[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2iXm9EvMzM-fsLF-K-YXyNzsxE31gKkjuS3YaFO6Er0":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"48cdbd88-4812-4b31-a590-6a051d331032","New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims","new-dolphin-x-malware-uses-ai-profiler-to-rank-high-value-victims-1aaae2","Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.","Varonis Threat Labs has identified Dolphin X, a new Windows infostealer and RAT advertised on cybercrime forums. The malware features an 'AI Profiler' that scores infected PCs based on application use and browsing activity, helping attackers prioritize high-value victims. It targets over 300 applications, collecting sensitive data like cryptocurrency wallet information, cloud credentials, and SSH keys.","New Dolphin X malware uses AI to rank Windows PCs for high-value targets.","Security MalwareNew Dolphin X Malware Uses AI Profiler to Rank High-Value Victims Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly. byWaqasJuly 24, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Varonis Threat Labs has documented a new Windows infostealer and remote access trojan (RAT) called Dolphin X. The malware targets hundreds of applications and includes an “AI Profiler” designed to rank infected users, helping cybercriminals decide which victims deserve further attention. Researchers found Dolphin X advertised on a cybercrime forum by a vendor using the alias “Kontraktnik.” The seller promotes it as an all-in-one service that combines DDoS botnet, credential theft, remote computer control, and surveillance functions through a single operator panel. AI Profiler Sorts Victims by Value Once Dolphin X collects information from an infected computer, its profiler examines application use, browsing activity, and installed software. Operators then receive a daily summary containing risk scores and rankings for compromised machines. For criminals managing thousands of infections, those rankings reduce the time spent reviewing stolen data manually. A computer used for cryptocurrency trading, software development or corporate administration could receive greater attention because it may contain wallets, cloud credentials or access to company systems. According to the seller’s listing, Dolphin X can target more than 300 applications. A single stolen archive may contain information from nine browsers, more than 100 cryptocurrency wallet extensions, 65 desktop wallets, 10 password managers and 30 cloud command-line tools, according to the Varonis report. The collected material can include browser passwords, cryptocurrency wallet data, SSH keys, cloud tokens and .env files. Developers commonly store database passwords, API keys and service credentials in .env files, so one infected work computer could expose access far beyond the individual user’s accounts. Malware author Kontraktnik pitching their infostealer to potential buyers – Image credit: Varonis Malware Seller Offers Custom Builds Dolphin X operators configure the malware through a desktop panel, selecting its server address, installation location, persistence settings, and evasion options. The configuration is submitted to the seller’s server, which builds the Windows executable and returns it to the customer. Additionally, there are paid mutation options that can alter each generated file by changing instructions, encrypted strings, import information, and file metadata. These changes are intended to make new builds harder to block using file hashes or detection rules based on fixed byte patterns. The advertised feature set also includes process injection, scheduled-task persistence, antivirus evasion, remote command execution, and hidden remote desktop sessions. In practical terms, Dolphin X is sold as both a data thief and a tool for maintaining control of an infected PC. Varonis noted an important limitation in its findings. Researchers analyzed the operator panel and its network traffic, not the malware running on a victim’s computer. Unless otherwise stated, many capabilities were visible in the builder or described by the seller but were not independently confirmed during execution. Anyone who suspects an infostealer infection should disconnect the computer from the network, scan or rebuild it, and change passwords from a separate clean device. Browser sessions, cloud tokens, and SSH keys should be revoked, while exposed cryptocurrency wallets should be replaced with new wallets created on a trusted device. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts BotnetCyber CrimeCybersecurityDDOSDolphin XInfostealerMalwareRATSpywareWindows Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Cyber Attacks Malware Black Basta Ransomware Uses MS Teams, Email Bombing to Spread Malware The Black Basta ransomware group is using advanced social engineering tactics and a multi-stage infection process to target organizations. byDeeba Ahmed Read More Cyber Crime Malware Gionee subsidiary implanted malware in over 20 million phones The Chinese smartphone maker reportedly made $4.2 million through manufacturing malware-infected phones. byDeeba Ahmed Read More Security Cyber Attacks Malware FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit Bitdefender Labs reveals how the China-linked FamousSparrow hacking group targeted an Azerbaijani energy firm using ProxyNotShell, Deed RAT,… byDeeba Ahmed Read More Security Upwind Security Brings AI Visibility to the Endpoint, Unifying Cloud and Device Security Upwind’s AI Sensor links endpoint activity with cloud context, helping teams track MCP connections, AI actions, identities and developer risk in one view today. byOwais Sultan","https:\u002F\u002Fhackread.com\u002Fdolphin-x-malware-ai-profiler-rank-victims\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002Fdolphin-x-malware-ai-profiler-rank-victims-2.jpg","2026-07-24T10:09:52+00:00","2026-07-24T12:00:20.692091+00:00",8,[18,21],{"name":19,"type":20},"Kontraktnik","threat_actor",{"name":22,"type":23},"AI","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":26,"name":27,"slug":28},null,"Malware","malware",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]