Dolphin X: New Windows Stealer Uses AI to Rank Which Victims Are Worth Robbing
- Threat discovered: Varonis Threat Labs researcher Daniel Kelley uncovered Dolphin X, a Windows stealer and RAT sold by a vendor using the alias "Kontraktnik."
- Massive scope: The malware targets more than 300 applications, including browsers, crypto wallets, SSH keys, .env files, and cloud tokens.
- AI profiling: An "AI Profiler" scores infected users to help attackers prioritize high-value victims.
A new Windows stealer and remote access trojan (RAT) advertised on a cybercrime forum by a vendor operating under the alias "Kontraktnik" is marketed as multi-purpose. The user advertises it as usable as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, and as a loader.
Varonis Threat Labs has uncovered the Dolphin X malware, which reaches far beyond browser passwords to harvest credentials across an enterprise attack surface.
Dolphin X Targets 300+ Applications
The listing claims Dolphin X is an all-in-one RAT that can target more than 300 applications, with collection capabilities spanning cryptocurrency wallets, .env files, SSH keys, cloud tokens, and other DevOps credentials. A single archive can contain data pulled from:
- nine browsers,
- more than 100 wallet extensions,
- 65 desktop wallets,
- 10 password managers,
- 30 cloud command-line tools.
On a developer's machine, over-scoped, long-lived credentials in .env files and SSH directories can expose cloud consoles, build pipelines, and production data in one pass.
AI Profiler Ranks High-Value Victims
Dolphin X includes an "AI Profiler" that scores infected users based on application usage, browsing activity, and installed software. Attackers receive the rankings in a daily summary, letting them filter thousands of infected machines and focus on the most valuable targets first.
Server-Side Mutation and 329 Features
The operator panel lists 329 features across ten categories. Rather than compiling locally, the client submits build configurations to backend.thedolphinx[.]top:8443, while the operator sets the agent's C2 address, installation path, persistence, and evasion options. Routing every build through the vendor's server allows modifying each binary before it returns.
"It's probably one of the biggest stealers I've ever seen, and covers the biggest attack surface," senior threat researcher Daniel Kelley told The Register. He said the AI Profiler feature is something he's "never seen before" in an infostealer of this kind.
Kelley said the builder "had everything to suggest the features were legitimate" and that it "probably lives up to most of its expectations."
Last week, a fake NVIDIA software was reported distributing the novel LabubaRAT malware to hijack Windows PCs.









