Exposing the Adtech Underworld: How ‘DecryptAds’ is Shedding Light on Digital Surveillance

exposing-the-adtech-underworld-how-decryptads-is-shedding-light-on-digital-surveillance

In the sprawling, opaque ecosystem of digital advertising, the average internet user is tracked, profiled, and sold dozens of times within the milliseconds it takes for a webpage to load. For years, the mechanisms behind this surveillance have been hidden behind a veil of proprietary complexity, shielded by large advertising platforms that treat their supply chains as trade secrets.

This era of total obscurity may be coming to an end. A powerful new, free service called DecryptAds has launched with the mission of scraping, correlating, and simplifying the labyrinthine data that defines the modern adtech industry. By focusing on the publicly available but historically neglected files—ads.txt, app-ads.txt, and sellers.json—DecryptAds is providing researchers, security professionals, and privacy-conscious users with a lens through which they can finally see who is watching them, where that data is going, and the risks associated with the ad-supported web.

The Mechanics of Transparency: How It Works

At the heart of the digital ad economy are three fundamental files that websites and mobile apps use to disclose their authorized partners. These files are supposed to ensure transparency, but they are rarely human-readable or cross-referenced effectively.

  • ads.txt: A file used by websites to list every authorized adtech company and data broker allowed to run ads or harvest user information.
  • app-ads.txt: The mobile and Smart TV equivalent, providing similar disclosures for app ecosystems.
  • sellers.json/buyers.json: Files that track the entities responsible for buying, selling, or reselling ad inventory.

DecryptAds, spearheaded by Chief Research Officer Zach Edwards—who also serves as a threat researcher at the security firm Infoblox—constantly scrapes these files across the web. The platform’s true innovation is not in the collection of this data, but in its ability to synthesize it.

"It’s an adtech tool, but we’re trying to approach it from a security perspective," Edwards explains. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

A Chronology of the Adtech Data Crisis

The rise of "adtech transparency" has been a slow, uneven process. For years, the industry operated on a "trust us" basis. However, as the sophistication of malvertising—malicious ads designed to distribute malware or phishing links—increased, so did the need for accountability.

In recent years, the urgency has been bolstered by legislation. Four U.S. states—California, Oregon, Texas, and Vermont—have enacted laws requiring data brokers to register if they buy or sell consumer data. This has forced a trickle of information into the public domain that was previously locked behind nondisclosure agreements.

DecryptAds arrives at a critical juncture. The rise of AI-generated "slop" websites—low-quality content farms designed solely to host ads and harvest data—has created a new frontier for malicious actors. Furthermore, the discovery that hardware, such as the H96 line of TV streaming sticks, has been caught spoofing mobile device behavior to click on ads highlights the severe, real-world consequences of an unpoliced advertising supply chain.

Supporting Data: The ESPN and Military News Case Studies

To understand the scale of the tracking ecosystem, one need look no further than a search on DecryptAds for a major entity like espn.com. A single query reveals 143 ad partners and 19 registered data brokers.

The data is sobering:

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
  • Geolocation Tracking: Nearly half of the identified data brokers on ESPN are collecting precise geolocation data from visitors who do not use ad-blocking software.
  • Device Fingerprinting: Three of these entities explicitly disclose that they are collecting device fingerprints and sensitive personal information.
  • Geopolitical Risk: The platform flags ad partners based in "geo-risk" regions, such as Russia, China, or countries with close financial ties to these nations, like the United Arab Emirates (UAE).

Perhaps most alarmingly, DecryptAds discovered that several prominent U.S. military news outlets—including armytimes.com and defensenews.com—are allowing ads from entities with deep ties to Russian financial systems. One such firm, "Between Digital," is flagged in the DecryptAds dossier as a Russian-affiliated firm that processes publisher offers through Alfa Bank, one of Russia’s largest private commercial banks currently under U.S. sanctions.

The "Quiet Removal" Phenomenon

One of the most insidious practices revealed by the platform is the "quiet removal." When ad networks suspect a partner of fraud—such as unauthentic clicks or malicious ad delivery—they often remove that entity from their sellers.json file without public notice.

"The ban is just removing them from the sellers.json file, but they told nobody," Edwards notes. "One day it was there, the next it was gone."

This lack of transparency allows bad actors to hop between exchanges, evading detection and continuing to victimize users. DecryptAds combats this by hosting a "Quiet Removals Feed," which correlates removals across multiple exchanges, finally allowing researchers to identify trends in who is being blacklisted and why.

Implications for Global Security

The security implications of this opaque supply chain are profound. As Edwards points out, "Supply-chain integrity issues rarely live in a single file." Instead, they manifest as broken cross-references between different adtech files or cloned declaration sets across unrelated domains.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Malvertising is no longer just a nuisance; it is a vector for nation-state-level threats. While major, high-traffic websites employ sophisticated security teams to vet their partners, the "AI slop" farms of the world do not. These sites, which often appear in search results for common queries, serve as "greased rails" for zero-click payloads.

Government personnel, corporate executives, and ordinary citizens are being targeted on these low-quality sites by ads that possess the technical capability to deploy malware. Without access to the "Supply Chain Object" (SCO)—structured data that identifies every intermediary involved in the delivery of an ad—security teams are effectively blind to the origin of these attacks. Edwards advocates for an industry-wide push to expose this data, arguing that only through radical transparency can we begin to prevent these attacks.

Official Responses and Industry Accountability

When queried about the findings regarding Between Digital and the presence of sanctioned-bank-linked adtech on high-profile sites, the industry response has been largely silent. KrebsOnSecurity reached out to Between Digital and its founder for comment but did not receive a response at the time of publication.

The silence is telling. The adtech industry has long relied on the complexity of its own architecture to insulate itself from scrutiny. By providing a tool that makes this complexity searchable, DecryptAds is forcing a conversation that many of these companies would prefer to avoid.

Practical Steps: Reclaiming Your Digital Privacy

For the individual user, the findings presented by DecryptAds confirm what many privacy advocates have long suspected: the web is designed to track you.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Recommended Defenses:

  1. Browser-Level Blocking: For desktop users, uBlock Origin Lite remains the gold standard. It is open-source, efficient, and aggressively targets the trackers identified by services like DecryptAds.
  2. Network-Level Protection: For those seeking a comprehensive solution, a Raspberry Pi running Pi-hole is the most effective way to block ads at the local network level. By acting as a DNS sinkhole, it prevents ad traffic from ever reaching your devices, including Smart TVs and mobile phones.
  3. Browser Caution: Many companies push users toward mobile apps under the guise of a "better user experience." In reality, these apps often provide a more invasive, persistent window for data collection and user profiling. Where possible, stick to a privacy-focused web browser.
  4. Critical Evaluation: Be wary of the apps you install, particularly on smart home devices. Before downloading an app from a lesser-known developer, use the DecryptAds "Legal Dossier" lookup to see if the developer has any documented history with questionable adtech firms.

Conclusion

The launch of DecryptAds represents a shift in the power dynamic of the internet. By demystifying the adtech supply chain, it empowers users and security professionals to hold the advertising industry accountable. The era of silent, invisible tracking is being challenged, not by legislation alone, but by the application of data-driven transparency.

As Edwards summarizes, "A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis." For the rest of us, it is a reminder that in the digital age, knowledge is the first and most vital line of defense.