Summary
- DecryptAds.com is a free service that cross-references ads.txt, app-ads.txt, sellers.json, and buyers.json files to map the full advertising and data-broker ecosystem behind any website or app.
- ESPN.com, for example, lists 143 ad partners and 19 registered data broker domains, including four entities based in Russia, China, or the UAE — one of which processes payments through a sanctioned Russian bank.
- US military news sites including Army Times and Defense News are listed as partners of that same Russian-linked adtech firm, Between Digital.
- A ‘quiet removals’ feed records when ad exchanges silently drop suspicious sellers, providing a threat-intelligence signal that was previously invisible.
- Malvertising is increasingly concentrated on AI-generated low-quality content sites, which typically lack the brand-safety tooling deployed by major publishers.
What DecryptAds does
A newly launched service, decryptads.com, continuously scrapes the files that websites and apps are required to publish to disclose their advertising relationships. Those files — ads.txt, app-ads.txt, buyers.json, and sellers.json — are individually public but practically unreadable in isolation. DecryptAds correlates them across domains and exchanges to surface patterns that no single file reveals. Zach Edwards, the service’s chief research officer and a threat researcher at Infoblox, described the goal plainly: “It’s an adtech tool but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”
Supply-chain integrity as a security problem
The service’s own documentation frames the core issue well: supply-chain integrity problems rarely appear in a single file. They materialise as broken cross-references between declaration files, cloned declaration sets across unrelated domains, and seller removals that only make sense when viewed across multiple exchanges. For security teams, this framing should be familiar — it is the same logic applied to software supply-chain risk, now applied to the advertising layer sitting inside your organisation’s browsers and mobile devices.
Geo-risk partners and sanctioned banking relationships
DecryptAds flags adtech partners domiciled in countries it classifies as geo-risk, including China, Russia, and the UAE, as well as jurisdictions with strong financial or political ties to those nations such as Cyprus. A search on ESPN.com surfaces four such entities. One of them, Between Digital, lists a New York address but its publisher payment documents are processed through Alfa Bank — Russia’s largest private commercial bank, and a target of US sanctions imposed in 2022. Between Digital is reportedly active across approximately 55,000 partner websites. Notably, several US military-focused news titles — including Army Times, Air Force Times, and Defense News — list Between Digital as an authorised partner.
Conflicts of interest in the bidding chain
Edwards noted that Between Digital’s own declarations show the company listed as both publisher and reseller on roughly two-thirds of its portfolio. That dual role creates structural opportunities to direct advertiser spend toward owned properties. “It means they are basically playing both sides of the bidding equation,” Edwards said. The broader problem, he added, is that these declaration files have gone largely unpoliced for years.
Quiet removals: an overlooked threat signal
When ad exchanges suspect a partner of ad fraud or malicious behaviour, the standard response is to remove that partner from their sellers.json file without any public disclosure. DecryptAds tracks these removals across exchanges and correlates them by seller domain or name. Edwards described the pattern: a company disappears from a sellers.json file overnight, no announcement is made, and the rest of the ecosystem has no idea. That quiet removal feed now gives security researchers — and security teams — a working signal of suspicious activity that previously went unshared.
Malvertising is moving to AI slop sites
Edwards made a point worth noting for teams that monitor threat intelligence: malicious ads are increasingly delivered via machine-generated, low-quality content sites rather than through high-traffic destinations. Major publishers invest in third-party tools to detect and pull bad ads quickly. AI-generated content farms do not. Users land on these sites through organic search and are then exposed to ads that can deliver zero-click malware payloads or redirect to phishing pages. Without access to the supply-chain object — structured data embedded in each ad bid request that identifies every intermediary in the chain — even investigators who observe a malicious redirection cannot reliably attribute it to a specific buyer.
Opera and app-level exposure
The service also illustrates risk at the browser level. Opera, majority-owned by Chinese company Kunlun Tech since 2016, lists 27 registered data brokers collecting information via its ads.txt and app-ads.txt files, alongside 15 adtech partners in the UAE, six in China, three in Cyprus, and two in Russia. Mobile apps present a separate concern: standard ad blockers typically have limited effectiveness against tracking embedded within installed applications.
Why it matters
CISOs generally have limited visibility into the adtech layer operating inside their users’ browsers and on the devices accessing corporate systems. That layer can be an active delivery mechanism for malware, a surveillance channel for adversarial-nation data brokers, and a source of supply-chain integrity failures that no standard security tool is scanning. DecryptAds provides a free, structured way to audit those relationships for any site or app relevant to your organisation — whether that means reviewing apps approved for corporate use, assessing partners on your own web properties, or investigating a malvertising incident. The exposure is real: US defence-sector media carrying a Russian-linked adtech partner is a concrete example of how this risk surfaces in practice.
What to do now
- Use decryptads.com to audit the adtech and data-broker relationships declared by any apps or websites your organisation operates, approves for staff use, or relies on for sensitive communications.
- Search for any adtech partners your properties list that are flagged as geo-risk (Russia, China, UAE, Cyprus) and assess whether those relationships are intentional and acceptable given your threat model.
- Monitor the DecryptAds quiet removals feed as a supplementary threat-intelligence signal for ad-fraud and malvertising activity.
- Enforce ad-blocking at the browser or network level for managed devices — security experts cited in the source material broadly endorse this as the most effective individual control, with options including uBlock Origin Lite for desktop, Pi-hole for network-level blocking, and Adblock Plus for iOS.
- Review mobile app approvals with the understanding that in-app tracking is largely unaffected by browser-based ad blockers and may involve data brokers collecting geolocation or device fingerprint data.
- Where malvertising incidents occur, check the organisation’s ads.txt and app-ads.txt files for the responsible entity — Edwards notes that in most cases the answer is already listed in those files.
