New Tool DecryptAds Offers Unprecedented Transparency into the Murky World of Adtech

Determining who is responsible for serving advertisements on the websites we visit or identifying which entities are harvesting data from the mobile apps we use daily has long been a daunting task for the average internet user. While this information is technically public, it has historically remained siloed within large advertising platforms, hidden behind layers of technical jargon and intentionally opaque industry practices. A powerful new, free service called DecryptAds is now changing that dynamic by scraping and correlating complex adtech data to provide a clear, accessible view of the entities tracking user behavior across the web.

The newly launched platform, decryptads.com, operates by continuously monitoring the files that websites and mobile applications make publicly available to disclose their advertising partnerships. These critical files, which have long been under-utilized by security researchers and privacy advocates alike, include "ads.txt" for websites, "app-ads.txt" for mobile and smart TV applications, and "buyers.json" or "sellers.json" files, which identify the entities involved in buying, selling, or reselling advertising inventory. By aggregating this information, DecryptAds allows users to instantly learn a great deal about the sprawling, often hidden ecosystem of trackers and data brokers.

Zach Edwards, the chief research officer for DecryptAds and a threat researcher at the security firm Infoblox, spearheaded the project alongside two other founders. Edwards explains that the service was born out of a necessity to cross-reference adtech data to build a more comprehensive picture of the advertising supply chain. While the tool functions as an adtech utility, Edwards emphasizes that the team’s approach is rooted in a security-first perspective. He believes the service is built to address critical privacy and security use cases that have remained dramatically underserved by the existing, fragmented industry standards.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

According to Edwards, these use cases are extensive. They include tracking the origins of malicious advertisements designed to distribute malware, identifying ad networks operating within adversarial nations, and detecting the rapidly growing influx of AI-generated "slop" websites and applications. The reality of the modern web is that these threats are almost impossible to identify by simply inspecting an individual ads.txt file. As the team behind DecryptAds notes, supply-chain integrity issues rarely exist in a vacuum; they manifest as broken cross-references between different files, cloned declaration sets across unrelated domains, and supply paths that appear in bid logs but are absent from a publisher’s authorized-seller list.

Unmasking the Adtech Supply Chain

The depth of the data available through DecryptAds is striking. A search for a major destination like espn.com reveals 143 distinct advertising partners and 19 registered data broker domains listed within its authorized files. This transparency regarding data brokers is being bolstered by recent legislative efforts in states like California, Oregon, Texas, and Vermont, which now require brokers to register if they buy or sell consumer data. DecryptAds reports that nearly half of the brokers identified on espn.com collect geolocation data from users who do not block advertisements, while three others explicitly disclose the collection of device fingerprints and sensitive personal information.

The platform also provides a vital window into the "geo-risk" associated with adtech partners. It displays clear warnings when a website or application partners with entities based in jurisdictions known for high geopolitical tension, including Russia, China, or countries with strong financial and political ties to them, such as Cyprus and the United Arab Emirates.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

For instance, the dossier on Between Digital—an adtech firm with a listed New York address—flags the company as a Russian entity. The firm’s publisher offers are reportedly processed through Alfa Bank, Russia’s largest private commercial bank, which has been subject to U.S. sanctions since the 2022 invasion of Ukraine. Despite these associations, Between Digital remains a partner for high-profile sites, including several U.S. military news outlets such as armytimes.com, defensenews.com, and navytimes.com. DecryptAds estimates that Between Digital collects ad data on approximately 55,000 partner websites, illustrating how deep these connections run even within sensitive sectors.

Furthermore, by analyzing Between Digital’s app-ads.txt file, researchers found that the company is listed as both a publisher and a reseller on roughly two-thirds of its portfolio. Edwards warns that this creates significant conflicts of interest, as firms can effectively play both sides of the bidding equation, directing client spending toward their own infrastructure. The lack of robust policing of these public declaration files has allowed such practices to flourish for years, often without the knowledge of the publishers themselves or the consumers being tracked.

Hidden Risks and Corporate Control

The complexities of adtech reach into popular consumer software as well. The Opera web browser, for example, has been majority-owned and controlled by the Chinese company Kunlun Tech since 2016, despite maintaining its operational headquarters in Norway. A search on DecryptAds for opera.com reveals 27 registered data brokers, including 15 partners in the UAE, six in China, three in Cyprus, and two in Russia. While these entities represent only a small fraction of the total adtech partners identified in the browser’s declaration files, the data provides a sobering look at how deeply global advertising infrastructure is woven into common software.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The platform’s "Legal Dossier" feature further assists researchers by uncovering ownership structures, domain registration histories, and hidden relationships between adtech companies. This function has become particularly relevant in light of recent investigations into malicious hardware. For example, researchers at Bitsight recently discovered that H96 streaming sticks were quietly renting out users’ internet connections and spoofing mobile device behavior to click on ads hosted on AI-generated "slop" websites. DecryptAds helps map the connections between these malicious landing pages and broader networks, such as the Fengwo Group, which was found to be involved in both the development of the malicious apps and the operation of the ad networks being targeted by the infected devices.

Addressing Malvertising and Accountability

A significant challenge in the current landscape is the prevalence of "quiet removals." When ad networks identify a partner engaging in fraudulent activity or distributing malware, they often remove them from their systems without public disclosure. This lack of transparency allows bad actors to continue operating elsewhere. To combat this, DecryptAds features a "Quiet Removals" feed that tracks these disappearances across various exchanges, providing researchers with a clearer view of who is being purged and why.

Edwards highlights that malvertising—the injection of malicious code into ad streams—is increasingly moving away from high-traffic, well-monitored websites toward low-quality AI-generated content farms. These sites, which prioritize volume over security, rarely invest in the protective layers that major publishers use to flag malicious ads. Consequently, they serve as conduits for zero-click payloads that can target unsuspecting visitors.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

According to Edwards, mitigating these threats requires a paradigm shift in how ad networks share information. He advocates for the broader adoption of the "supply chain object" (SCO), a piece of structured data attached to bid requests that would reveal the entire path of an ad from the publisher to the final buyer. By exposing this data, the industry could identify the exact entities responsible for malicious injections. DecryptAds provides an API to help researchers automate these queries, aiming to bring greater accountability to an industry that has operated in the shadows for too long.

For the average internet user, the insights provided by DecryptAds confirm what many security experts have long advised: the most effective way to protect against intrusive tracking and potential malvertising is to block ads at the source. While browser extensions like uBlock Origin Lite or Adblock Plus can be effective, they often struggle to mitigate the data collection occurring within mobile apps. As mobile apps continue to push for deeper access to user data—often under the guise of improving user experience or training AI models—experts emphasize the importance of caution. Opting to use a mobile web browser rather than a proprietary app, and employing network-level blocking tools like Pi-hole, remains the most robust strategy for those seeking to regain control over their digital footprint in an increasingly transparent, yet increasingly invasive, advertising ecosystem.

Share:

Azzam Bilal Chamdy writes for Tech Maze.

Leave a comment