DecryptAds: Unveiling Hidden Adtech Supply Chain Risks
The digital advertising ecosystem, often opaque and sprawling, presents significant challenges for security professionals seeking to understand data flows and potential threats. A new, free service called DecryptAds is addressing this by scraping and correlating publicly available adtech data, offering unprecedented visibility into the entities tracking users and serving advertisements. This platform enables a more granular analysis of the ad supply chain, exposing geo-risk partners, potential conflicts of interest, and avenues for malicious activity, as detailed by KrebsOnSecurity.
Technical Analysis: Auditing Adtech Supply Chains for Hidden Threats
DecryptAds, developed by Zach Edwards, Chief Research Officer at Infoblox, and two co-founders, was built to approach adtech from a security perspective. The service aggregates and cross-references data from several standard files that websites and applications use to declare their advertising and data-sharing partners:
- ads.txt: Declares authorized digital sellers of inventory for websites.
- app-ads.txt: Extends the
ads.txtstandard to mobile apps, connected TV, and other programmatic inventory. - buyers.json/sellers.json: Files that disclose the entities buying, selling, or reselling ad inventory.
Traditionally, the data within these individual files is difficult to parse and correlate, making it challenging for organizations to gain a complete picture of their adtech dependencies. DecryptAds centralizes this information, making it actionable for privacy and security use cases that have been historically underserved.
One critical application is the identification of malicious ads designed to foist malware on users. By mapping the intricate relationships declared across ads.txt, app-ads.txt, and sellers.json files, DecryptAds helps uncover supply-chain integrity issues that rarely reside within a single file. These issues can manifest as broken cross-references, cloned declaration sets across unrelated domains, or seller removals that are only evident when viewed across multiple exchanges.
Furthermore, DecryptAds highlights ad networks based in “geo-risk” areas, such as China, Russia, Cyprus, and the United Arab Emirates (UAE), which may pose heightened national security or data privacy concerns. For instance, an analysis of espn.com using DecryptAds revealed 143 ad partners and 19 registered data broker domains. Notably, four of espn.com’s advertising entities were found to be based in geo-risk regions.
A prominent example identified is the adtech firm Between Digital. Despite listing a New York address, DecryptAds flags it as a Russian firm, noting that its publisher offers are processed through Alfa Bank, a major Russian financial institution sanctioned by the U.S. in 2022. Worryingly, Between Digital, which collects ad data on approximately 55,000 partner websites, is listed on several top U.S. military news websites, including armytimes.com and defensenews.com. DecryptAds’ research also points to potential conflicts of interest, as Between Digital acts as both a publisher and a reseller for approximately two-thirds of its portfolio, creating opportunities to direct client spending towards its own properties. This exemplifies the importance of proactively auditing ads.txt and app-ads.txt files to detect such opaque arrangements.
The service also aids in detecting the proliferation of AI-generated “slop” websites and apps, which often rely on complex adtech connections. With several U.S. states now requiring data brokers to register, tools like DecryptAds are becoming essential for organizations to monitor who is collecting data from their users and through which channels. Almost half of the data brokers identified on espn.com were found to be collecting geolocation data, while others gathered device fingerprints and sensitive personal information.
Actionable Recommendations for Enhancing Adtech Supply Chain Security
Security professionals and privacy officers should integrate tools like DecryptAds into their threat intelligence and compliance workflows. Proactive steps include:
- Utilize DecryptAds: Regularly scan and analyze your organization’s websites and applications using DecryptAds to gain clear visibility into your adtech ecosystem. This is a crucial step for how to identify adtech geo-risk partners and verify the legitimacy of declared partners.
- Review and Validate Ad Partners: Scrutinize all declared adtech partners, especially those flagged as geo-risk or exhibiting reseller/publisher conflicts of interest. Evaluate the necessity of partnerships with entities from adversarial or high-risk nations.
- Enhance Data Privacy Controls: Understand what data your ad partners are collecting (geolocation, device fingerprints, PII) and ensure compliance with relevant data privacy regulations like those in California, Oregon, Texas, and Vermont.
- Monitor for Supply Chain Anomalies: Implement continuous monitoring for changes or inconsistencies in your
ads.txt,app-ads.txt, andsellers.jsonfiles, which could indicate compromise, misconfiguration, or new risky partnerships. - Educate Stakeholders: Inform marketing, web development, and legal teams about the security and privacy implications of adtech partnerships and the importance of supply chain transparency.
By proactively managing and monitoring the adtech supply chain, organizations can significantly reduce their exposure to malicious advertising, data exfiltration, and other privacy and security risks.
Related: npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises, GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2