An AI gateway designed to steal your data
2026-03-26T20:51:59Z•bf167257cd10d4bcceae696e788eaf6721fd162e78f842708c22eb0a1a310195
AI-gatewayAndroid-trojanArkanixBeatBankerCVE-2023-32434CVE-2023-38606CorunaGoPixHorabot','Mexico','SOC','vulnerabilities-report','Q4-2025','mobKeenaduKimwolfLiteLLMMaaSMamontOperation-TriangulationPACTriadabanking-trojandata-theftexploit-kitiOS-kernel-exploitinfostealermalvertisingmemory-onlysupply-chain
What happened
Kaspersky Securelist summaries covering multiple active threats and research: a supply‑chain backdoor in the LiteLLM AI gateway capable of data theft; the Coruna exploit kit (updated Operation Triangulation) using updated iPhone kernel exploits (CVE-2023-32434, CVE-2023-38606); banking Trojans and complex Android/iOS threats including GoPix (memory‑only implants, PAC-based MITM, malvertising), BeatBanker (dual‑mode Android banker/miner), and Keenadu (firmware/system backdoor) plus other mobile/IoT threats (Triada, Kimwolf, Mamont); an Arkanix C++/Python infostealer offered as MaaS; a Horabot A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- bf167257cd10d4bcceae696e788eaf6721fd162e78f842708c22eb0a1a310195
- Enrichment time
- 2026-03-26T20:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.