ADEX, an AI-powered traffic validation and anti-fraud ecosystem, reports that it’s identified similarities between visitor-filtering techniques used by Coruna, an iOS exploit kit linked to Apple’s March 2026 security updates, and methods used to conceal fraudulent advertising campaigns.
Coruna, first documented by Google’s Threat Intelligence Group in March 2026, checks a visitor’s device, iPhone model and iOS version before deciding whether to deliver an exploit. Visitors who don’t match the required profile are shown harmless content instead, helping the attackers avoid researchers, security tools and other unwanted scrutiny.
ADEX reports that it’s has observed the same underlying logic in advertising fraud. Fraudulent campaigns can use information about a visitor’s device, browser or location to determine which content to serve. Automated checks may see a benign landing page, while users matching specific conditions are redirected to fraudulent or otherwise prohibited destinations.
ADEX says fingerprinting itself is not inherently malicious. It’s widely used by websites, analytics platforms and security systems. The key difference is how that information is used after collection.
ADEX reportedly has observed comparable advertising campaigns across several regions, including Europe and India, with many linked to advertisers based in Asia. Around 50 accounts were identified as running similar campaigns, and the findings were shared with relevant clients for review and action.
The campaigns frequently changed their visible appearance. One could resemble a social media promotion, while another presented itself as a financial service, making seemingly unrelated advertisers harder to connect through creatives alone.
However, ADEX found that underlying delivery behavior provided stronger signals. Redirect chains, iframe activity, scripts and hosting patterns often remained consistent even when creatives and landing pages changed.
ADEX says the findings highlight a broader challenge for ad fraud detection: visible content alone may no longer provide enough information to identify malicious campaigns.
The Coruna case also underlines the relevance of older devices. Apple’s March updates covered devices including the iPhone 6s, first-generation iPhone SE and original iPad mini 4. For traffic-quality teams, older-device traffic should therefore not be dismissed simply because newer operating systems have already received security updates.
I hope you’ll help support Apple World Today by becoming a patron. Almost all our income is from Patreon support and sponsored posts. Patreon pricing ranges from $2 to $10 a month. Thanks in advance for your support.




