Dolphin X: New Windows Stealer Uses AI to Rank Which Victims Are Worth Robbing

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Threat discovered: Varonis Threat Labs researcher Daniel Kelley uncovered Dolphin X, a Windows stealer and RAT sold by a vendor using the alias "Kontraktnik."
  • Massive scope: The malware targets more than 300 applications, including browsers, crypto wallets, SSH keys, .env files, and cloud tokens.
  • AI profiling: An "AI Profiler" scores infected users to help attackers prioritize high-value victims.

A new Windows stealer and remote access trojan (RAT) advertised on a cybercrime forum by a vendor operating under the alias "Kontraktnik" is marketed as multi-purpose. The user advertises it as usable as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, and as a loader.

Varonis Threat Labs has uncovered the Dolphin X malware, which reaches far beyond browser passwords to harvest credentials across an enterprise attack surface.

Dolphin X Targets 300+ Applications

The listing claims Dolphin X is an all-in-one RAT that can target more than 300 applications, with collection capabilities spanning cryptocurrency wallets, .env files, SSH keys, cloud tokens, and other DevOps credentials. A single archive can contain data pulled from:

Forum post advertising Dolphin X as an all-in-one RAT | Source: Varonis
Forum post advertising Dolphin X as an all-in-one RAT | Source: Varonis

On a developer's machine, over-scoped, long-lived credentials in .env files and SSH directories can expose cloud consoles, build pipelines, and production data in one pass.  

Feature panel, with the 300+ collection targets under the credential looter category | Source: Varonis
Feature panel, with the 300+ collection targets under the credential looter category | Source: Varonis

AI Profiler Ranks High-Value Victims

Dolphin X includes an "AI Profiler" that scores infected users based on application usage, browsing activity, and installed software. Attackers receive the rankings in a daily summary, letting them filter thousands of infected machines and focus on the most valuable targets first. 

Server-Side Mutation and 329 Features

The operator panel lists 329 features across ten categories. Rather than compiling locally, the client submits build configurations to backend.thedolphinx[.]top:8443, while the operator sets the agent's C2 address, installation path, persistence, and evasion options. Routing every build through the vendor's server allows modifying each binary before it returns. 

"It's probably one of the biggest stealers I've ever seen, and covers the biggest attack surface," senior threat researcher Daniel Kelley told The Register. He said the AI Profiler feature is something he's "never seen before" in an infostealer of this kind.

Kelley said the builder "had everything to suggest the features were legitimate" and that it "probably lives up to most of its expectations."

Last week, a fake NVIDIA software was reported distributing the novel LabubaRAT malware to hijack Windows PCs.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: