Dolphin X Malware Uses AI To Rank Victims By Value

Security researchers have identified a new Windows-based malware strain called Dolphin X that combines the credential-stealing capabilities of a traditional infostealer with an artificial-intelligence-driven feature designed to help criminals decide which infected computers are worth attacking first.

Varonis Threat Labs researcher Daniel Kelley discovered the malware being advertised on a cybercrime forum by a seller operating under the alias "Kontraktnik," who markets Dolphin X as an all-in-one remote access trojan (RAT).

Dolphin X Malware Uses AI To Rank Victims By Value

Unlike malware that simply harvests as much data as possible and leaves attackers to sort through it manually, Dolphin X reportedly automates that triage process. Researchers emphasize that they examined the malware's operator panel, builder, and associated network traffic in a controlled lab environment rather than a live agent running on an infected machine, so several of the vendor's claims have not been independently verified through execution.

According to Varonis, the Dolphin X operator panel advertises 329 features spread across ten categories. The most significant of these, from a defender's perspective, is the credential-looter category, which claims to target more than 300 applications.

The malware's advertised collection scope includes:

  • Nine Chromium- and Gecko-based web browsers, along with saved login data
  • More than 100 cryptocurrency wallet browser extensions and 65 desktop wallet applications
  • Ten password managers and more than 30 cloud command-line interface (CLI) tools

Beyond these categories, Dolphin X also claims the ability to pull SSH keys, .env configuration files, and cloud access tokens from infected systems. On a developer's machine in particular, these files often contain long-lived, overly privileged credentials that can grant access to cloud consoles, build pipelines, and production environments.

All the stolen material is reportedly staged into a single archive before exfiltration, giving attackers a consolidated package that could expose everything from a victim's personal accounts to their employer's cloud infrastructure.

What sets Dolphin X apart from many earlier infostealers is a feature tucked inside its surveillance tab called the "AI Profiler." The seller describes it as an AI behavioral profiler that tracks application usage, assigns a risk score, and delivers a daily summary of infected machines.

In practice, researchers believe the tool functions as an automated sorting mechanism, ranking victims so that attackers can prioritize the machines most likely to yield valuable access, such as corporate networks, cloud environments, cryptocurrency holdings, or production systems.

Varonis researcher Daniel Kelley compared the feature to a warehouse sorter that automatically scores and tags each victim, then returns a ranked list of infections that deserve immediate attention. The operator panel claims the AI Profiler processes several data points to build these rankings, including browser domains visited, installed software, and behavioral risk tags collected from the victim's system.

Kelley confirmed that technical strings supporting this profiling workflow are present within the panel itself, including references such as Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage. These strings indicate that the underlying profiling mechanism exists within the tool and is not merely a marketing claim.

However, Varonis was unable to determine which artificial intelligence engine or model powers the scoring system, as researchers lacked access to a live malware sample actively profiling a victim.

How the Malware Is Built and Delivered

Dolphin X's operator panel functions as a configuration wizard rather than a traditional local builder. Operators select settings such as the command-and-control (C2) address, installation path, persistence mechanism, and evasion options, and the panel then submits this configuration to a remote backend server for compilation. Because every build passes through the vendor's infrastructure, the seller can apply modifications to each binary before delivering it back to the customer.

This remote-build process also enables an optional mutation engine, which the panel presents in three tiers. Two of the more advanced tiers are restricted to buyers on a "PRO" plan.

Researchers outline the tiers as follows:

  • The top tier claims to rewrite control flow, substitute instructions, and re-encrypt embedded strings with a new key each time, making it harder for defenders to identify stable byte patterns across samples.
  • The middle tier shuffles the import table, altering the binary's import hash between builds.
  • The lowest tier rewrites PE timestamps, the Rich header, and section padding — the same byte regions that many YARA rules and hash-based blocklists rely on for detection.

The mutation engine is off by default, meaning that builds generated without it enabled will share the same file hash. This detail matters for defenders, since it suggests that baseline detection through static hashes may still catch unmodified builds, while paying customers who activate the mutation features could evade signature-based tools more easily.

Dolphin X is not the first piece of cybercrime software to fold artificial intelligence into its feature set. Researchers point to earlier tools such as SpamGPT and other AI-assisted platforms as evidence that threat actors are increasingly experimenting with automation to make large-scale attacks more efficient.

Rather than using AI to generate phishing lures or write malicious code, Dolphin X applies the technology to a purely operational problem: filtering a flood of stolen data down to a manageable list of the most promising targets.

Varonis notes that this shift mirrors a broader pattern in which criminal groups controlling thousands of compromised machines simply cannot review every infection by hand. Automated scoring systems like the AI Profiler reduce that workload, allowing a small team of operators to focus their efforts on victims most likely to yield a worthwhile payout.

Because Dolphin X and similar stealers are designed to sweep up any credentials or tokens they can find, security researchers recommend limiting the amount of sensitive material stored locally in the first place.

Practical defensive steps include:

  • Avoid storing long-lived credentials, API keys, or cloud tokens directly on disk, particularly inside project directories, .env files, or local password stores, since infostealers are built to collect everything in a single pass.
  • Monitor for behavioral indicators rather than relying solely on file signatures. For example, a browser process running under a non-default desktop session can indicate hidden virtual network computing (HVNC) activity, regardless of how the malware binary itself is packed or hashed.

Users should also remain cautious of unsolicited downloads, cracked software, and suspicious email attachments, as infostealers of this type are commonly distributed through such channels rather than through sophisticated exploits.

Keeping operating systems and security software up to date, avoiding storing sensitive credentials in browsers where possible, and using dedicated password managers with strong master passwords can further reduce the risk of falling victim to Dolphin X or similar malware families.

As always, computer users who suspect an infection should disconnect the affected machine from the internet and run a full scan with a reputable anti-malware tool as soon as possible.

Share:

facebook
X (Twitter)
linkedin
copy link
Karolis Liucveikis

Karolis Liucveikis

Experienced software engineer, passionate about behavioral analysis of malicious apps

Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate