ADEX uncovers fraud campaigns mimicking Coruna exploit kit techniques
ADEX, an AI-powered traffic validation and anti-fraud ecosystem, has uncovered a disturbing trend in fraudulent advertising campaigns. These campaigns are employing similar fingerprinting and filtering techniques previously seen in the Coruna exploit kit, which targeted iOS devices.
Coruna, first documented by Google's Threat Intelligence Group in March 2026, was designed to evade detection by checking a visitor's device, iPhone model, and iOS version before delivering an exploit. If a visitor did not match the required profile, they were shown harmless content. This strategy allowed the attackers to avoid the attention of researchers, security tools, and other forms of unwanted scrutiny.
ADEX has observed a striking similarity in advertising fraud tactics. These campaigns use visitor information such as device type, browser, or location to determine which content to display. Automated checks may serve a benign landing page to some users, while others with specific conditions are redirected to fraudulent or otherwise prohibited destinations.
Fingerprinting, while not inherently malicious, becomes problematic when the collected data is used to deceive or manipulate users. ADEX found that several fraudulent campaigns were operating across different regions, including Europe and India, with many linked to advertisers based in Asia. Around 50 accounts were identified as running similar campaigns, and the findings were shared with relevant clients for review and action.
The campaigns were often difficult to trace because of their changing visible appearances. One campaign might appear as a social media promotion, while another might present itself as a financial service, making it challenging to connect unrelated advertisers through their creatives alone. However, ADEX discovered that the underlying delivery behavior provided stronger signals. Redirect chains, iframe activity, scripts, and hosting patterns often remained consistent even as the creatives and landing pages changed.
This trend highlights a broader challenge for ad fraud detection: relying solely on visible content may no longer provide enough information to identify malicious campaigns. The Coruna case also underscores the continued relevance of older devices. Apple's March 2026 security updates covered devices such as the iPhone 6s, the first-generation iPhone SE, and the original iPad mini 4. For traffic-quality teams, older-device traffic should not be dismissed simply because newer operating systems have already received security updates.
These findings have significant implications for the digital advertising industry, as they suggest that fraudsters are increasingly using sophisticated techniques to bypass detection mechanisms. Companies must remain vigilant and adapt their strategies to combat evolving threats.