HackRead

New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims


Varonis Threat Labs has documented a new Windows infostealer and remote access trojan (RAT) called Dolphin X. The malware targets hundreds of applications and includes an “AI Profiler” designed to rank infected users, helping cybercriminals decide which victims deserve further attention.

Researchers found Dolphin X advertised on a cybercrime forum by a vendor using the alias “Kontraktnik.” The seller promotes it as an all-in-one service that combines DDoS botnet, credential theft, remote computer control, and surveillance functions through a single operator panel.

AI Profiler Sorts Victims by Value

Once Dolphin X collects information from an infected computer, its profiler examines application use, browsing activity, and installed software. Operators then receive a daily summary containing risk scores and rankings for compromised machines.

For criminals managing thousands of infections, those rankings reduce the time spent reviewing stolen data manually. A computer used for cryptocurrency trading, software development or corporate administration could receive greater attention because it may contain wallets, cloud credentials or access to company systems.

According to the seller’s listing, Dolphin X can target more than 300 applications. A single stolen archive may contain information from nine browsers, more than 100 cryptocurrency wallet extensions, 65 desktop wallets, 10 password managers and 30 cloud command-line tools, according to the Varonis report.

The collected material can include browser passwords, cryptocurrency wallet data, SSH keys, cloud tokens and .env files. Developers commonly store database passwords, API keys and service credentials in .env files, so one infected work computer could expose access far beyond the individual user’s accounts.

Malware author Kontraktnik pitching their infostealer to potential buyers – Image credit: Varonis

Malware Seller Offers Custom Builds

Dolphin X operators configure the malware through a desktop panel, selecting its server address, installation location, persistence settings, and evasion options. The configuration is submitted to the seller’s server, which builds the Windows executable and returns it to the customer.

Additionally, there are paid mutation options that can alter each generated file by changing instructions, encrypted strings, import information, and file metadata. These changes are intended to make new builds harder to block using file hashes or detection rules based on fixed byte patterns.

The advertised feature set also includes process injection, scheduled-task persistence, antivirus evasion, remote command execution, and hidden remote desktop sessions. In practical terms, Dolphin X is sold as both a data thief and a tool for maintaining control of an infected PC.

Varonis noted an important limitation in its findings. Researchers analyzed the operator panel and its network traffic, not the malware running on a victim’s computer. Unless otherwise stated, many capabilities were visible in the builder or described by the seller but were not independently confirmed during execution.

Anyone who suspects an infostealer infection should disconnect the computer from the network, scan or rebuild it, and change passwords from a separate clean device. Browser sessions, cloud tokens, and SSH keys should be revoked, while exposed cryptocurrency wallets should be replaced with new wallets created on a trusted device.





Source link