Coruna: the framework used in Operation Triangulation

2026-03-26T08:51:53Zefd440a565cee892b82dd50646c0e323a7e3768cc6d5a2af32562b869ae1447a
CVE-2023-32434CVE-2023-38606acr-stealer','vulnerabilities-report','q4-2025','mobile-malwareandroidarkanix-stealerbanking-trojanbeatbankercorunaexploit-kitfirmware-backdoorgopixhijackloaderhorabotioskeenadukernel-exploitlummamaasmalvertisingmemory-onlyoperation-triangulationpacproxy-auto-configrenenginestealer

What happened

Kaspersky Securelist (Mar 2026) collection describing multiple active threats and research: an updated Coruna exploit framework used in Operation Triangulation that includes updated iPhone kernel exploits for CVE-2023-32434 and CVE-2023-38606; a Horabot campaign in Mexico; GoPix, a complex Brazilian banking Trojan employing memory-only implants, PAC files for MITM and malvertising; BeatBanker, a dual‑mode Android trojan (miner + banker); Keenadu Android backdoor targeting firmware and system apps; Arkanix stealer (C++/Python, MaaS); RenEngine/HijackLoader chains distributing Lumma and ACR stea

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
efd440a565cee892b82dd50646c0e323a7e3768cc6d5a2af32562b869ae1447a
Enrichment time
2026-03-26T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Coruna: the framework used in Operation Triangulation · Baitaphish