New Dolphin X Malware Uses AI to Rank High-Value Targets
New Dolphin X Malware Uses AI to Rank High-Value Targets 🚀
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias “Kontraktnik,” promoting it as an all-in-one remote access trojan.
According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications. However, one of its notable features is an AI Profiler that analyzes information collected from infected computers and assigns each victim a risk score.
Beyond credential collection, the panel includes a surveillance tab containing the AI Profiler. The seller describes it as an ‘AI behavioral profiler with app usage tracking, risk score, and daily summary,’ explains Varonis. Dolphin X’s AI Profiler claims to automate this process by acting as a sorting system that scores, categorizes, and ranks infected computers so that the attackers know which are the most high-value to target further.
The operator panel claims that the AI Profiler can process victims’ application usage, risk scores and tags, browser domains, and installed software to produce ranked profiles. These scores are given to attackers in daily summaries containing ranked victim profiles, allowing them to prioritize machines that may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems. As Kelley explains, “In practice, the feature appears designed to help operators triage victims.”
Varonis researcher Daniel Kelley confirmed to BleepingComputer that the AI Profiler is present in the operator panel and discovered technical strings supporting the profiling workflow, including Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage. The researcher added that these strings indicate the profiling workflow is actually included and that the panel can process the data needed to rank victims. However, Varonis could not determine what artificial intelligence engine is being used to produce the rankings without analyzing a live Dolphin X malware sample.
Additionally, the malware also operates as a credential stealer, with the operator panel showing that it targets more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools. Dolphin X also claims to steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials.
Varonis analyzed the Dolphin X operator panel, builder, and related network traffic rather than a live malware sample executing on an infected machine, so the malware’s advertised collection capabilities were not independently confirmed by the researcher. The Dolphin X platform instead uses AI to solve an operational problem by processing large amounts of stolen data and automatically sorting infected users into highest-value victims.