Figuring out which organizations place advertisements on the sites you browse or extract information from the applications on your phone can feel overwhelming. While this information technically exists in the public domain, it remains scattered and fragmented, historically locked away within the proprietary systems of major ad platforms. That situation has changed with the arrival of DecryptAds, a no-cost tool that aggregates and cross-references advertising technology data to give users clear visibility into entities monitoring their online behavior.
The recently launched decryptads.com continuously harvests publicly disclosed files that websites and applications maintain to identify which organizations may display advertisements or access user information. These documents include:
- ads.txt: a list of advertising technology companies and data brokers permitted to run ads or extract data from a website
- app-ads.txt: organizations authorized to collect data from or display ads within mobile and smart TV applications
- buyers.json/sellers.json: parties engaged in purchasing, selling or redistributing advertising inventory associated with a specific website or application
Zach Edwards, who serves as chief research officer at DecryptAds and works as a threat researcher for security firm Infoblox, explained that he and two co-founders recognized the necessity for this service. The advertising data contained in these files becomes genuinely useful only when cross-referenced to construct a fuller understanding of the advertising landscape surrounding each website or application.
It's an adtech tool but we're trying to approach adtech from a security perspective. It's really built for a lot of privacy and security use cases that have been dramatically underserved.
Zach Edwards
Edwards outlined several critical applications for this capability: locating the origins of malicious advertisements designed to distribute malware to specific users, pinpointing advertising networks operating from hostile nations, and identifying the rapidly expanding ecosystem of AI-generated low-quality websites and applications. As the DecryptAds platform demonstrates, these security and privacy concerns become nearly undetectable when examining a single ads.txt or app-ads.txt file in isolation.
Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher's authorized-seller list.
DecryptAds
When searching DecryptAds for espn.com, the results reveal 143 advertising partners alongside 19 registered data broker domains listed in its ads.txt and app-ads.txt files. The availability of data broker information is expanding as four states—California, Oregon, Texas and Vermont—have enacted legislation mandating that data brokers register if they acquire or sell consumer information from residents of those jurisdictions. According to DecryptAds, nearly half of these data brokers are harvesting location information from espn.com visitors who have not activated ad-blocking measures, while three others report collecting device fingerprints and sensitive personal details.

HIGH-RISK AD PARTNERS
DecryptAds streamlines the process of identifying the owners and geographic locations of advertising firms embedded within applications and websites. The platform displays prominent alerts when advertising partners originate from "geo-risk" jurisdictions including China and Russia, or from nations maintaining substantial financial and political connections to both—such as Cyprus and the United Arab Emirates (UAE).
According to DecryptAds, espn.com engages with four separate advertising entities headquartered in Russia, China or the UAE. One such firm, Between Digital, maintains a listed New York office but DecryptAds identifies it as a Russian operation, revealing that its publisher materials are handled through Alfa Bank, Russia's largest privately held commercial bank. Alfa Bank was among numerous financial institutions subjected to U.S. sanctions in 2022 following Russia's invasion of Ukraine. KrebsOnSecurity contacted both Between Digital and its founder requesting comment and will revise this article if either party responds.
Examining several prominent U.S. military-focused news outlets—armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com—demonstrates that all permit Between Digital to deliver advertisements and monitor visitors. These sites also work with two entities based in the UAE and another operating from Panama, a jurisdiction known for corporate secrecy. DecryptAds indicates that Between Digital collects advertising data across approximately 55,000 partner websites.

Analyzing Between Digital's app-ads.txt file uncovers hundreds of domains hosting basic web-based games frequently interrupted by advertisements. Edwards noted that Between Digital's own records indicate the company functions simultaneously as both a publisher and a reseller across roughly two-thirds of its portfolio.
It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest. The problem we have right now is that for years we've had almost no one policing these ads.txt and app-ads.txt files.
Zach Edwards
The Opera Web browser maintains substantial market presence, yet many users remain unaware that since 2016 it has been majority-owned and operated by Chinese firm Kunlun Tech, despite maintaining operational headquarters in Oslo, Norway.
Opera.com's DecryptAds profile lists 27 registered data brokers collecting information, encompassing 15 advertising partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds clarifies, however, that these entities represent only seven percent of the total advertising partners specified within Opera.com's ads.txt and app-ads.txt files.
LEGAL DOSSIERS
A particularly valuable DecryptAds feature is its Legal Dossier lookup function, which requires several minutes per search but ultimately produces substantial information regarding domain or application ownership, registration dates, and any connections or relationships to advertising technology companies and other digital properties.
In a previous investigation, KrebsOnSecurity reported on Bitsight researchers who discovered that a widely distributed line of TV streaming devices called H96 surreptitiously leases each user's internet connection to third parties. Bitsight also found that when these devices are not streaming pirated video, they masquerade as mobile phones clicking advertisements on AI-generated low-quality websites.
Bitsight determined that the same Chinese organization responsible for creating multiple malicious applications common to these H96 streaming sticks—the Fengwo Group—also operated the advertising network and AI-generated website ecosystem being accessed by tens of thousands of these devices posing as mobile phones.

A DecryptAds legal dossier examining the now-inactive Fengwo Group domain for an AI-generated website (medicalbeautyhub dot com) reveals it shares a seller identifier (1674071) with a gaming website—giacoloredstones[.]com—which carries a different seller identifier (103488000).
Investigating that second seller identifier uncovers hundreds of operational websites within Russia's Yandex advertising system, each offering extremely poor-quality games or basic utilities saturated with advertisements.
QUIET REMOVALS
Edwards explained that when advertising networks determine a particular advertiser is participating in fraudulent clicks or distributing malicious advertisements, they frequently remove that party from their approved partners list without publicly disclosing their concerns.
This practice, he noted, enables questionable advertising firms to evade responsibility and continue harming others. To address this transparency deficit, DecryptAds maintains a quiet removals feed that documents and correlates all sellers.json removals across advertising exchanges for the same seller domain or entity.

The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won't make it public. The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you're trying to navigate who is suspicious, that's usually tough to do because there are a lot of adtech companies removing things all at once.
Zach Edwards
MALVERTISING AND AI SLOP
Malvertising—the insertion of malicious advertisements that distribute malware or redirect users to fraudulent pages—continues plaguing the contemporary advertising ecosystem. However, Edwards noted that these harmful advertisements appear far more frequently on newly created AI-generated low-quality websites than on high-traffic platforms that typically deploy multiple protective technologies and third-party tools to rapidly identify problematic advertisements.
None of these slop AI content farms are paying for that kind of protection. They're just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don't happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.
Zach Edwards
Edwards described AI-generated websites as containing machine-produced blog articles and graphics spanning diverse categories including home improvement, interior design, food preparation, hunting, automobiles and consumer electronics. He noted that organizations experiencing malvertising attacks frequently lack direction on remediation, unaware that answers typically reside within the entities listed in the website's ads.txt or app-ads.txt file.
A lot of serious organizations are starting to understand that if we're not breaking down this ad data, we're not going to know who's targeting government people with zero-click payloads on an almost daily basis.
Zach Edwards
Edwards contends that effectively addressing malvertising and AI-generated content challenges requires expanded data-sharing among major advertising networks. He specifically identifies the absence of broad distribution of the "supply chain object" or SCO—structured information connected to each advertising bid request that permits buyers to identify every seller, reseller and intermediary involved in transferring an advertisement impression from publisher to final purchaser.
That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload. You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won't know who targeted your people with malware and won't have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.
Zach Edwards
DecryptAds provides an application programming interface (API) enabling researchers to automate searches and incorporate the platform's capabilities into widely-used artificial intelligence systems.
WHAT CAN YOU DO?
The most prudent approach involves blocking all digital advertisements entirely. Security professionals widely recommend this strategy because it simultaneously complicates efforts by advertising firms and data brokers to construct comprehensive profiles and monitor your activities across the internet and physical world.
The optimal choice depends on your typical browsing habits and confidence level in third-party browser add-ons and extensions. For users primarily accessing the internet through standard desktop or laptop browsers, uBlock Origin Lite represents an excellent free and actively maintained open-source solution. uBlock Origin should also function with mobile browsers including Firefox, though apparently only on Android devices.
Adblock Plus serves as a reasonable choice for iPhone and iPad users. Advanced users can leverage both Adblock and uBlock Origin to implement custom blocking rules from easylist.to, which maintains a regularly refreshed compilation that eliminates the majority of web advertisements.
The established browser extension NoScript prevents all unapproved JavaScript code from executing and generally succeeds at blocking most advertisements. However, script-blocking tools like NoScript may prove unsuitable for typical users who lack interest in constantly deciding which scripts warrant permission to load for proper website functionality.
Users with greater technical expertise should seriously investigate a hardware-based approach to advertisement blocking at the network level, as this represents the most economical, secure and expandable option. A compact, inexpensive and readily obtainable device called a Raspberry Pi can function as a sophisticated ad blocker for all devices on a local network when equipped with a microSD card and the free Pi-hole software. Following proper configuration and modification of router network settings to utilize the Pi-hole's DNS sinkhole and DHCP servers, advertisements should be prevented from displaying on any devices connected to that network.
Remember that advertisement blockers frequently provide minimal protection against advertisements and tracking originating from within mobile applications that users have independently installed. Numerous websites now encourage users to download mobile applications, claiming this enables fuller access to and enjoyment of site offerings. However, experience suggests this motivation differs from the stated rationale. Most mobile applications appear poorly designed, frustrating, and fundamentally unnecessary, and when available, direct website or service interaction through a web browser remains preferable.
The reality is that major web platforms aggressively promote their applications because doing so extends user engagement duration and facilitates collection—and frequently resale—of substantially more granular information regarding user identity, preferences and location. Furthermore, companies most forcefully pushing mobile app adoption consistently enable everyone by default to have their information utilized for training large language models. Exercise caution regarding applications you install on mobile devices and smart televisions, and examine their DecryptAds profiles to understand their privacy approaches and connections to advertising technology firms.
Source: Krebs on Security