September 29, 2026

Exposing the Adtech Underworld: New Intelligence Tool Unmasks Global Surveillance and Malvertising

exposing-the-adtech-underworld-new-intelligence-tool-unmasks-global-surveillance-and-malvertising

exposing-the-adtech-underworld-new-intelligence-tool-unmasks-global-surveillance-and-malvertising

Main Facts

The hidden mechanics of the modern digital advertising ecosystem have long remained an opaque labyrinth. While websites and mobile applications are legally obligated to disclose their programmatic advertising partners and data-harvesting affiliates, this information has traditionally been sequestered behind fragmented files, specialized interfaces, and proprietary walled gardens. For the average internet user, determining who is harvesting personal data, tracking real-world movements, or funding malicious ad networks is nearly impossible.

Enter DecryptAds, a powerful, free, and publicly accessible intelligence platform designed to scrape, correlate, and demystify the vast web of adtech relationships. Launched via decryptads.com, the service continuously analyzes public disclosure files—such as ads.txt, app-ads.txt, and sellers.json—to build comprehensive profiles of how data brokers, advertisers, and publishers interact.

Co-founded by Zach Edwards, chief research officer for DecryptAds and a threat researcher at security firm Infoblox, alongside two other technology veterans, the platform approaches advertising technology strictly through a security and privacy lens. By cross-referencing fragmented supply chains, DecryptAds uncovers severe risks, including hidden connections to sanctioned regimes, widespread distribution of AI-generated content farms ("AI slop"), and covert "malvertising" vectors that target unsuspecting web users with malware and phishing payloads.


Chronology of an Adtech Revolution

The opacity of the digital advertising supply chain has been a systemic vulnerability for decades, evolving alongside programmatic bidding platforms.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
  • The Birth of ads.txt (2017): To combat ad fraud—specifically domain spoofing, where bad actors pretend to sell legitimate ad inventory—the Interactive Advertising Bureau (IAB) introduced ads.txt (Authorized Digital Sellers). Publishers were encouraged to publish a public text file listing who was authorized to sell their ad space. While it provided a foundational ledger, analyzing these files manually across millions of domains remained impractical.
  • The Rise of Mobile and App Disclosures: As traffic shifted aggressively to mobile applications and smart TVs, the IAB introduced app-ads.txt, expanding public disclosures to mobile environments. However, these files grew exponentially complex, riddled with cross-references, resellers, and intermediary brokers.
  • State-Level Data Broker Registrations (Recent Years): Increased regulatory pressure prompted states including California, Oregon, Texas, and Vermont to pass landmark legislation requiring data brokers to formally register their operations if they buy or sell consumer data originating within their borders. This provided a new stream of transparency data.
  • The Launch of DecryptAds (2026): Recognizing that individual disclosure files were useless in isolation, Edwards and his co-founders developed decryptads.com to continuously scrape and correlate ads.txt, app-ads.txt, and sellers.json files globally. The platform introduced advanced analytical features, a "geo-risk" warning system, a "quiet removals feed," and a legal dossier lookup engine to expose the structural integrity issues plaguing modern digital advertising.

Supporting Data and Case Studies

DecryptAds has already brought to light staggering insights regarding how high-traffic mainstream platforms, military news outlets, and popular software interact with questionable advertising entities.

The ESPN Supply Chain

A search for the major sports network espn.com reveals 143 ad partners and 19 registered data broker domains declared within its ads.txt and app-ads.txt files. According to DecryptAds, nearly half of these data brokers collect precise geolocation data from visitors who do not utilize ad blockers, while others harvest device fingerprints and sensitive personal information.

High-Risk Geographies and Sanctioned Entities

DecryptAds explicitly flags advertising partners based in "geo-risk" regions—primarily China and Russia—as well as intermediary financial hubs closely tied to them, such as Cyprus and the United Arab Emirates (UAE).

  • Between Digital: ESPN.com works with four ad entities based in Russia, China, or the UAE. Among them is Between Digital, which lists a New York address but is unmasked by DecryptAds as a Russian firm. Its publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank, which was placed under U.S. sanctions following the 2022 invasion of Ukraine.
  • Military News Targeting: A query across major U.S. military news publications—including Army Times, Air Force Times, Defense News, Navy Times, Marine Corps Times, and Federal Times—reveals that all of them allow Between Digital to serve ads and track users, alongside other entities in the UAE and the ownership secrecy haven of Panama. Between Digital’s data collection extends across approximately 55,000 partner websites.
  • The Opera Browser: Majority-owned since 2016 by the Chinese company Kunlun Tech (though maintaining operational headquarters in Oslo, Norway), Opera.com features a profile listing 27 registered data brokers. These include 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine—representing just 7% of the total adtech partners specified in its disclosure files.

The AI Slop and H96 Streaming Stick Connection

In July 2026, security researchers at Bitsight exposed popular H96 TV streaming sticks for quietly renting out user internet connections to strangers and spoofing mobile phone traffic to click on ads hosted on AI-generated "slop" websites. Bitsight linked these malicious operations to the Chinese entity known as the Fengwo Group.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Utilizing DecryptAds’ Legal Dossier feature, researchers discovered that a dormant Fengwo Group domain (medicalbeautyhub.com) shared a seller ID (1674071) with a gaming website (giacoloredstones.com), which in turn linked to another seller ID (103488000). Pivoting on that second ID revealed hundreds of active websites operating within Russia’s Yandex ad system, pumping out low-quality games and utility apps designed to aggressively pepper users with ads.


Official Responses and Industry Dynamics

The creation of DecryptAds highlights a glaring structural flaw in the digital advertising industry: the lack of systemic accountability.

According to Zach Edwards, major advertising networks frequently suspect individual advertisers of generating fraudulent, unauthentic clicks or serving malicious code. When this happens, the standard industry response is a "quiet removal"—the offender is silently scrubbed from the network’s sellers.json file without public notification.

"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards explained to KrebsOnSecurity. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

To counteract this, DecryptAds developed a Quiet Removals Feed to track and correlate these sudden disappearances across multiple ad exchanges, providing researchers with a unified historical ledger of bad actors.

Furthermore, Edwards emphasizes that solving the epidemic of malvertising and AI slop requires greater data-sharing from major ad networks. Specifically, he advocates for the widespread exposure of the Supply Chain Object (SCO)—structured data attached to server-side bid requests that details every intermediary, reseller, and final buyer involved in an ad impression. Without the SCO, organizations hit with zero-click malware payloads or phishing redirects remain powerless to trace the precise financial culprit.

At the time of reporting, KrebsOnSecurity reached out to Between Digital and its founder for comment regarding its ties to sanctioned Russian financial institutions; the story remains open for future updates pending a reply.


Implications for National Security, Privacy, and Consumers

The democratization of adtech intelligence via DecryptAds carries profound implications for cybersecurity, privacy advocates, and everyday internet users.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

National Security and Government Targeting

The fact that defense news outlets and mainstream media properties are deeply entangled with ad networks operating out of adversarial nations creates severe counterintelligence vulnerabilities. As Edwards warns, sophisticated threat actors frequently utilize programmatic advertising rails to target government personnel and defense contractors with zero-click payloads, leveraging low-quality content farms that lack basic security vetting.

The Erosion of Consumer Privacy

The ease with which data brokers harvest geolocation data, device fingerprints, and browsing habits underscores the reality that the modern web is a surveillance economy. Companies aggressively push consumers toward dedicated mobile apps not to improve user experience, but to lock them into proprietary ecosystems where tracking is more precise, continuous, and lucrative. These apps are also frequently leveraged to quietly enroll users into data-harvesting pipelines used to train large language models.

Actionable Defense: What You Can Do

Security experts agree that the only foolproof defense against ad-based tracking, malvertising, and data harvesting is aggressive ad-blocking. Users are advised to adopt a multi-layered approach depending on their environment:

  • Desktop Browsing: Open-source, well-maintained extensions such as uBlock Origin Lite or traditional ad blockers utilizing custom blocklists from easylist.to offer robust protection.
  • Mobile Devices: Adblock Plus provides viable filtering for iOS devices (iPhones and iPads), while Firefox on Android supports advanced extension architectures.
  • Network-Level Defense: Technically inclined users can deploy a micro-computer like a Raspberry Pi running Pi-hole, transforming it into a local network-level DNS sinkhole that stops advertisements and trackers across every connected device in a household.
  • App Caution: Minimize the installation of unnecessary mobile applications and smart TV utilities. Whenever possible, interact with online services directly through a secure web browser equipped with content-blocking extensions.