Coruna: the framework used in Operation Triangulation
2026-03-26T08:51:53Z•efd440a565cee892b82dd50646c0e323a7e3768cc6d5a2af32562b869ae1447a
CVE-2023-32434CVE-2023-38606acr-stealer','vulnerabilities-report','q4-2025','mobile-malwareandroidarkanix-stealerbanking-trojanbeatbankercorunaexploit-kitfirmware-backdoorgopixhijackloaderhorabotioskeenadukernel-exploitlummamaasmalvertisingmemory-onlyoperation-triangulationpacproxy-auto-configrenenginestealer
What happened
Kaspersky Securelist (Mar 2026) collection describing multiple active threats and research: an updated Coruna exploit framework used in Operation Triangulation that includes updated iPhone kernel exploits for CVE-2023-32434 and CVE-2023-38606; a Horabot campaign in Mexico; GoPix, a complex Brazilian banking Trojan employing memory-only implants, PAC files for MITM and malvertising; BeatBanker, a dual‑mode Android trojan (miner + banker); Keenadu Android backdoor targeting firmware and system apps; Arkanix stealer (C++/Python, MaaS); RenEngine/HijackLoader chains distributing Lumma and ACR stea
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- efd440a565cee892b82dd50646c0e323a7e3768cc6d5a2af32562b869ae1447a
- Enrichment time
- 2026-03-26T08:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.