{"id":6085,"date":"2026-08-20T15:04:39","date_gmt":"2026-08-20T15:04:39","guid":{"rendered":"https:\/\/adex.com\/blog\/?p=6085"},"modified":"2026-08-21T07:22:11","modified_gmt":"2026-08-21T07:22:11","slug":"coruna-ios-exploit-kit","status":"publish","type":"post","link":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/","title":{"rendered":"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On March 3, 2026, Google Threat Intelligence Group published its analysis of <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/coruna-powerful-ios-exploit-kit\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Coruna, an iOS exploit kit.<\/a> This kit was a full<a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/coruna-powerful-ios-exploit-kit\"> <\/a>framework with five complete exploit chains and 23 individual exploits, covering every iOS version from 13.0 to 17.2.1. The delivery was zero-click: a user opened a web page in Safari, and the attack began before anything even appeared on screen, but only if the device matched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, here is the trick that helped Coruna stay out of sight for years: before it delivers anything, it fingerprints the visitor and decides whether that visitor is worth exploiting, and visitors who fail the check get something harmless instead. That is the same filtering logic that ad cloaking uses to separate moderation systems from real users, running with the goal inverted.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"inside-the-coruna-exploit-kit\">Inside the Coruna Exploit Kit<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Coruna works like a construction set, or a modular framework, as GTIG describes it. The set contains separate pieces that share a common set of utilities, and the kit&#8217;s own loaders hold them together. Each iOS band gets a matched exploit and bypass: one bypass for iOS 13 through 14.x, another for 15 through 16.2, and three more covering the 16.3 to 17.2.1 range.<\/p>\n\n\n\n<!-- =========================================================\n     ADEX-STYLE VISUAL: \"What Is Actually Inside the Coruna Kit\"\n     For: Coruna iOS exploit kit article\n\n     WORDPRESS: paste this whole block into a \"Custom HTML\" block.\n     All CSS is scoped under .adexvz-6 so it cannot touch the theme.\n     No global selectors, no <body> rules, no webfont loading,\n     no emoji. Diagram is inline SVG, scales cleanly.\n     ========================================================= -->\n\n<div class=\"adexvz-6\">\n<style>\n.adexvz-6{\n  --az-ink:#0B0F1C; --az-body:#2A3347; --az-faint:#8896B3;\n  --az-line:#DDE3EE; --az-bg:#F7F9FC;\n  --az-teal:#00C9B8; --az-blue:#3B5BDB; --az-red:#E03355;\n  all:initial;\n  display:block !important;\n  font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Arial,sans-serif !important;\n  color:var(--az-body) !important;\n  background:var(--az-bg) !important;\n  border:1px solid var(--az-line) !important;\n  border-radius:12px !important;\n  padding:24px 20px 18px !important;\n  margin:32px 0 !important;\n  -webkit-font-smoothing:antialiased;\n}\n.adexvz-6 *,.adexvz-6 *::before,.adexvz-6 *::after{box-sizing:border-box !important;}\n\n.adexvz-6 .az-head{display:flex !important;align-items:center !important;gap:10px !important;margin:0 0 18px !important;}\n.adexvz-6 .az-logo{width:24px !important;height:28px !important;flex:0 0 auto !important;display:block !important;}\n.adexvz-6 .az-title{\n  margin:0 !important;padding:0 !important;border:0 !important;\n  font-size:16px !important;line-height:1.3 !important;font-weight:700 !important;\n  color:var(--az-ink) !important;letter-spacing:-0.01em !important;font-family:inherit !important;\n}\n.adexvz-6 .az-sub{\n  margin:2px 0 0 !important;font-size:12px !important;line-height:1.4 !important;\n  color:var(--az-faint) !important;font-weight:400 !important;\n}\n\n.adexvz-6 .az-scroll{\n  overflow-x:auto !important;-webkit-overflow-scrolling:touch !important;\n  border:1px solid var(--az-line) !important;border-radius:10px !important;\n  background:#fff !important;padding:16px 14px 12px !important;\n}\n.adexvz-6 .az-svg{display:block !important;width:100% !important;min-width:960px !important;height:auto !important;}\n\n.adexvz-6 .az-foot{\n  display:flex !important;flex-wrap:wrap !important;align-items:center !important;gap:16px !important;\n  margin:14px 0 0 !important;padding:12px 2px 0 !important;border-top:1px solid var(--az-line) !important;\n}\n.adexvz-6 .az-leg{display:flex !important;align-items:center !important;gap:6px !important;\n  font-size:11px !important;line-height:1.4 !important;color:var(--az-faint) !important;}\n.adexvz-6 .az-bar{width:12px !important;height:3px !important;border-radius:2px !important;display:block !important;flex:0 0 auto !important;}\n.adexvz-6 .az-src{margin-left:auto !important;font-size:10px !important;color:#C5CDD9 !important;letter-spacing:0.05em !important;}\n.adexvz-6 .az-hint{display:none !important;}\n\n@media (max-width:760px){\n  .adexvz-6{padding:18px 14px 14px !important;}\n  .adexvz-6 .az-hint{display:block !important;margin:0 0 8px !important;font-size:11px !important;color:var(--az-faint) !important;}\n  .adexvz-6 .az-src{margin-left:0 !important;}\n}\n<\/style>\n\n  <div class=\"az-head\">\n    <svg class=\"az-logo\" viewBox=\"0 0 34 40\" fill=\"none\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M5.31 32.14L17.23 39l11.92-6.87L17.23 20 5.31 32.14ZM4.57 28.5l10.36-10.84-2.77-2.84L4.57 28.5ZM19.55 17.62l10.33 10.88-5.91-10.47 2.47-2.51 7.15 14.04.85-.5V9.19l-4.23-2.45L19.55 17.62ZM15.93 0L0 9.19V29.06l.85.5 10.44-19.48 5.96 6.15 3.32-3.47L17.23 5.48l-1.65 3.01-2.62-2.69L15.93 0ZM18.53 0l4.64 9.08 3.97-4.12L18.53 0Z\" fill=\"#00C9B8\"\/>\n    <\/svg>\n    <div>\n      <p class=\"az-title\">What Is Actually Inside the Coruna Kit<\/p>\n      <p class=\"az-sub\">Five stages, 23 interchangeable parts. The kit reads the iOS version first, then assembles the one combination that fits it.<\/p>\n    <\/div>\n  <\/div>\n\n  <p class=\"az-hint\">Scroll sideways to see all five stages.<\/p>\n\n  <div class=\"az-scroll\">\n    <svg class=\"az-svg\" viewBox=\"0 0 1088 470\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"\n         aria-labelledby=\"azd6t azd6d\" focusable=\"false\">\n      <title id=\"azd6t\">The composition of the Coruna iOS exploit kit<\/title>\n      <desc id=\"azd6d\">Five stages of the exploit chain shown as five columns. Stage one, running code in the browser, holds five WebContent remote code execution exploits. Stage two, defeating pointer authentication, holds five PAC bypasses. Stage three, escaping the browser sandbox, holds two. Stage four, reaching kernel privileges, holds six privilege escalation exploits. Stage five, bypassing page protection, holds five PPL bypasses. Each part covers a different band of iOS versions, so a device running a given version is matched with exactly one part per stage. The highlighted parts show the chain that would be assembled for an iPhone on iOS 16.6: cassowary, seedbell 16 6, NeuronLoader, Gruber and Carbone.<\/desc>\n\n      <g font-family=\"'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Arial,sans-serif\">\n\n        <!-- ============ COLUMN 1: WebContent RCE ============ -->\n        <rect x=\"10\" y=\"10\" width=\"204\" height=\"60\" rx=\"9\" fill=\"#EEF2FF\" stroke=\"#C9D4F5\"\/>\n        <rect x=\"22\" y=\"20\" width=\"23\" height=\"16\" rx=\"4\" fill=\"#DCE4FF\"\/>\n        <text x=\"33.5\" y=\"31.5\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"middle\" letter-spacing=\"0.04em\">01<\/text>\n        <text x=\"52\" y=\"32\" font-size=\"11\" font-weight=\"700\" fill=\"#0B0F1C\">Run code in the browser<\/text>\n        <text x=\"22\" y=\"52\" font-size=\"9.5\" fill=\"#2A3347\">WebContent RCE<\/text>\n        <text x=\"204\" y=\"52\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"end\">5 parts<\/text>\n\n        <rect x=\"10\" y=\"80\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"22\" y=\"99\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">buffout<\/text>\n        <text x=\"22\" y=\"114\" font-size=\"9\" fill=\"#8896B3\">iOS 13 to 15.1.1<\/text>\n\n        <rect x=\"10\" y=\"132\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"22\" y=\"151\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">jacurutu<\/text>\n        <text x=\"22\" y=\"166\" font-size=\"9\" fill=\"#8896B3\">iOS 15.2 to 15.5<\/text>\n\n        <rect x=\"10\" y=\"184\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"22\" y=\"203\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">bluebird<\/text>\n        <text x=\"22\" y=\"218\" font-size=\"9\" fill=\"#8896B3\">iOS 15.6 to 16.1.2<\/text>\n\n        <rect x=\"10\" y=\"236\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"22\" y=\"255\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">terrorbird<\/text>\n        <text x=\"22\" y=\"270\" font-size=\"9\" fill=\"#8896B3\">iOS 16.2 to 16.5.1<\/text>\n\n        <rect x=\"10\" y=\"288\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F2FCF8\" stroke=\"#00C9B8\" stroke-width=\"1.8\"\/>\n        <text x=\"22\" y=\"307\" font-size=\"10.5\" font-weight=\"700\" fill=\"#0A6B57\">cassowary<\/text>\n        <text x=\"22\" y=\"322\" font-size=\"9\" fill=\"#20544A\">iOS 16.6 to 17.2.1<\/text>\n\n        <!-- ============ COLUMN 2: PAC bypass ============ -->\n        <rect x=\"226\" y=\"10\" width=\"204\" height=\"60\" rx=\"9\" fill=\"#EEF2FF\" stroke=\"#C9D4F5\"\/>\n        <rect x=\"238\" y=\"20\" width=\"23\" height=\"16\" rx=\"4\" fill=\"#DCE4FF\"\/>\n        <text x=\"249.5\" y=\"31.5\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"middle\" letter-spacing=\"0.04em\">02<\/text>\n        <text x=\"268\" y=\"32\" font-size=\"11\" font-weight=\"700\" fill=\"#0B0F1C\">Defeat pointer checks<\/text>\n        <text x=\"238\" y=\"52\" font-size=\"9.5\" fill=\"#2A3347\">PAC bypass<\/text>\n        <text x=\"420\" y=\"52\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"end\">5 parts<\/text>\n\n        <rect x=\"226\" y=\"80\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"238\" y=\"99\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">breezy<\/text>\n        <text x=\"238\" y=\"114\" font-size=\"9\" fill=\"#8896B3\">iOS 13 to 14.x<\/text>\n\n        <rect x=\"226\" y=\"132\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"238\" y=\"151\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">breezy15<\/text>\n        <text x=\"238\" y=\"166\" font-size=\"9\" fill=\"#8896B3\">iOS 15 to 16.2<\/text>\n\n        <rect x=\"226\" y=\"184\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"238\" y=\"203\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">seedbell<\/text>\n        <text x=\"238\" y=\"218\" font-size=\"9\" fill=\"#8896B3\">iOS 16.3 to 16.5.1<\/text>\n\n        <rect x=\"226\" y=\"236\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F2FCF8\" stroke=\"#00C9B8\" stroke-width=\"1.8\"\/>\n        <text x=\"238\" y=\"255\" font-size=\"10.5\" font-weight=\"700\" fill=\"#0A6B57\">seedbell_16_6<\/text>\n        <text x=\"238\" y=\"270\" font-size=\"9\" fill=\"#20544A\">iOS 16.6 to 16.7.12<\/text>\n\n        <rect x=\"226\" y=\"288\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"238\" y=\"307\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">seedbell_17<\/text>\n        <text x=\"238\" y=\"322\" font-size=\"9\" fill=\"#8896B3\">iOS 17 to 17.2.1<\/text>\n\n        <!-- ============ COLUMN 3: sandbox escape ============ -->\n        <rect x=\"442\" y=\"10\" width=\"204\" height=\"60\" rx=\"9\" fill=\"#EEF2FF\" stroke=\"#C9D4F5\"\/>\n        <rect x=\"454\" y=\"20\" width=\"23\" height=\"16\" rx=\"4\" fill=\"#DCE4FF\"\/>\n        <text x=\"465.5\" y=\"31.5\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"middle\" letter-spacing=\"0.04em\">03<\/text>\n        <text x=\"484\" y=\"32\" font-size=\"11\" font-weight=\"700\" fill=\"#0B0F1C\">Leave the browser<\/text>\n        <text x=\"454\" y=\"52\" font-size=\"9.5\" fill=\"#2A3347\">Sandbox escape<\/text>\n        <text x=\"636\" y=\"52\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"end\">2 parts<\/text>\n\n        <rect x=\"442\" y=\"80\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"454\" y=\"99\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">IronLoader<\/text>\n        <text x=\"454\" y=\"114\" font-size=\"9\" fill=\"#8896B3\">iOS 16.0 to 16.4, A12 and older<\/text>\n\n        <rect x=\"442\" y=\"132\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F2FCF8\" stroke=\"#00C9B8\" stroke-width=\"1.8\"\/>\n        <text x=\"454\" y=\"151\" font-size=\"10.5\" font-weight=\"700\" fill=\"#0A6B57\">NeuronLoader<\/text>\n        <text x=\"454\" y=\"166\" font-size=\"9\" fill=\"#20544A\">iOS 16.4 to 16.6.1, A13 to A16<\/text>\n\n        <rect x=\"442\" y=\"184\" width=\"204\" height=\"148\" rx=\"7\" fill=\"#FAFBFE\" stroke=\"#E8ECF5\" stroke-dasharray=\"4 4\"\/>\n        <text x=\"544\" y=\"248\" font-size=\"10\" fill=\"#8896B3\" text-anchor=\"middle\">Only two parts here.<\/text>\n        <text x=\"544\" y=\"264\" font-size=\"10\" fill=\"#8896B3\" text-anchor=\"middle\">This is the narrowest stage<\/text>\n        <text x=\"544\" y=\"280\" font-size=\"10\" fill=\"#8896B3\" text-anchor=\"middle\">in the whole kit.<\/text>\n\n        <!-- ============ COLUMN 4: privilege escalation ============ -->\n        <rect x=\"658\" y=\"10\" width=\"204\" height=\"60\" rx=\"9\" fill=\"#EEF2FF\" stroke=\"#C9D4F5\"\/>\n        <rect x=\"670\" y=\"20\" width=\"23\" height=\"16\" rx=\"4\" fill=\"#DCE4FF\"\/>\n        <text x=\"681.5\" y=\"31.5\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"middle\" letter-spacing=\"0.04em\">04<\/text>\n        <text x=\"700\" y=\"32\" font-size=\"11\" font-weight=\"700\" fill=\"#0B0F1C\">Reach kernel level<\/text>\n        <text x=\"670\" y=\"52\" font-size=\"9.5\" fill=\"#2A3347\">Privilege escalation<\/text>\n        <text x=\"852\" y=\"52\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"end\">6 parts<\/text>\n\n        <rect x=\"658\" y=\"80\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"670\" y=\"99\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Neutron<\/text>\n        <text x=\"670\" y=\"114\" font-size=\"9\" fill=\"#8896B3\">iOS 13.x<\/text>\n\n        <rect x=\"658\" y=\"132\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"670\" y=\"151\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Dynamo<\/text>\n        <text x=\"670\" y=\"166\" font-size=\"9\" fill=\"#8896B3\">iOS 13.x<\/text>\n\n        <rect x=\"658\" y=\"184\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"670\" y=\"203\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Pendulum<\/text>\n        <text x=\"670\" y=\"218\" font-size=\"9\" fill=\"#8896B3\">iOS 14 to 14.4.x<\/text>\n\n        <rect x=\"658\" y=\"236\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"670\" y=\"255\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Photon<\/text>\n        <text x=\"670\" y=\"270\" font-size=\"9\" fill=\"#8896B3\">iOS 14.5 to 15.7.6<\/text>\n\n        <rect x=\"658\" y=\"288\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"670\" y=\"307\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Parallax<\/text>\n        <text x=\"670\" y=\"322\" font-size=\"9\" fill=\"#8896B3\">iOS 16.4 to 16.7<\/text>\n\n        <rect x=\"658\" y=\"340\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F2FCF8\" stroke=\"#00C9B8\" stroke-width=\"1.8\"\/>\n        <text x=\"670\" y=\"359\" font-size=\"10.5\" font-weight=\"700\" fill=\"#0A6B57\">Gruber<\/text>\n        <text x=\"670\" y=\"374\" font-size=\"9\" fill=\"#20544A\">iOS 15.2 to 17.2.1<\/text>\n\n        <!-- ============ COLUMN 5: PPL bypass ============ -->\n        <rect x=\"874\" y=\"10\" width=\"204\" height=\"60\" rx=\"9\" fill=\"#EEF2FF\" stroke=\"#C9D4F5\"\/>\n        <rect x=\"886\" y=\"20\" width=\"23\" height=\"16\" rx=\"4\" fill=\"#DCE4FF\"\/>\n        <text x=\"897.5\" y=\"31.5\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"middle\" letter-spacing=\"0.04em\">05<\/text>\n        <text x=\"916\" y=\"32\" font-size=\"11\" font-weight=\"700\" fill=\"#0B0F1C\">Unlock protected memory<\/text>\n        <text x=\"886\" y=\"52\" font-size=\"9.5\" fill=\"#2A3347\">PPL bypass<\/text>\n        <text x=\"1068\" y=\"52\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" text-anchor=\"end\">5 parts<\/text>\n\n        <rect x=\"874\" y=\"80\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"886\" y=\"99\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Quark<\/text>\n        <text x=\"886\" y=\"114\" font-size=\"9\" fill=\"#8896B3\">iOS 13.x<\/text>\n\n        <rect x=\"874\" y=\"132\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"886\" y=\"151\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Gallium<\/text>\n        <text x=\"886\" y=\"166\" font-size=\"9\" fill=\"#8896B3\">iOS 14.x<\/text>\n\n        <rect x=\"874\" y=\"184\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F2FCF8\" stroke=\"#00C9B8\" stroke-width=\"1.8\"\/>\n        <text x=\"886\" y=\"203\" font-size=\"10.5\" font-weight=\"700\" fill=\"#0A6B57\">Carbone<\/text>\n        <text x=\"886\" y=\"218\" font-size=\"9\" fill=\"#20544A\">iOS 15.0 to 16.7.6<\/text>\n\n        <rect x=\"874\" y=\"236\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"886\" y=\"255\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Sparrow<\/text>\n        <text x=\"886\" y=\"270\" font-size=\"9\" fill=\"#8896B3\">iOS 17.0 to 17.3<\/text>\n\n        <rect x=\"874\" y=\"288\" width=\"204\" height=\"44\" rx=\"7\" fill=\"#F7F9FF\" stroke=\"#DDE3EE\"\/>\n        <text x=\"886\" y=\"307\" font-size=\"10.5\" font-weight=\"700\" fill=\"#5B6A8A\">Rocket<\/text>\n        <text x=\"886\" y=\"322\" font-size=\"9\" fill=\"#8896B3\">iOS 17.1 to 17.4<\/text>\n\n        <!-- ============ ASSEMBLED CHAIN RIBBON ============ -->\n        <rect x=\"10\" y=\"404\" width=\"1068\" height=\"54\" rx=\"10\" fill=\"#F2FCF8\" stroke=\"#BFE9DC\" stroke-width=\"1.4\"\/>\n        <text x=\"26\" y=\"426\" font-size=\"11\" font-weight=\"700\" fill=\"#0A6B57\">One assembled chain, for a device fingerprinted as iOS 16.6<\/text>\n        <text x=\"26\" y=\"445\" font-size=\"10\" fill=\"#20544A\">cassowary  &#8594;  seedbell_16_6  &#8594;  NeuronLoader  &#8594;  Gruber  &#8594;  Carbone<\/text>\n        <text x=\"1062\" y=\"445\" font-size=\"10\" fill=\"#5B9E8C\" text-anchor=\"end\">A different version number pulls a different set of five.<\/text>\n\n      <\/g>\n    <\/svg>\n  <\/div>\n\n  <div class=\"az-foot\">\n    <span class=\"az-leg\"><span class=\"az-bar\" style=\"background:#3B5BDB\"><\/span>Stage of the chain<\/span>\n    <span class=\"az-leg\"><span class=\"az-bar\" style=\"background:#8896B3\"><\/span>Parts covering other iOS versions<\/span>\n    <span class=\"az-leg\"><span class=\"az-bar\" style=\"background:#00C9B8\"><\/span>Parts selected for iOS 16.6<\/span>\n    <span class=\"az-src\">Composition and version ranges per Google Threat Intelligence Group, March 2026<\/span>\n  <\/div>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Several of the vulnerabilities are named and public. <a href=\"https:\/\/thehackernews.com\/2026\/03\/coruna-ios-exploit-kit-uses-23-exploits.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Hacker News lists the CVE mapping in full<\/a>, including CVE-2024-23222, a WebKit type confusion bug that had been exploited as a zero-day before Apple patched it in iOS 17.3 on January 22, 2024. Others go back further, to CVE-2021-30952 and a pair of 2020 kernel issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The final payloads are packed in a format built specifically for this kit. Each one is encrypted under its own key, compressed, wrapped in a custom container, and tagged with metadata stating which chips and iOS builds it supports. One detail matters for anyone watching traffic: these files arrive from addresses ending in .min.js, exactly like the ordinary scripts every site loads, so nothing about the request looks out of place.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"how-the-kit-decides-who-gets-exploited\">How the Kit Decides Who Gets Exploited<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Coruna does not fire at everyone who loads the page. First, it runs a JavaScript fingerprinting module and answers three questions: is this a real device, which iPhone model is it, and which iOS version is running.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Only after that, the framework loads the exploit pair that matches, and there are three reasons for such a flow:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reason 1: Plain engineering<\/strong>. Every exploit is written for a narrow band of iOS builds. If a chain fires blindly the wrong one, nothing happens, or Safari crashes. Besides ruining the overall flow, it makes the attack easier to detect, as a victim will notice and might report the browser crash.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reason 2: The hardware matters, too.<\/strong> The two sandbox escapes are split by hardware generation, one for A12 and older, one for A13 through A16, and every packed payload carries a note saying which chips it runs on. Reading the model wrong wastes the visit as surely as reading the version wrong does.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reason 3: Self-preservation.<\/strong> The kit fails when the device is in Lockdown Mode or when the session is in private browsing, because such a visitor is more likely to be a researcher, a sandbox, or a scanner. Delivering a working chain to any of them might cost the whole campaign, because the chain gets taken apart and patched.<\/li>\n<\/ul>\n\n\n<div class=\"block__preview\">\n        <a href=\"https:\/\/adex.com\/blog\/triada-malvertising-case-study\/\" class=\"block__preview_img\"><img src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2025\/12\/adex-investigarion-triada-infected-campaigns.png\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2025\/12\/adex-investigarion-triada-infected-campaigns.png\" sizes=\"100vw\" alt=\"adex-investigation-triada-infected-campaigns\" decoding=\"async\" class=\"lazy\"><\/a>\n    <div class=\"block__preview_box\">\n        <a href=\"https:\/\/adex.com\/blog\/category\/current_risks\/\" class=\"block__preview_box-cat\">Current risks<\/a>        <h3 class=\"block__preview_box-title\" id=\"inside-the-triada-battle-a-five-year-investigation-and-the-security-upgrades-it-triggered\"><a href=\"https:\/\/adex.com\/blog\/triada-malvertising-case-study\/\">Inside the Triada Battle: A Five-Year Investigation and the Security Upgrades It Triggered<\/a><\/h3>\n    <\/div>\n<\/div>\n<style>\n.block__preview {display: flex;align-items: center;justify-content: center; margin: 32px 0;}\n.block__preview a {text-decoration: none;}\n.block__preview_img {min-width: 360px;max-width: 360px;min-height: 188px;width: 100%;height: 100%;}\n.block__preview_img img {width: 100%;height: 100%;}\n.block__preview_box {margin-left: 40px;max-width: 360px;}\n.block__preview_box-cat {color: #00B8A7 !important;font-weight: 600;font-size: 12px;line-height: 16px;text-transform: uppercase; display: block; margin-bottom: 4px;}\n.block__preview_box-cat:hover {color: #FE645A !important; text-decoration: none !important;}\n.block__preview_box-title {font-size: 20px;font-weight: 700;line-height: 24px;color: #0B172D;}\n.block__preview_box-title a {color: #0B172D !important;}\n.block__preview_box-title a:hover {color: #FE645A !important;}\n@media screen and (max-width: 768px) {.block__preview {flex-direction: column;}.block__preview_box {max-width: 100%; margin-top: 32px;margin-left: 0px;}.block__preview_img {max-width: 100%;min-width: 100%;min-height: 100%;}}<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"from-a-few-targets-to-anyone-who-lands\">From a Few Targets to Anyone Who Lands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GTIG first captured a Coruna chain in February 2025, in a narrowly targeted attack on a handful of devices. By that summer, the same framework turned up on compromised websites, used by a group GTIG tracks as UNC6353 against a limited set of targets. By December 2025 the kit was in the hands of UNC6691, a financially motivated group, and the targeting discipline was gone. <a href=\"https:\/\/www.securityweek.com\/nation-state-ios-exploit-kit-coruna-found-powering-global-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">SecurityWeek&#8217;s write-up describes the shift plainly<\/a>: fake exchange sites, hidden iframes, exploit delivery to any iOS visitor regardless of location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The end payload matched the new motive. GTIG describes an implant that injects into a root-level system daemon, targets 18 wallet and financial applications, decodes QR codes found in images, and searches Apple Memos for recovery seed phrases. A tool built for a few selected devices had become a theft pipeline with a wide funnel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Quick fact: Coruna did not appear from nowhere. Two of its exploits target the same vulnerabilities used as zero-days in Operation Triangulation, the 2023 campaign <a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/kaspersky-discloses-iphone-hardware-feature-vital-in-operation-triangulation-case\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Kaspersky uncovered while monitoring its own corporate Wi-Fi network<\/a> and which relied on an undocumented hardware feature in Apple chips. Three weeks later, Kaspersky<a href=\"https:\/\/securelist.com\/coruna-framework-updated-operation-triangulation-exploit\/119228\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> compared the code itself<\/a> and concluded that Coruna&#8217;s kernel exploit for those two bugs is an updated build of the Triangulation one, and that the kit is an updated version of the same framework.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Set against the dates the vulnerabilities were open, the handover sequence below is the part that generalizes past this one kit.<\/p>\n\n\n\n<!-- =========================================================\n     ADEX-STYLE VISUAL: \"From a Few Targets to Anyone Who Lands\"\n     Simple four-step lifecycle. For the Coruna article.\n\n     WORDPRESS: paste this whole block into a \"Custom HTML\" block.\n     All CSS is scoped under .adexvz-10 so it cannot touch the theme.\n     ========================================================= -->\n\n<div class=\"adexvz-10\">\n<style>\n.adexvz-10{\n  --az-ink:#0B0F1C; --az-body:#2A3347; --az-faint:#8896B3;\n  --az-line:#DDE3EE; --az-bg:#F7F9FC;\n  --az-teal:#00C9B8; --az-blue:#3B5BDB; --az-red:#E03355;\n  all:initial;\n  display:block !important;\n  font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Arial,sans-serif !important;\n  color:var(--az-body) !important;\n  background:var(--az-bg) !important;\n  border:1px solid var(--az-line) !important;\n  border-radius:12px !important;\n  padding:22px 20px 16px !important;\n  margin:32px 0 !important;\n  -webkit-font-smoothing:antialiased;\n}\n.adexvz-10 *,.adexvz-10 *::before,.adexvz-10 *::after{box-sizing:border-box !important;}\n\n.adexvz-10 .az-head{display:flex !important;align-items:center !important;gap:10px !important;margin:0 0 16px !important;}\n.adexvz-10 .az-logo{width:22px !important;height:26px !important;flex:0 0 auto !important;display:block !important;}\n.adexvz-10 .az-title{margin:0 !important;padding:0 !important;border:0 !important;font-size:15px !important;\n  line-height:1.3 !important;font-weight:700 !important;color:var(--az-ink) !important;letter-spacing:-0.01em !important;font-family:inherit !important;}\n.adexvz-10 .az-sub{margin:2px 0 0 !important;font-size:11.5px !important;line-height:1.4 !important;color:var(--az-faint) !important;}\n\n.adexvz-10 .az-scroll{overflow-x:auto !important;-webkit-overflow-scrolling:touch !important;\n  border:1px solid var(--az-line) !important;border-radius:10px !important;background:#fff !important;padding:14px 12px 10px !important;}\n.adexvz-10 .az-svg{display:block !important;width:100% !important;min-width:860px !important;height:auto !important;}\n\n.adexvz-10 .az-foot{margin:12px 2px 0 !important;padding:10px 0 0 !important;border-top:1px solid var(--az-line) !important;\n  font-size:10px !important;color:#C5CDD9 !important;letter-spacing:0.05em !important;}\n.adexvz-10 .az-hint{display:none !important;}\n\n@media (max-width:680px){\n  .adexvz-10{padding:16px 12px 12px !important;}\n  .adexvz-10 .az-hint{display:block !important;margin:0 0 8px !important;font-size:11px !important;color:var(--az-faint) !important;}\n}\n<\/style>\n\n  <div class=\"az-head\">\n    <svg class=\"az-logo\" viewBox=\"0 0 34 40\" fill=\"none\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M5.31 32.14L17.23 39l11.92-6.87L17.23 20 5.31 32.14ZM4.57 28.5l10.36-10.84-2.77-2.84L4.57 28.5ZM19.55 17.62l10.33 10.88-5.91-10.47 2.47-2.51 7.15 14.04.85-.5V9.19l-4.23-2.45L19.55 17.62ZM15.93 0L0 9.19V29.06l.85.5 10.44-19.48 5.96 6.15 3.32-3.47L17.23 5.48l-1.65 3.01-2.62-2.69L15.93 0ZM18.53 0l4.64 9.08 3.97-4.12L18.53 0Z\" fill=\"#00C9B8\"\/>\n    <\/svg>\n    <div>\n      <p class=\"az-title\">From a Few Chosen Targets to Anyone Who Lands<\/p>\n      <p class=\"az-sub\">Ten months, three sets of hands. This is the usual path an expensive attack tool takes.<\/p>\n    <\/div>\n  <\/div>\n\n  <p class=\"az-hint\">Scroll sideways to see all four steps.<\/p>\n\n  <div class=\"az-scroll\">\n    <svg class=\"az-svg\" viewBox=\"0 0 1070 196\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"\n         aria-labelledby=\"azd10t azd10d\" focusable=\"false\">\n      <title id=\"azd10t\">How the Coruna exploit kit moved from narrowly targeted use to mass theft<\/title>\n      <desc id=\"azd10d\">Four steps on one line. February 2025, Google Threat Intelligence Group captures one chain from a narrowly targeted attack on a handful of devices. Summer 2025, a group tracked as UNC6353 plants it on compromised websites, still aimed at chosen targets. December 2025, a financially motivated group puts it on fake exchange sites and hits any iOS visitor with no geographic filter. March 2026, GTIG publishes the analysis on the third and Apple backports fixes to legacy devices on the eleventh. A bar underneath shows the shift from selective use to indiscriminate use.<\/desc>\n\n      <g font-family=\"'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Arial,sans-serif\">\n\n        <text x=\"10\" y=\"18\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" letter-spacing=\"0.1em\">FEB 2025<\/text>\n        <text x=\"10\" y=\"40\" font-size=\"12\" font-weight=\"700\" fill=\"#0B0F1C\">Narrowly targeted use<\/text>\n        <text x=\"10\" y=\"60\" font-size=\"10\" fill=\"#2A3347\">GTIG captures one chain from an attack<\/text>\n        <text x=\"10\" y=\"75\" font-size=\"10\" fill=\"#2A3347\">on a handful of devices.<\/text>\n\n        <text x=\"275\" y=\"18\" font-size=\"9.5\" font-weight=\"700\" fill=\"#3B5BDB\" letter-spacing=\"0.1em\">SUMMER 2025<\/text>\n        <text x=\"275\" y=\"40\" font-size=\"12\" font-weight=\"700\" fill=\"#0B0F1C\">Watering hole attack<\/text>\n        <text x=\"275\" y=\"60\" font-size=\"10\" fill=\"#2A3347\">UNC6353 plants it on compromised sites,<\/text>\n        <text x=\"275\" y=\"75\" font-size=\"10\" fill=\"#2A3347\">still aimed at chosen targets.<\/text>\n\n        <text x=\"540\" y=\"18\" font-size=\"9.5\" font-weight=\"700\" fill=\"#9B0E2F\" letter-spacing=\"0.1em\">DEC 2025<\/text>\n        <text x=\"540\" y=\"40\" font-size=\"12\" font-weight=\"700\" fill=\"#9B0E2F\">Fake exchange sites<\/text>\n        <text x=\"540\" y=\"60\" font-size=\"10\" fill=\"#7A1530\">UNC6691, a group after money, hits any<\/text>\n        <text x=\"540\" y=\"75\" font-size=\"10\" fill=\"#7A1530\">iOS visitor, with no geo filter.<\/text>\n\n        <text x=\"805\" y=\"18\" font-size=\"9.5\" font-weight=\"700\" fill=\"#0A6B57\" letter-spacing=\"0.1em\">MARCH 2026<\/text>\n        <text x=\"805\" y=\"40\" font-size=\"12\" font-weight=\"700\" fill=\"#0A6B57\">Public, then patched<\/text>\n        <text x=\"805\" y=\"60\" font-size=\"10\" fill=\"#20544A\">GTIG publishes on the 3rd. Apple patches<\/text>\n        <text x=\"805\" y=\"75\" font-size=\"10\" fill=\"#20544A\">legacy devices on the 11th.<\/text>\n\n        <line x1=\"16\" y1=\"104\" x2=\"1054\" y2=\"104\" stroke=\"#DDE3EE\" stroke-width=\"1.5\"\/>\n        <circle cx=\"16\" cy=\"104\" r=\"5\" fill=\"#3B5BDB\"\/>\n        <circle cx=\"281\" cy=\"104\" r=\"5\" fill=\"#3B5BDB\"\/>\n        <circle cx=\"546\" cy=\"104\" r=\"6.5\" fill=\"#E03355\"\/>\n        <circle cx=\"811\" cy=\"104\" r=\"5\" fill=\"#00C9B8\"\/>\n\n        <rect x=\"16\" y=\"126\" width=\"530\" height=\"10\" rx=\"5\" fill=\"#EEF2FF\"\/>\n        <rect x=\"546\" y=\"126\" width=\"508\" height=\"10\" rx=\"5\" fill=\"#FFF4F6\"\/>\n        <line x1=\"546\" y1=\"112\" x2=\"546\" y2=\"150\" stroke=\"#E8A9B8\" stroke-width=\"1.4\" stroke-dasharray=\"4 3\"\/>\n\n        <text x=\"16\" y=\"158\" font-size=\"10.5\" font-weight=\"700\" fill=\"#3B5BDB\">Chosen targets, small numbers<\/text>\n        <text x=\"1054\" y=\"158\" font-size=\"10.5\" font-weight=\"700\" fill=\"#9B0E2F\" text-anchor=\"end\">Whoever opens the page<\/text>\n\n        <text x=\"16\" y=\"184\" font-size=\"10\" fill=\"#8896B3\">The bugs behind all of this shipped between 2019 and 2023, so the window was open long before the first campaign.<\/text>\n\n      <\/g>\n    <\/svg>\n  <\/div>\n\n  <div class=\"az-foot\">SEQUENCE PER GOOGLE THREAT INTELLIGENCE GROUP AND APPLE SECURITY RELEASES, MARCH 2026<\/div>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-apple-patched-and-what-it-left-exposed\">What Apple Patched, and What It Left Exposed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Most of the bugs the kit relied on were fixed in 2020 \u2013 2024, on the normal update track. A phone on a current version of iOS was never in range of the chains in the report \u2013 the kit doesn\u2019t work on versions higher than 17.2.1.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then, on March 11, 2026, Apple did something less routine. It shipped<a href=\"https:\/\/support.apple.com\/en-us\/126632\"> iOS and iPadOS 15.8.7 for hardware that cannot run anything newer<\/a>, backporting three of the fixes \u2014 CVE-2023-41974 in the kernel, CVE-2024-23222 and CVE-2023-43000 in WebKit \u2014 to iOS 15.8.7, with a fourth, CVE-2023-43010, shipped the same day in iOS 16.7.15 for a newer set of devices. The device list reads like an archaeology report: iPhone 6s, iPhone 7, the first iPhone SE, iPad Air 2, iPad mini 4, and the seventh-generation iPod touch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, a patch only helps a phone that actually installs it, but many never do. If someone has been on iOS 16.2 for three years, nothing has changed for them. Besides, Apple sent four fixes across two legacy branches not the whole set, and, finally, a phone that was already broken into stays broken into.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-same-signals-different-jobs-why-coruna-case-matters-for-advertisers\">The Same Signals, Different Jobs: Why Coruna Case Matters for Advertisers&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Coruna did not invent this. Reading a visitor&#8217;s device to work out who they are is an old technique called fingerprinting, and serving different content depending on the answer is what advertising calls <a href=\"https:\/\/adex.com\/blog\/ad-cloaking\/\">cloaking<\/a>. Both are long-standing practices, and the second one is what ADEX deals with in campaign traffic every day.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p><strong>Note: Fingerprinting on its own is neutral. Anti-fraud systems and ordinary analytics run the same checks, so finding them on a page proves nothing. What matters is what the page does with the answer, and a cloaked page shows two visitors two different pages.<\/strong><\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-the-adex-team-saw-on-the-advertising-side\">What the ADEX Team Saw on the Advertising Side<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Around 50 accounts were identified as the source of campaigns with the same pattern, and the findings were passed to the client for review and action on those accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The advertisers behind them usually traced back to Asian origin, and the campaigns were not limited to one region: affected GEOs included Europe, India, and other markets. Here are a few of the landing pages behind these campaigns. They have no theme in common, which is exactly why they read as unrelated advertisers at first glance:<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-3.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"392\" height=\"850\" data-id=\"6087\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-3.png\" alt=\"landing page from a fraud ad campaign\" class=\"wp-image-6087\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-3.png 392w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-3-138x300.png 138w\" sizes=\"(max-width: 392px) 100vw, 392px\" \/><\/a><figcaption class=\"wp-element-caption\">domain: bctcert[.]com<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-4.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"406\" height=\"887\" data-id=\"6088\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-4.png\" alt=\"landing page from a fraud ad campaign\" class=\"wp-image-6088\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-4.png 406w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-4-137x300.png 137w\" sizes=\"(max-width: 406px) 100vw, 406px\" \/><\/a><figcaption class=\"wp-element-caption\">domain: go[.]exploregrid[.]best\/<\/figcaption><\/figure>\n\n\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-1.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"306\" height=\"833\" data-id=\"6090\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-1.png\" alt=\"landing page from a fraud ad campaign\" class=\"wp-image-6090\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-1.png 306w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-1-110x300.png 110w\" sizes=\"(max-width: 306px) 100vw, 306px\" \/><\/a><figcaption class=\"wp-element-caption\">domain: watchats[.]saje[.]top<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-2.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"280\" height=\"481\" data-id=\"6089\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-2.png\" alt=\"landing page from a fraud ad campaign\" class=\"wp-image-6089\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-2.png 280w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-langing-example-2-175x300.png 175w\" sizes=\"(max-width: 280px) 100vw, 280px\" \/><\/a><figcaption class=\"wp-element-caption\">domain: oc2[.]live<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is what researchers recorded on page load:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The landing page loads with a hidden iframe. Nothing on the visible page gives it away.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"911\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1.png\" alt=\"The landing page loads with a hidden iframe. Nothing on the visible page gives it away.\" class=\"wp-image-6092\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1-300x133.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1-1024x456.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1-768x342.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-1-1536x683.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The iframe checks the device. In this case, the check was a simple one: the OS version.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"960\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2.png\" alt=\"The iframe checks the device. In this case, the check was a simple one: the OS version.\n\" class=\"wp-image-6093\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2-300x141.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2-1024x480.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2-768x360.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-2-1536x720.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A delivery orchestrator loads next. It filters out bots and crawlers, then picks the malicious script written for that specific version of iOS.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"962\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3.png\" alt=\"A delivery orchestrator loads next. It filters out bots and crawlers, then picks the malicious script written for that specific version of iOS.\" class=\"wp-image-6094\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3-300x141.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3-1024x481.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3-768x361.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-3-1536x722.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">4. The device&#8217;s IP is checked and passed on, and the script matching that iOS version is delivered.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"918\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4.png\" alt=\"The device's IP is checked and passed on, and the script matching that iOS version is delivered.\" class=\"wp-image-6095\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4-300x134.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4-1024x459.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4-768x344.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-4-1536x689.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"916\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5.png\" alt=\"The device's IP is checked and passed on, and the script matching that iOS version is delivered.\" class=\"wp-image-6096\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5-300x134.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5-1024x458.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5-768x344.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-flow-5-1536x687.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The two JavaScript files from that chain, the orchestrator itself and the script it delivers, are both public on VirusTotal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The delivery orchestrator as seen on VirusTotal. This is the script that decides who gets what: it filters out crawlers and picks the build matching the visitor&#8217;s iOS version:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"613\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator.png\" alt=\"Coruna delivery orchestrator\" class=\"wp-image-6097\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator-300x90.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator-1024x307.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator-768x230.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-delivery-orchestrator-1536x460.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The script that is actually delivered once the orchestrator decides the visitor qualifies:<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img decoding=\"async\" width=\"2048\" height=\"564\" src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script.png\" alt=\"Coruna script\" class=\"wp-image-6099\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script.png 2048w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script-300x83.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script-1024x282.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script-768x212.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-script-1536x423.png 1536w\" sizes=\"(max-width: 2048px) 100vw, 2048px\" \/><\/a><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">What stands out is that the advertisers did not try to hide the violation behind a single landing page or a single category: the landing pages in these campaigns looked nothing alike. For example, one page could copy a Social offer, the next was a serious-looking finance page, while the formats and verticals kept changing, too.&nbsp;<\/p>\n\n\n<div class=\"block__preview\">\n        <a href=\"https:\/\/adex.com\/blog\/abuse-of-trusted-domains-in-igaming\/\" class=\"block__preview_img\"><img src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/02\/Adex-Subdomain-Takeover-Case-Study.png\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/02\/Adex-Subdomain-Takeover-Case-Study.png\" sizes=\"100vw\" alt=\"Adex-Subdomain-Takeover-Case-Study\" decoding=\"async\" class=\"lazy\"><\/a>\n    <div class=\"block__preview_box\">\n        <a href=\"https:\/\/adex.com\/blog\/category\/guides\/\" class=\"block__preview_box-cat\">Guides<\/a>        <h3 class=\"block__preview_box-title\" id=\"adex-detects-abuse-of-trusted-domains-in-igaming-advertising-campaigns\"><a href=\"https:\/\/adex.com\/blog\/abuse-of-trusted-domains-in-igaming\/\">Adex Detects Abuse of Trusted Domains in iGaming Advertising Campaigns<\/a><\/h3>\n    <\/div>\n<\/div>\n<style>\n.block__preview {display: flex;align-items: center;justify-content: center; margin: 32px 0;}\n.block__preview a {text-decoration: none;}\n.block__preview_img {min-width: 360px;max-width: 360px;min-height: 188px;width: 100%;height: 100%;}\n.block__preview_img img {width: 100%;height: 100%;}\n.block__preview_box {margin-left: 40px;max-width: 360px;}\n.block__preview_box-cat {color: #00B8A7 !important;font-weight: 600;font-size: 12px;line-height: 16px;text-transform: uppercase; display: block; margin-bottom: 4px;}\n.block__preview_box-cat:hover {color: #FE645A !important; text-decoration: none !important;}\n.block__preview_box-title {font-size: 20px;font-weight: 700;line-height: 24px;color: #0B172D;}\n.block__preview_box-title a {color: #0B172D !important;}\n.block__preview_box-title a:hover {color: #FE645A !important;}\n@media screen and (max-width: 768px) {.block__preview {flex-direction: column;}.block__preview_box {max-width: 100%; margin-top: 32px;margin-left: 0px;}.block__preview_img {max-width: 100%;min-width: 100%;min-height: 100%;}}<\/style>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, these campaigns appear in review as several unrelated advertisers, but in most cases they belong to a single operator. The reason is a difference in cost: the cloaking setup, the redirect chain, and the hidden scripts take weeks to build, while a landing page can be produced in a day. Therefore, the setup is reused, with a new theme placed on top each time, and a page that never looks the same twice gives moderation no pattern to learn.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p><strong>The more useful outcome came afterwards: the analysis of these campaigns gave us a set of metrics that flags the same pattern during moderation, before a campaign goes live and reaches any traffic.<\/strong><\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-this-changes-for-traffic-quality-teams\">What This Changes for Traffic Quality Teams<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Nothing here demands a new detection product, but it argues for a few adjustments in how existing checks are run:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Scan more than once, and from more than one profile.<\/strong> A single visit from a consistent crawler profile is exactly the input the filtering layer is built to recognize. Varying fingerprints and revisiting after approval is what catches the switch.<\/li>\n\n\n\n<li><strong>Treat a clean result from an unusual client as low-confidence.<\/strong> If your scanner runs from a data-center range with a hardened configuration, a clean result is weak evidence. Record it as inconclusive rather than passed.<\/li>\n\n\n\n<li><strong>Cluster by delivery, not by creative.<\/strong> Redirect chain shape, iframe behavior, script hashes, and hosting patterns survive a creative refresh, but vertical labels do not.<\/li>\n\n\n\n<li><a href=\"https:\/\/adex.com\/promoderation\"><strong>Watch for iframe injection on approved destinations<\/strong><\/a><strong>.<\/strong> The Coruna campaigns did not need the landing page to look malicious. A hidden iframe on an otherwise ordinary page carried the whole delivery.<\/li>\n\n\n\n<li><strong>Keep legacy device traffic in view.<\/strong> Old iOS builds in your traffic matter beyond monetization. That segment stays exploitable longest after a disclosure, as the March backport to devices released between 2014 and 2019 shows.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"faq\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"is-the-coruna-exploit-kit-still-a-threat-on-current-iphones\">Is the Coruna exploit kit still a threat on current iPhones?&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Not through the documented chains. The chains cover iOS 13.0 through 17.2.1, and the underlying vulnerabilities were patched on the mainline update track in 2023 and 2024. The remaining exposure sits with devices that never received those updates, which is why Apple backported four of the fixes to iOS 15.8.7 in March 2026.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"how-was-coruna-delivered-to-victims\">How was Coruna delivered to victims?&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Through web pages, with no user interaction beyond opening the page. GTIG describes hidden iframes on compromised sites and on attacker-built fake exchange sites, loading a JavaScript framework that fingerprinted the visitor before any exploit was sent.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"why-does-an-exploit-kit-care-whether-a-device-is-in-lockdown-mode\">Why does an exploit kit care whether a device is in Lockdown Mode?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Because a hardened or unusual device is more likely to belong to a researcher, a sandbox, or a scanner, and delivering a working chain to one of those means losing it. Bailing out preserves the exploit. The same reasoning explains the private browsing check.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-does-an-ios-exploit-kit-have-to-do-with-ad-fraud\">What does an iOS exploit kit have to do with ad fraud?&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The visitor-classification layer is shared. Deciding which visitor is real and which is an automated reviewer is the same problem cloaked campaigns solve, using the same signals. The techniques transfer across use cases even when the operators do not.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"can-a-buyer-or-a-publisher-detect-this-in-their-own-traffic\">Can a buyer or a publisher detect this in their own traffic?&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Partially, by delivery behavior: unexpected iframes on approved destinations, redirect chains that change after approval, and pages that respond differently to two visitors with different device profiles. Confirming what an exploit chain actually did on an end-user device is not something a buyer or publisher can do from campaign data.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"wrapping-up\">Wrapping Up<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The strongest argument in the Coruna disclosure reaches well past iOS. A filtering layer built to protect an exploit and a filtering layer built to hide a scam landing page are the same piece of engineering, reused by operators with different goals, and that layer is where both are easiest to catch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the first question for a review process is whether the malicious page ever shows itself at all, and recognizing it comes second. If your scanner presents one profile, visits once, and reports clean, you have learned what the delivery layer wanted you to learn. Change the profile, come back later, and compare what two different visitors were shown. The difference between those two responses is the finding.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 3, 2026, Google Threat Intelligence Group published its analysis of Coruna, an iOS exploit kit. This kit was a full framework with five complete exploit chains and 23 individual exploits, covering every iOS version from 13.0 to 17.2.1. The delivery was zero-click: a user opened a web page in Safari, and the attack [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":6110,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6],"tags":[16],"class_list":["post-6085","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-reports","tag-threat"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics - ADEX<\/title>\n<meta name=\"description\" content=\"Inside the Coruna iOS exploit kit: 23 exploits, zero-click delivery, and a visitor check that works like ad cloaking. Plus what Adex found in campaign traffic.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics - ADEX\" \/>\n<meta property=\"og:description\" content=\"Inside the Coruna iOS exploit kit: 23 exploits, zero-click delivery, and a visitor check that works like ad cloaking. Plus what Adex found in campaign traffic.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/\" \/>\n<meta property=\"og:site_name\" content=\"ADEX\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/adexsaas\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T15:04:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-21T07:22:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-exploit-kit.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Mikheeva\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@adexsaas\" \/>\n<meta name=\"twitter:site\" content=\"@adexsaas\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Mikheeva\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/\"},\"author\":{\"name\":\"Olya Mikheeva\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/person\\\/c5794aef7aa28987e7019a804390ee3a\"},\"headline\":\"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics\",\"datePublished\":\"2026-08-20T15:04:39+00:00\",\"dateModified\":\"2026-08-21T07:22:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/\"},\"wordCount\":2582,\"publisher\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/adex-coruna-exploit-kit.png\",\"keywords\":[\"Threat\"],\"articleSection\":[\"Reports\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/\",\"name\":\"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics - ADEX\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/adex-coruna-exploit-kit.png\",\"datePublished\":\"2026-08-20T15:04:39+00:00\",\"dateModified\":\"2026-08-21T07:22:11+00:00\",\"description\":\"Inside the Coruna iOS exploit kit: 23 exploits, zero-click delivery, and a visitor check that works like ad cloaking. Plus what Adex found in campaign traffic.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/adex-coruna-exploit-kit.png\",\"contentUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/adex-coruna-exploit-kit.png\",\"width\":1200,\"height\":628,\"caption\":\"Coruna fingerprinted every visitor before sending an exploit. How that filter worked, what Apple patched, and why Adex sees the same logic in ad campaigns.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/coruna-ios-exploit-kit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/adex.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/\",\"name\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\"},\"alternateName\":\"ADEX\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/adex.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\",\"name\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/CDD2258_copy-48-1.svg\",\"contentUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/CDD2258_copy-48-1.svg\",\"width\":148,\"height\":30,\"caption\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/adexsaas\\\/\",\"https:\\\/\\\/x.com\\\/adexsaas\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/person\\\/c5794aef7aa28987e7019a804390ee3a\",\"name\":\"Olya Mikheeva\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g\",\"caption\":\"Olya Mikheeva\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics - ADEX","description":"Inside the Coruna iOS exploit kit: 23 exploits, zero-click delivery, and a visitor check that works like ad cloaking. Plus what Adex found in campaign traffic.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/","og_locale":"en_US","og_type":"article","og_title":"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics - ADEX","og_description":"Inside the Coruna iOS exploit kit: 23 exploits, zero-click delivery, and a visitor check that works like ad cloaking. Plus what Adex found in campaign traffic.","og_url":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/","og_site_name":"ADEX","article_publisher":"https:\/\/www.facebook.com\/adexsaas\/","article_published_time":"2026-08-20T15:04:39+00:00","article_modified_time":"2026-08-21T07:22:11+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-exploit-kit.png","type":"image\/png"}],"author":"Olya Mikheeva","twitter_card":"summary_large_image","twitter_creator":"@adexsaas","twitter_site":"@adexsaas","twitter_misc":{"Written by":"Olya Mikheeva","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#article","isPartOf":{"@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/"},"author":{"name":"Olya Mikheeva","@id":"https:\/\/adex.com\/blog\/#\/schema\/person\/c5794aef7aa28987e7019a804390ee3a"},"headline":"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics","datePublished":"2026-08-20T15:04:39+00:00","dateModified":"2026-08-21T07:22:11+00:00","mainEntityOfPage":{"@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/"},"wordCount":2582,"publisher":{"@id":"https:\/\/adex.com\/blog\/#organization"},"image":{"@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-exploit-kit.png","keywords":["Threat"],"articleSection":["Reports"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/","url":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/","name":"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics - ADEX","isPartOf":{"@id":"https:\/\/adex.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#primaryimage"},"image":{"@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-exploit-kit.png","datePublished":"2026-08-20T15:04:39+00:00","dateModified":"2026-08-21T07:22:11+00:00","description":"Inside the Coruna iOS exploit kit: 23 exploits, zero-click delivery, and a visitor check that works like ad cloaking. Plus what Adex found in campaign traffic.","breadcrumb":{"@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#primaryimage","url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-exploit-kit.png","contentUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/08\/adex-coruna-exploit-kit.png","width":1200,"height":628,"caption":"Coruna fingerprinted every visitor before sending an exploit. How that filter worked, what Apple patched, and why Adex sees the same logic in ad campaigns."},{"@type":"BreadcrumbList","@id":"https:\/\/adex.com\/blog\/coruna-ios-exploit-kit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/adex.com\/blog\/"},{"@type":"ListItem","position":2,"name":"The Coruna iOS Exploit Kit: How Zero-Click Attacks Mirror Ad Fraud Tactics"}]},{"@type":"WebSite","@id":"https:\/\/adex.com\/blog\/#website","url":"https:\/\/adex.com\/blog\/","name":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform","description":"","publisher":{"@id":"https:\/\/adex.com\/blog\/#organization"},"alternateName":"ADEX","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/adex.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/adex.com\/blog\/#organization","name":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform","url":"https:\/\/adex.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/adex.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/05\/CDD2258_copy-48-1.svg","contentUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/05\/CDD2258_copy-48-1.svg","width":148,"height":30,"caption":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform"},"image":{"@id":"https:\/\/adex.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/adexsaas\/","https:\/\/x.com\/adexsaas"]},{"@type":"Person","@id":"https:\/\/adex.com\/blog\/#\/schema\/person\/c5794aef7aa28987e7019a804390ee3a","name":"Olya Mikheeva","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g","caption":"Olya Mikheeva"}}]}},"_links":{"self":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/6085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/comments?post=6085"}],"version-history":[{"count":32,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/6085\/revisions"}],"predecessor-version":[{"id":6146,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/6085\/revisions\/6146"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/media\/6110"}],"wp:attachment":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/media?parent=6085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/categories?post=6085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/tags?post=6085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}