How to remove Dolphin X RAT trojan from the operating system
TrojanAlso Known As: Dolphin X remote access trojan
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of malware is Dolphin X RAT?
Dolphin X RAT is a multi-purpose Windows malware sold as a subscription service to cybercriminals. It combines a Remote Access Trojan (RAT), information stealer, cryptocurrency clipper, and distributed denial-of-service (DDoS) tool in a single package.
Research published by Varonis Threat Labs documents Dolphin X targeting over 300 applications across ten categories, with an operator panel containing 329 features. A cybercriminal using the alias "Kontraktnik" sells access to the platform on underground forums at 69.95 euros per month.
What sets Dolphin X apart from many similar tools is a built-in AI behavioral profiler. It analyzes data from each infected machine and assigns a risk score, letting operators rank victims and focus on the highest-value targets first. BleepingComputer has also reported on this AI ranking capability.

Dolphin X RAT overview
Dolphin X operates as a Malware-as-a-Service (MaaS) platform. Operators purchase a subscription, access an online control panel, and receive malware builds compiled server-side at the vendor's backend infrastructure. This remote compilation model means each build is assembled at the vendor's servers rather than on the operator's own machine.
Varonis Threat Labs researcher Daniel Kelley examined the operator panel, builder, and network traffic. The analysis identified strings confirming an active AI profiling workflow, including references to risk scoring and profiler data retrieval.
All data stolen from an infected machine is staged into a single archive before exfiltration. The malware is designed to run silently, leaving few visible indicators on the compromised system.
Data theft capabilities
Dolphin X's stealer module targets nine Chromium and Gecko-based browsers, pulling saved passwords, cookies, autofill entries, and bookmarks. It also reaches 100 cryptocurrency wallet browser extensions and 65 desktop wallet applications, including Exodus and MetaMask.
WiFi passwords stored on the system are harvested, and the Windows Credential Manager is dumped for any saved credentials. A sensitive file hunter scans the machine for documents and files that may interest the operator.
Developer and cloud credentials are a specific focus. The stealer collects SSH keys, .env files, cloud access tokens, and data from over 30 cloud command-line tools. Ten password manager applications are also in scope.
Session data from Discord, Telegram, Steam, and Minecraft is captured, along with credentials from sysadmin tools including FileZilla, WinSCP, and PuTTY.
Remote control, surveillance, and clipping
The remote control module gives operators live access to the infected machine. A remote desktop feature allows viewing and interacting with the victim's screen in real time. A reverse shell enables direct command execution, and a built-in file manager and network scanner complete the core toolkit.
An HVNC (Hidden Virtual Network Computing) module creates a parallel desktop session invisible to the victim. Operators can work within this hidden session without triggering any visible indication of activity on the victim's screen.
A SOCKS5 reverse-proxy capability routes operator traffic through the infected machine. The cryptocurrency clipper watches the Windows clipboard and silently swaps any copied wallet address with one the attacker controls, redirecting cryptocurrency payments without the victim noticing.
Persistence, defense evasion, and offensive capabilities
Dolphin X achieves persistence through Windows Registry Run key entries, the Windows startup folder, scheduled tasks, and Windows service installation. A UEFI bootkit module is also listed among its persistence options, capable of surviving even a full operating system reinstall.
Defense evasion is a core strength. The malware patches AMSI and ETW - two Windows interfaces used by security software - and uses direct system calls to sidestep user-mode API hooks. It can also bypass User Account Control (UAC) using eight different methods.
A three-tier mutation engine makes each build appear unique. The first tier rewrites control flow and re-encrypts embedded strings. The second shuffles import tables. The third modifies PE timestamps, Rich headers, and section padding.
Additional capabilities include manipulating Windows Defender, editing the firewall and Hosts file, applying anti-forensics techniques, and spreading to connected USB drives. The DDoS module supports over 20 attack methods, and botnet-style proxying and control are available as well.
System manipulation features allow the malware to block Windows updates, restrict Task Manager and Registry Editor access, inject code via DLL injection and shellcode injection, and trigger a Blue Screen of Death on demand.
AI-powered victim profiling
The AI behavioral profiler is one of Dolphin X RAT's most distinctive features. It automatically analyzes data from each infected machine - including installed applications, browsing activity, and software usage patterns - and generates a risk score and daily summary for each victim.
These scores allow operators to rank infected machines and focus first on the most valuable ones. According to Varonis, the profiler helps attackers identify machines likely to provide access to corporate networks, cloud environments, cryptocurrency holdings, or financial accounts.
The specific AI engine powering this feature has not been confirmed without live sample execution. That said, strings found during the Varonis analysis - including references to risk scoring and profiler startup routines - indicate the component is fully functional.
| Name | Dolphin X remote access trojan |
| Threat Type | RAT, Information Stealer, Clipper, Trojan |
| Symptoms | Remote Access Trojans are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine. |
| Distribution methods | Infected email attachments, malicious online advertisements, social engineering, software 'cracks', fake websites. |
| Damage | Stolen passwords and banking information, identity theft, cryptocurrency theft, the victim's computer added to a botnet, additional infections, monetary loss, account hijacking, remote control of the infected device. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Conclusion
Dolphin X RAT gives cybercriminals a comprehensive toolkit for stealing data, controlling infected machines remotely, and clipping cryptocurrency transfers. The AI-powered victim profiler adds a targeting layer not typically found in malware of this type, helping operators focus on the most valuable compromised systems.
Victims can face stolen passwords, hijacked accounts, lost cryptocurrency, and unauthorized remote access to their devices. The malware's deep persistence options - including a UEFI bootkit - make it particularly hard to remove without dedicated security tools. It should be eliminated from the system without delay.
More examples of malware classified as a RAT are MarkiRAT, Starland, and DenoRAT.
How did Dolphin X RAT infiltrate my computer?
Dolphin X RAT is sold as a subscription service to cybercriminals, each of whom deploys it through their own chosen channels. The developer, known as "Kontraktnik," handles backend infrastructure and compiles builds server-side, giving subscribers a ready-to-deploy tool requiring minimal technical skill.
Common distribution methods used by MaaS operators include phishing emails with malicious attachments or links, fake software download websites, pirated software and cracks, and malvertising.
Attackers may also rely on fake installer sites impersonating legitimate software. Common file types used in such campaigns include executable installers, archive packages, and malicious document attachments. Being wary of unexpected download links and unsolicited email attachments is one of the most reliable defenses.
How to avoid installation of malware?
Download software only from official developer websites and verified platform stores. Avoid cracks, key generators, and pirated content, as these are common delivery vehicles for malware. Be cautious with unexpected emails, particularly those containing attachments or links, even when the sender appears to be someone you know.
Keep your operating system and all applications updated, as attackers frequently exploit vulnerabilities in outdated software. Use a reputable security solution and run regular system scans. If you believe that your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Website promoting Dolphin X RAT:

Post on hacker forum promoting Dolphin X RAT:

Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quick menu:
- What is Dolphin X RAT?
- STEP 1. Manual removal of Dolphin X RAT malware.
- STEP 2. Check if your computer is clean.
How to remove malware manually?
Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows.
If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove. Here is an example of a suspicious program running on a user's computer:

If you checked the list of programs running on your computer, for example, using task manager, and identified a program that looks suspicious, you should continue with these steps:
Download a program called Autoruns. This program shows auto-start applications, Registry, and file system locations:

Restart your computer into Safe Mode:
Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, and then select Safe Mode with Networking from the list.

Video showing how to start Windows 7 in "Safe Mode with Networking":
Windows 8 users: Start Windows 8 is Safe Mode with Networking - Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click Advanced startup options, in the opened "General PC Settings" window, select Advanced startup.
Click the "Restart now" button. Your computer will now restart into the "Advanced Startup options menu". Click the "Troubleshoot" button, and then click the "Advanced options" button. In the advanced option screen, click "Startup settings".
Click the "Restart" button. Your PC will restart into the Startup Settings screen. Press F5 to boot in Safe Mode with Networking.

Video showing how to start Windows 8 in "Safe Mode with Networking":
Windows 10 users: Click the Windows logo and select the Power icon. In the opened menu click "Restart" while holding "Shift" button on your keyboard. In the "choose an option" window click on the "Troubleshoot", next select "Advanced options".
In the advanced options menu select "Startup Settings" and click on the "Restart" button. In the following window you should click the "F5" button on your keyboard. This will restart your operating system in safe mode with networking.

Video showing how to start Windows 10 in "Safe Mode with Networking":
Extract the downloaded archive and run the Autoruns.exe file.

In the Autoruns application, click "Options" at the top and uncheck "Hide Empty Locations" and "Hide Windows Entries" options. After this procedure, click the "Refresh" icon.

Check the list provided by the Autoruns application and locate the malware file that you want to eliminate.
You should write down its full path and name. Note that some malware hides process names under legitimate Windows process names. At this stage, it is very important to avoid removing system files. After you locate the suspicious program you wish to remove, right click your mouse over its name and choose "Delete".

After removing the malware through the Autoruns application (this ensures that the malware will not run automatically on the next system startup), you should search for the malware name on your computer. Be sure to enable hidden files and folders before proceeding. If you find the filename of the malware, be sure to remove it.

Reboot your computer in normal mode. Following these steps should remove any malware from your computer. Note that manual threat removal requires advanced computer skills. If you do not have these skills, leave malware removal to antivirus and anti-malware programs.
These steps might not work with advanced malware infections. As always it is best to prevent infection than try to remove malware later. To keep your computer safe, install the latest operating system updates and use antivirus software. To be sure your computer is free of malware infections, we recommend scanning it with Combo Cleaner Antivirus for Windows.
Frequently Asked Questions (FAQ)
My computer is infected with Dolphin X RAT malware, should I format my storage device to get rid of it?
Formatting will erase Dolphin X RAT along with all data on the drive. That is a last resort. Running a reputable security tool such as Combo Cleaner is the recommended first step and should remove the infection without destroying your files.
What are the biggest issues that Dolphin X RAT malware can cause?
Dolphin X RAT can steal passwords, session tokens, and cryptocurrency from hundreds of applications, allow attackers to remotely view and control the desktop, and add the machine to a DDoS botnet.
Victims may face identity theft, drained cryptocurrency wallets, unauthorized access to corporate or cloud accounts, and financial fraud - all without any visible sign that the machine is compromised.
What is the purpose of Dolphin X RAT malware?
The purpose of Dolphin X RAT is to give cybercriminals a comprehensive platform for stealing sensitive data, remotely controlling infected machines, and clipping cryptocurrency transactions. An AI profiler also ranks victims by value so operators can focus on the highest-priority targets.
How did Dolphin X RAT malware infiltrate my computer?
Dolphin X RAT is sold as a subscription service to cybercriminals who deploy it through their own channels. Common infection methods include phishing emails, fake software download sites, pirated software packages, and malvertising campaigns.
Will Combo Cleaner protect me from malware?
Yes. Combo Cleaner can detect and remove Dolphin X RAT and most other known malware. Because advanced threats can hide deeply in the system, running a full scan is the most reliable way to ensure the machine is completely clean.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion