DecryptAds Exposes Hidden Online Ad Tracking

DecryptAds Exposes Hidden Online Ad Tracking

Free service DecryptAds cross-references ads.txt and related files to reveal ad partners, data brokers, and geo-risk tracking on any website or app.

DecryptAds, a newly launched free service, maps the often hidden advertising and data-collection relationships behind websites and mobile apps. The service continuously scrapes public files that sites and apps must publish to disclose which companies are allowed to serve ads or harvest data: ads.txt for websites, app-ads.txt for mobile and smart TV apps, and buyers.json/sellers.json files that show who buys, sells, or resells ad inventory. By cross-referencing these declarations, DecryptAds builds a fuller picture of the adtech ecosystem around any domain.

Zach Edwards, chief research officer for DecryptAds and a threat researcher at Infoblox, told KrebsOnSecurity that he and two co-founders built the service for privacy and security use cases that he said have been dramatically underserved. He described it as an adtech tool approached from a security perspective. The site notes that supply-chain integrity issues rarely live in a single file; they show up as broken cross-references across ads.txt, app-ads.txt, and sellers.json files, as cloned declaration sets across unrelated domains, as seller removals that only make sense when viewed across exchanges, and as supply paths in bid logs that never appear in any publisher’s authorized-seller list.

A search for espn.com on DecryptAds shows 143 ad partners and 19 registered data broker domains listed in its ads.txt and app-ads.txt files. The data broker information is becoming available because California, Oregon, Texas, and Vermont have passed laws requiring data brokers to register if they buy or sell data on residents of those states. DecryptAds reports that almost half of those brokers collect geolocation data from ESPN visitors who do not block ads, while three more disclose collecting device fingerprints and sensitive personal information.

DecryptAds also flags ad partners based in what it calls geo-risk areas, including China and Russia, or countries with strong financial and political ties to both, such as Cyprus and the United Arab Emirates. For ESPN, DecryptAds identifies four ad entities based in Russia, China, or the UAE. One is Between Digital, which lists a New York address but is flagged as a Russian firm. Its publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank, which was placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from Between Digital and its founder. Searches for several U.S. military news sites, including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com, show they all allow Between Digital to serve ads and track users, along with two entities in the UAE and another in Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains with simple web games frequently interrupted by ads. Edwards said Between Digital’s own declarations show it acts as both publisher and reseller on roughly two-thirds of its portfolio, which he said creates opportunities for conflicts of interest by allowing a company to play both sides of the bidding equation. He added that for years almost no one has been policing these files.

The Opera browser profile on DecryptAds illustrates how ownership and adtech partners can diverge. Since 2016 Opera has been majority owned and controlled by the Chinese company Kunlun Tech, while its operational headquarters remain in Oslo, Norway. Opera.com’s profile shows 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. DecryptAds notes these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

DecryptAds also offers a Legal Dossier lookup that takes several minutes per search but returns detailed ownership, registration, and alias information for a domain or app. This feature connects domains to adtech entities and other sites. For example, KrebsOnSecurity previously reported on researchers from Bitsight who found that H96 TV streaming sticks quietly rent out each user’s Internet connection to strangers and, when idle, spoof themselves as mobile phones clicking ads on AI-generated slop websites. Bitsight concluded that the Chinese company Fengwo Group made several malicious apps common on these devices and also ran the network of ads and slop sites. A DecryptAds legal dossier on a now dormant Fengwo Group domain for the slop site medicalbeautyhub dot com shows it shares a seller ID, 1674071, with a gaming website, giacoloredstones dot com, which has another seller ID, 103488000. Pivoting on that latter ID reveals hundreds of active websites within Russia’s Yandex ad system featuring low-quality games or simple utilities that pepper visitors with ads.

DecryptAds also records what Edwards calls quiet removals. When ad networks suspect an advertiser of unauthentic clicks or malicious ads, they often remove the offender from their approved partner list without telling anyone else. DecryptAds has a quiet removals feed that correlates seller removals across ad exchanges for the same seller domain or name. Edwards said the industry often keeps fraud reports private, so the public only sees a seller disappear from sellers.json with no explanation. That makes it difficult to know who is suspicious.

Edwards said malvertising, the practice of serving malicious ads that push malware or phishing pages, is now far more common on newly generated AI slop websites than on high-traffic destinations that pay for ad-quality protection. These slop sites are filled with machine-generated blog posts and images on topics such as home improvement, recipes, hunting, cars, and consumer technology. When organizations are hit by malicious ads, Edwards said many do not realize the answer often lies in one of the entities listed in the site’s ads.txt or app-ads.txt file. He said serious organizations are starting to understand that without breaking down this ad data, they will not know who is targeting people with zero-click payloads.

Edwards maintains that solving malvertising and AI slop will require more data-sharing by major ad networks, especially the supply chain object (SCO), structured data attached to each advertising bid request that shows every seller, reseller, and intermediary. He said the SCO is only served server side, so without it a defender sees a malicious redirection but cannot identify who bought the impression that served the malware payload. DecryptAds also offers an application programming interface (API) so researchers can automate queries and integrate the service into AI platforms.

For end users, the most direct response is to block online ads. Security experts broadly endorse ad blocking because it also makes it harder for adtech fir

How to Protect Yourself

  1. Install a trusted ad blocker such as uBlock Origin Lite on your computer browser and Adblock Plus on iPhone or iPad.
  2. Before installing a mobile app, search its name on DecryptAds to see its ad and data broker partnerships.
  3. Limit or block location and fingerprinting permissions for apps and websites that do not need them.
  4. If you manage a home or office network, set up a Pi-hole on a Raspberry Pi or use a private, secure DNS service to block many ad and tracking domains at the network level.
  5. Avoid installing apps for websites when the browser version works well; apps often collect more precise data.
  6. Keep your browser and operating system updated so ad-based malware delivery has fewer known weaknesses.

Terms Explained

  • ads.txt A public file on a website that lists which companies are allowed to sell or place ads on that site.
  • app-ads.txt A similar public file for mobile and smart TV apps that discloses which ad companies may collect data or show ads.
  • sellers.json A file used by advertising systems to identify the businesses that sell or resell ad space.
  • data broker A company that buys, sells, or trades personal information collected about people, often without their direct knowledge.
  • device fingerprint A unique set of details about a phone or computer that can identify it across different websites without using cookies.
  • malvertising The use of online advertising to spread malware or trick people into visiting phishing pages.
  • supply chain object (SCO) Data attached to an ad bid request that shows every company involved in selling and reselling that ad impression.
  • DNS sinkhole A network setting that redirects requests for known advertising or tracking domains so they never load.

Related AEU services