A new free service called DecryptAds scrapes and cross-references public ad-tech files (ads.txt, app-ads.txt, sellers.json) to reveal which companies are tracking users across websites and apps, helping identify malicious ads and data brokers.
<p>It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called <strong>DecryptAds</strong> scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.</p>
<div id="attachment_74134" style="width: 760px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png" target="_blank" rel="noopener"><img aria-describedby="caption-attachment-74134" decoding="async" class="wp-image-74134" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png" alt="" width="750" height="443" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png 1346w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN-768x454.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN-782x462.png 782w" sizes="(max-width: 750px) 100vw, 750px" /></a><p id="caption-attachment-74134" class="wp-caption-text">A Decryptads summary of the advertising partnerships declared by espn.com.</p></div>
<p>The <a href="https://decryptads.com/blog/posts/ad-tech-transparency-launch.html" target="_blank" rel="noopener">newly launched</a> <strong>decryptads.com</strong> says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:</p>
<p>–<strong>ads.txt</strong>: all of the adtech companies and data brokers that may run ads or harvest data from the site;<br />
–<strong>app-ads.txt</strong>: entities that can harvest data from or display ads on mobile and smart TV apps;<br />
–<strong>buyers.json/sellers.json</strong>: the entities buying, selling or reselling ad inventory for a given site or app.</p>
<p><strong>Zach Edwards </strong>is chief research officer for DecryptAds and a threat researcher at the security company <strong>Infoblox</strong>. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.</p>
<p>“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”</p>
<p>Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.</p>
<p>“Supply-chain integrity issues rarely live in a single file,” the site <a href="https://decryptads.com/blog/posts/analytical-features.html" target="_blank" rel="noopener">explains</a>. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”</p>
<p>A search in DecryptAds for the hugely popular sports network <strong>espn.com</strong> reveals 143 ad partners and 19 registered data broker domains are listed within its <a href="https://www.espn.com/ads.txt" target="_blank" rel="noopener">ads.txt</a> and <a href="https://www.espn.com/app-ads.txt" target="_blank" rel="noopener">app-ads.txt</a> files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.</p>
<div id="attachment_74131" style="width: 760px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png" target="_blank" rel="noopener"><img aria-describedby="caption-attachment-74131" decoding="async" loading="lazy" class="wp-image-74131" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png" alt="" width="750" height="230" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png 1790w, https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain-768x236.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain-1536x472.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain-782x240.png 782w" sizes="(max-width: 750px) 100vw, 750px" /></a><p id="caption-attachment-74131" class="wp-caption-text">A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.</p></div>
<h2>HIGH-RISK AD PARTNERS</h2>
<p>DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in <a href="https://decryptads.com/geo_risk" target="_blank" rel="noopener">“geo-risk”</a> areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).</p>
<p>According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm <strong>Between Digital</strong>, which lists a New York address. However, the <a href="https://decryptads.com/ad_system/betweendigital.com" target="_blank" rel="noopener">dossier on Between Digital</a> flags them as a Russian firm, showing that <a href="https://cp.betweendigital.com/files/PublisherOffer.pdf" target="_blank" rel="noopener">their publisher offers</a> (PDF) are processed through <strong>Alfa Bank</strong>, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.</p>
<p>A search for several top U.S. military news websites — including <a href="https://decryptads.com/search/publisher/armytimes.com" target="_blank" rel="noopener">armytimes.com</a>, <a href="https://decryptads.com/publisher/airforcetimes.com" target="_blank" rel="noopener">airforcetimes.com</a>, <a href="https://decryptads.com/publisher/defensenews.com" target="_blank" rel="noopener">defensenews.com</a>, <a href="https://decryptads.com/publisher/navytimes.com" target="_blank" rel="noopener">navytimes.com</a>, <a href="https://decryptads.com/publisher/marinecorpstimes.com" target="_blank" rel="noopener">marinecorpstimes.com</a> and <a href="https://decryptads.com/publisher/federaltimes.com" target="_blank" rel="noopener">federaltimes.com</a> — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.</p>
<div id="attachment_74140" style="width: 758px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/?attachment_id=74140" target="_blank" rel="noopener"><img aria-describedby="caption-attachment-74140" decoding="async" loading="lazy" class="wp-image-74140" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk.png" alt="" width="748" height="374" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk.png 1750w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk-768x384.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk-1536x769.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk-782x391.png 782w" sizes="(max-width: 748px) 100vw, 748px" /></a><p id="caption-attachment-74140" class="wp-caption-text">The “Geo Risk” section of decryptads.com.</p></div>
<p>Pivoting on Between Digital’s <a href="https://decryptads.com/ad_system_sites/betweendigital.com/app_ads_txt/all" target="_blank" rel="noopener">app-ads.txt file</a> reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.</p>
<p>“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”</p>
<p>The <strong>Opera</strong> Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).</p>
<p>Opera.com’s <a href="https://decryptads.com/search/ad_system/opera.com" target="_blank" rel="noopener">profile at DecryptAds</a> identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.<span id="more-74105"></span></p>
<h2>LEGAL DOSSIERS</h2>
<p>One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its <a href="https://decryptads.com/legal_dossier" target="_blank" rel="noopener">Legal Dossier lookup</a>, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.</p>
<p>For example, last month KrebsOnSecurity wrote about researchers from <strong>Bitsight</strong> who found that an extremely popular line of TV streaming sticks called <strong>H96</strong> quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they <a href="https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/" target="_blank" rel="noopener">are spoofing themselves as mobile phones clicking ads on AI-generated slop websites</a>.</p>
<p>Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the <strong>Fengwo Group</strong> — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.</p>
<div id="attachment_74063" style="width: 760px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-74063" decoding="async" loading="lazy" class=" wp-image-74063" src="https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites.png" alt="" width="750" height="229" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites.png 967w, https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites-768x234.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites-782x239.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74063" class="wp-caption-text">Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.</p></div>
<p>A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (<a href="https://decryptads.com/search/publisher/medicalbeautyhub.com" target="_blank" rel="noopener">medicalbeautyhub dot com</a>) shows it shares a seller ID (<a href="https://decryptads.com/seller_id/1674071" target="_blank" rel="noopener">1674071</a>) with a gaming website — <a href="https://decryptads.com/publisher/giacoloredstones.com" target="_blank" rel="noopener">giacoloredstones[.]com</a> — which features yet another seller ID (<a href="https://decryptads.com/seller_id/103488000" target="_blank" rel="noopener">103488000</a>).</p>
<p>Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s <strong>Yandex</strong> ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.</p>
<h2>QUIET REMOVALS</h2>
<p>Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.</p>
<p>This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a <a href="https://decryptads.com/quiet_removals_feed" target="_blank" rel="noopener">quiet removals feed</a> that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.</p>
<div id="attachment_74132" style="width: 760px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-74132" decoding="async" loading="lazy" class=" wp-image-74132" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed.png" alt="" width="750" height="471" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed.png 1411w, https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed-768x483.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed-782x492.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74132" class="wp-caption-text">A screenshot of the Quiet Removals Feed at decryptads.com.</p></div>
<p>“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”</p>
<h2>MALVERTISING AND AI SLOP</h2>
<p>Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.</p>
<p>“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”</p>
<p>Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.</p>
<p>“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.</p>
<p>Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.</p>
<p>“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”</p>
<p>DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.</p>
<h2>WHAT CAN YOU DO?</h2>
<p>The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.</p>
<p>However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, <strong>uBlock Origin Lite</strong> is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.</p>
<p><strong>Adblock Plus</strong> is a decent option for <strong>iPhone</strong> and <strong>iPad</strong> users. For power users, Adblock and uBlock Origin both support custom blocking rules from <a href="https://easylist.to/" target="_blank" rel="noopener">easylist.to</a>, which publishes a frequently updated list that removes most advertisements from webpages.</p>
<p>The well established browser extension <strong>NoScript</strong> blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.</p>
<p>More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a <strong>Raspberry Pi</strong> can be turned into <a href="https://www.raspberrypi.com/tutorials/running-pi-hole-on-a-raspberry-pi/" target="_blank" rel="noopener">a powerful ad blocker for all devices on a local network</a> when fitted with a microSD memory card and a free program called <a href="https://github.com/pi-hole/pi-hole" target="_blank" rel="noopener"><strong>Pi-hole</strong></a>. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.</p>
<p>Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.</p>
<p>No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) <a href="https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/" target="_blank" rel="noopener">far more precise data</a> about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (<a href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/" target="_blank" rel="noopener">including any smart TVs!</a>), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.</p>
# Who’s Tracking You? Use This New Service to Find Out
Source: [https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/](https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/)
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day\. That information is already semi\-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms\. Not anymore: A powerful and free new service called**DecryptAds**scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you\.
[](https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png)
A Decryptads summary of the advertising partnerships declared by espn\.com\.
The[newly launched](https://decryptads.com/blog/posts/ad-tech-transparency-launch.html)**decryptads\.com**says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data\. These files include:
–**ads\.txt**: all of the adtech companies and data brokers that may run ads or harvest data from the site; –**app\-ads\.txt**: entities that can harvest data from or display ads on mobile and smart TV apps; –**buyers\.json/sellers\.json**: the entities buying, selling or reselling ad inventory for a given site or app\.
**Zach Edwards**is chief research officer for DecryptAds and a threat researcher at the security company**Infoblox**\. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross\-referenced to build a more complete picture of the advertising ecosystem for each website or app\.
“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said\. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved\.”
Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI\-generated slop websites and apps\. And as decryptads\.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps\.txt or app\-ads\.txt file\.
“Supply\-chain integrity issues rarely live in a single file,” the site[explains](https://decryptads.com/blog/posts/analytical-features.html)\. “They show up as broken cross\-references between ads\.txt, app\-ads\.txt, and sellers\.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized\-seller list\.”
A search in DecryptAds for the hugely popular sports network**espn\.com**reveals 143 ad partners and 19 registered data broker domains are listed within its[ads\.txt](https://www.espn.com/ads.txt)and[app\-ads\.txt](https://www.espn.com/app-ads.txt)files\. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states\. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn\.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information\.
[](https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png)
A visual representation of the complex ad supply chain declared by espn\.com\. Image: decryptads\.com\.
## HIGH\-RISK AD PARTNERS
DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in[“geo\-risk”](https://decryptads.com/geo_risk)areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates \(UAE\)\.
According to DecryptAds, espn\.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm**Between Digital**, which lists a New York address\. However, the[dossier on Between Digital](https://decryptads.com/ad_system/betweendigital.com)flags them as a Russian firm, showing that[their publisher offers](https://cp.betweendigital.com/files/PublisherOffer.pdf)\(PDF\) are processed through**Alfa Bank**, Russia’s largest private commercial bank and one of several financial institutions placed under U\.S\. sanctions in 2022 after Russia invaded Ukraine\. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies\.
A search for several top U\.S\. military news websites — including[armytimes\.com](https://decryptads.com/search/publisher/armytimes.com),[airforcetimes\.com](https://decryptads.com/publisher/airforcetimes.com),[defensenews\.com](https://decryptads.com/publisher/defensenews.com),[navytimes\.com](https://decryptads.com/publisher/navytimes.com),[marinecorpstimes\.com](https://decryptads.com/publisher/marinecorpstimes.com)and[federaltimes\.com](https://decryptads.com/publisher/federaltimes.com)— shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama\. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites\.
[](https://krebsonsecurity.com/?attachment_id=74140)
The “Geo Risk” section of decryptads\.com\.
Pivoting on Between Digital’s[app\-ads\.txt file](https://decryptads.com/ad_system_sites/betweendigital.com/app_ads_txt/all)reveals hundreds of domains featuring simple web\-based games that are frequently interrupted by ads\. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two\-thirds of their portfolio\.
“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity\. “The problem we have right now is that for years we’ve had almost no one policing these ads\.txt and app\-ads\.txt files\.”
The**Opera**Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech \(the operational headquarters of Opera remain in Oslo, Norway\)\.
Opera\.com’s[profile at DecryptAds](https://decryptads.com/search/ad_system/opera.com)identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine\. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera\.com’s ads\.txt and app\-ads\.txt files\.
## LEGAL DOSSIERS
One feature of DecryptAds that sent this author down multiple hours\-long research rabbit holes is its[Legal Dossier lookup](https://decryptads.com/legal_dossier), which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps\.
For example, last month KrebsOnSecurity wrote about researchers from**Bitsight**who found that an extremely popular line of TV streaming sticks called**H96**quietly rent out each user’s Internet connection to strangers\. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they[are spoofing themselves as mobile phones clicking ads on AI\-generated slop websites](https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/)\.
Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the**Fengwo Group**— also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones\.

Examples of ad landing pages linked to the Fengwo Group\. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones\. Image: Bitsight\.
A DecryptAds legal dossier on the \(now dormant\) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above \([medicalbeautyhub dot com](https://decryptads.com/search/publisher/medicalbeautyhub.com)\) shows it shares a seller ID \([1674071](https://decryptads.com/seller_id/1674071)\) with a gaming website —[giacoloredstones\[\.\]com](https://decryptads.com/publisher/giacoloredstones.com)— which features yet another seller ID \([103488000](https://decryptads.com/seller_id/103488000)\)\.
Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s**Yandex**ad system featuring extremely low\-quality games or simple utilities that pepper visitors with ads\.
## QUIET REMOVALS
Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions\.
This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others\. To address that visibility gap, DecryptAds features a[quiet removals feed](https://decryptads.com/quiet_removals_feed)that records and correlates all of the sellers\.json removals across ad exchanges for the same seller domain or name\.

A screenshot of the Quiet Removals Feed at decryptads\.com\.
“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said\. “The ban is just removing them from the sellers\.json file, but they told nobody\. One day it was there, the next it was gone\. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once\.”
## MALVERTISING AND AI SLOP
Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all\-too\-frequent occurrence in the modern adtech industry\. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads\.
“None of these slop AI content farms are paying for that kind of protection,” he said\. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads\. Most malvertising attacks don’t happen on espn\.com or huffpost\.com, but rather \[on\] some lower quality content farm and someone just went there because it came up in a search\.”
Edwards said the AI slop websites are populated with machine\-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology\. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads\.txt or app\-ads\.txt file\.
“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero\-click payloads on an almost daily basis,” he said\.
Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data\-sharing by the major ad networks\. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer\.
“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained\. “You may see the malicious zero\-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly\. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad\.”
DecryptAds also offers an application programming interface \(API\) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms\.
## WHAT CAN YOU DO?
The only sane reaction to the examples described above is to block all online ads outright\. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world\.
However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions\. For those primarily surfing via a regular desktop or laptop Web browser,**uBlock Origin Lite**is an excellent free and well\-maintained open source option\. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android\-based devices\.
**Adblock Plus**is a decent option for**iPhone**and**iPad**users\. For power users, Adblock and uBlock Origin both support custom blocking rules from[easylist\.to](https://easylist.to/), which publishes a frequently updated list that removes most advertisements from webpages\.
The well established browser extension**NoScript**blocks all non\-approved Javascript code, and it generally does a fine job blocking most ads from loading\. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly\.
More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it\. A tiny, low\-cost and broadly available computer known as a**Raspberry Pi**can be turned into[a powerful ad blocker for all devices on a local network](https://www.raspberrypi.com/tutorials/running-pi-hole-on-a-raspberry-pi/)when fitted with a microSD memory card and a free program called[**Pi\-hole**](https://github.com/pi-hole/pi-hole)\. Once you’ve set it up properly and changed your router’s network settings to use the Pi\-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network\.
Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices\. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content\. But in my experience, they’re not doing this because the user experience is somehow way better on the app \(as LinkedIn tries to convince us non\-app users several times a week via email\)\. On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser\.
No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect \(and in many cases resell\)[far more precise data](https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/)about who, what and where their users are\. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days\. So be cautious about the apps you install on your mobile devices \([including any smart TVs\!](https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/)\), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms\.
The article introduces CloakBrowser, an open-source stealth Chromium-based browser designed to bypass bot detection systems like reCAPTCHA and Cloudflare Turnstile. It claims to offer superior stealth capabilities by patching the C++ source code rather than injecting JavaScript, positioning itself as a free alternative to expensive commercial anti-detect browsers.
Adform, a major online advertising platform, was hacked and served malicious code that stole cryptocurrency wallet addresses from visitors' clipboards, highlighting the security benefits of ad blockers.
A WIRED security roundup reveals that period tracker apps, notably Stardust, share intimate health data with third-party analytics firms and Facebook, raising serious privacy concerns.
A researcher reverse-engineered AppLovin's ad mediation cipher protocol, revealing that it uses a weak non-cryptographic PRNG and a static salt to encrypt device information, allowing deterministic re-identification of iPhones across apps even when users deny tracking permission.
Serus launches a privacy platform that helps users discover, control and remove personal data exposed across hundreds of sites and combat AI-generated scams and deepfakes.