ADEX, a traffic validation ecosystem based in Limassol, uncovered this shift after tracking campaigns across Europe and India. The core mechanism mirrors the Coruna exploit identified in March 2026, which vetted iPhone models and iOS versions to serve payloads only to targeted devices. In the current ad fraud landscape, this logic allows malicious entities to present benign landing pages to automated scanners while redirecting genuine users to prohibited destinations.
While the visual presentation of these ads constantly shifts—masquerading as everything from social media promotions to financial services—the underlying delivery infrastructure remains static. ADEX analysts identified consistent patterns in redirect chains, script execution, and hosting behaviors among approximately 50 active accounts linked to Asian-based advertisers. These findings suggest that relying on visual content for fraud detection is no longer sufficient.

Comments (0)
No comments yet. Be the first!