An AI gateway designed to steal your data

2026-03-27T20:51:58Zafa3136b8026919d2fcb5c02beb9e238f4ff97726db15d376cad171d1b0f66de
Android TrojanArkanix StealerBeatBankerCVE-2023-32434CVE-2023-38606CorunaGoPixHorabotKeenaduLiteLLMMaaSManaged Detection and ResponseOperation TriangulationPACQ4 2025data‑stealeriOSincident responsekernel exploitmalvertisingmemory-onlymobile malwaresupply-chainvulnerabilities

What happened

Kaspersky Securelist roundup covering multiple high‑risk findings: a supply‑chain attack in LiteLLM that embeds data‑stealing code in an AI gateway; Coruna exploit kit (an updated Operation Triangulation) using iOS kernel exploits CVE‑2023‑32434 and CVE‑2023‑38606; a broad set of mobile and banking threats including GoPix (memory‑only implants, PAC‑based MITM, malvertising), BeatBanker (dual‑mode Android miner and banker), and Keenadu (firmware/backdoor linking major Android botnets); an Arkanix C++/Python infostealer offered as MaaS; a Horabot campaign in Mexico; and Q4/2025 vulnerability/exп

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
afa3136b8026919d2fcb5c02beb9e238f4ff97726db15d376cad171d1b0f66de
Enrichment time
2026-03-27T20:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.