An AI gateway designed to steal your data
2026-03-27T20:51:58Z•afa3136b8026919d2fcb5c02beb9e238f4ff97726db15d376cad171d1b0f66de
Android TrojanArkanix StealerBeatBankerCVE-2023-32434CVE-2023-38606CorunaGoPixHorabotKeenaduLiteLLMMaaSManaged Detection and ResponseOperation TriangulationPACQ4 2025data‑stealeriOSincident responsekernel exploitmalvertisingmemory-onlymobile malwaresupply-chainvulnerabilities
What happened
Kaspersky Securelist roundup covering multiple high‑risk findings: a supply‑chain attack in LiteLLM that embeds data‑stealing code in an AI gateway; Coruna exploit kit (an updated Operation Triangulation) using iOS kernel exploits CVE‑2023‑32434 and CVE‑2023‑38606; a broad set of mobile and banking threats including GoPix (memory‑only implants, PAC‑based MITM, malvertising), BeatBanker (dual‑mode Android miner and banker), and Keenadu (firmware/backdoor linking major Android botnets); an Arkanix C++/Python infostealer offered as MaaS; a Horabot campaign in Mexico; and Q4/2025 vulnerability/exп
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- afa3136b8026919d2fcb5c02beb9e238f4ff97726db15d376cad171d1b0f66de
- Enrichment time
- 2026-03-27T20:51:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.