The same fingerprinting and filtering techniques used by the Coruna exploit kit to avoid detection are appearing in fraudulent advertising campaigns
LIMASSOL, Cyprus, August 24 2026 – ADEX, a leading AI-powered traffic validation and anti-fraud ecosystem, has identified similarities between the visitor filtering used by Coruna, an iOS exploit kit linked to Apple’s March 2026 security updates, and techniques used to conceal fraudulent advertising campaigns.
On March 11, 2026, Apple backported security patches to iOS 15.8.7 and iOS 16.7.15, covering devices as old as the iPhone 6s, the original iPad mini 4, and the first-generation iPhone SE. The patch responded to Coruna, a modular exploit framework first documented by Google’s Threat Intelligence Group on March 3, 2026, and traced by a major cybersecurity firm to the same code base as Operation Triangulation, the zero-click iOS campaign it uncovered in 2023.

Coruna checks a visitor’s device, iPhone model and iOS version before deciding whether to deliver an exploit. Visitors who do not match its criteria are shown harmless content instead. The approach allows the exploit kit to distinguish potential targets from researchers, security tools and other visitors it does not want to expose its activity to.
Coruna works like a construction set, or a modular framework, as GTIG describes it. The set contains separate pieces that share a common set of utilities, and the kit’s own loaders hold them together. Each iOS band gets a matched exploit and bypass: one bypass for iOS 13 through 14.x, another for 15 through 16.2, and three more covering the 16.3 to 17.2.1 range.
Several of the vulnerabilities are named and public. The Hacker News lists the CVE mapping in full, including CVE-2024-23222, a WebKit type confusion bug that had been exploited as a zero-day before Apple patched it in iOS 17.3 on January 22, 2024. Others go back further, to CVE-2021-30952 and a pair of 2020 kernel issues.
ADEX has found the same basic approach in ad fraud. Campaigns use information about the visitor to determine what content to serve, allowing them to show one page to automated checks and another to users who meet specific conditions.
The Same Logic, Different Purpose
Fingerprinting is not unusual on its own. Websites, analytics systems and security products can all use information about a visitor’s device and browser.
The difference is what happens after that information is collected. In Coruna’s case, the result determines whether an exploit chain is delivered. In fraudulent advertising, the same type of filtering can determine whether a visitor sees desired content or is redirected to a fraudulent or otherwise prohibited destination.

ADEX’s Findings in Advertising
Comparable campaigns were observed by ADEX across several regions, including Europe and India. Many of the campaigns were traced to advertisers based in Asia. Around 50 accounts were identified as being used to run similar campaigns. The information was shared with the relevant clients for review and action.
The campaigns also changed their visible content frequently. One could appear to promote a social media offer, while another presented itself as a financial service. The different themes made the advertisers appear unrelated even when they relied on similar delivery infrastructure.
The visible advertisement was therefore not always a useful way to identify the campaign.
ADEX found that the underlying delivery behavior provided stronger indicators. Redirect chains, iframe activity, scripts and hosting patterns could remain consistent even when the creative and landing page changed.
Older Devices Remain Relevant
The Coruna case also highlights the importance of monitoring older devices.
Apple issued security updates for iOS 15.8.7 and iOS 16.7.15 on March 11, 2026. The updates covered devices including the iPhone 6s, the original iPad mini 4 and the first generation iPhone SE. Coruna had been linked to the vulnerabilities addressed by those updates.
For traffic quality teams, older device traffic should not be treated as irrelevant simply because newer systems have received security updates.
Quick fact: Coruna did not appear from nowhere. Two of its exploits target the same vulnerabilities used as zero-days in Operation Triangulation, the 2023 campaign uncovered by a major cybersecurity vendor while monitoring its own corporate Wi-Fi network and which relied on an undocumented hardware feature in Apple chips. Three weeks later, researchers compared the code itself and concluded that Coruna’s kernel exploit for those two bugs is an updated build of the Triangulation one, and that the kit is an updated version of the same framework.
About ADEX
ADEX is the anti-fraud and traffic-quality platform within AdTech Holding. It analyzes billions of impressions, clicks, and conversions, protecting AdTech products and partners from malware-driven and invalid traffic attacks.