The same fingerprinting and filtering techniques used by the Coruna exploit kit to avoid detection are appearing in fraudulent advertising campaigns
LIMASSOL, Cyprus, Sept. 1, 2026 /PRNewswire/ — ADEX, an AI-powered traffic validation and anti-fraud ecosystem, has identified similarities between visitor-filtering techniques used by Coruna, an iOS exploit kit linked to Apple’s March 2026 security updates, and methods used to conceal fraudulent advertising campaigns.
Coruna, first documented by Google’s Threat Intelligence Group in March 2026, checks a visitor’s device, iPhone model and iOS version before deciding whether to deliver an exploit. Visitors who do not match the required profile are shown harmless content instead, helping the attackers avoid researchers, security tools and other unwanted scrutiny.
ADEX has observed the same underlying logic in advertising fraud.
Fraudulent campaigns can use information about a visitor’s device, browser or location to determine which content to serve. Automated checks may see a benign landing page, while users matching specific conditions are redirected to fraudulent or otherwise prohibited destinations.
Fingerprinting itself is not inherently malicious. It is widely used by websites, analytics platforms and security systems. The key difference is how that information is used after collection.
ADEX observed comparable advertising campaigns across several regions, including Europe and India, with many linked to advertisers based in Asia. Around 50 accounts were identified as running similar campaigns, and the findings were shared with relevant clients for review and action.
The campaigns frequently changed their visible appearance. One could resemble a social media promotion, while another presented itself as a financial service, making seemingly unrelated advertisers harder to connect through creatives alone.
However, ADEX found that underlying delivery behavior provided stronger signals. Redirect chains, iframe activity, scripts and hosting patterns often remained consistent even when creatives and landing pages changed.
The findings highlight a broader challenge for ad fraud detection: visible content alone may no longer provide enough information to identify malicious campaigns.
The Coruna case also underlines the relevance of older devices. Apple’s March updates covered devices including the iPhone 6s, first-generation iPhone SE and original iPad mini 4. For traffic-quality teams, older-device traffic should therefore not be dismissed simply because newer operating systems have already received security updates.
Media Contact:
Michael Gor
+35797767567
[email protected]
View original content:https://www.prnewswire.com/news-releases/adex-finds-coruna-ios-exploit-tactics-reused-in-ad-fraud-campaigns-302866013.html
SOURCE ADEX
