likely intensify, potentially leading to a more secure and transparent digital ecosystem.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Snapost
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.