Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Google Account Recovery Gets Selfie Video Feature for Enhanced Security
July 23, 2026
High-Severity Brokering File System Flaw Exposes Windows 11, Server 2025
July 23, 2026
DolphinX Malware Steals Credentials From 300+ Apps, Profiles Victims With AI
July 23, 2026
Home/Threats/DolphinX Malware Steals Credentials From 300+ Apps, Profiles Victims With AI
Threats

DolphinX Malware Steals Credentials From 300+ Apps, Profiles Victims With AI

Key Takeaways Dolphin X is a newly discovered Windows malware functioning as both an information stealer and a remote access trojan (RAT). It targets over 300 applications, including browsers,...

David kimber
David kimber
July 23, 2026 5 Min Read
1 0

Key Takeaways

  • Dolphin X is a newly discovered Windows malware functioning as both an information stealer and a remote access trojan (RAT).
  • It targets over 300 applications, including browsers, cryptocurrency wallets, password managers, and developer tools.
  • A unique “AI Profiler” feature allows attackers to prioritize victims based on their perceived value, optimizing post-compromise activities.
  • The malware offers advanced evasion techniques and a remote build service, making detection challenging for traditional signature-based defenses.
  • Individuals and organizations face significant risks, especially from compromised developer workstations holding sensitive cloud and production credentials.

New Dolphin X Malware Emerges with AI-Powered Victim Profiling

A sophisticated new Windows malware, dubbed Dolphin X, has been identified, posing a substantial threat beyond typical credential theft. This versatile tool is being actively marketed within underground criminal forums as a combined information stealer and remote access trojan (RAT), offering attackers extensive control and visibility over compromised systems. Its capabilities extend far beyond basic browser password extraction, encompassing a wide array of sensitive data sources.

Table Of Content

  • Key Takeaways
  • New Dolphin X Malware Emerges with AI-Powered Victim Profiling
  • Extensive Credential Collection Capabilities
  • AI Profiling Elevates Attack Sophistication
  • What You Should Do

The malware’s broad targeting includes critical data such as browser logins, cryptocurrency wallets, popular password managers, cloud command-line interface (CLI) tools, SSH keys, and various files found in developer environments. This comprehensive data exfiltration capability presents a severe risk to both individuals and enterprises. A single infected device could potentially yield credentials for cloud services or even production systems, leading to widespread breaches.

Security researchers at Varonis said in a report that they uncovered Dolphin X while monitoring an advertisement posted by a seller operating under the alias “Kontraktnik” on an illicit forum. The researchers conducted their analysis within an isolated laboratory environment, examining the malware’s operator panel and its associated network traffic. A key distinguishing feature of Dolphin X is its integration of large-scale credential harvesting with an innovative AI-based victim profiling mechanism.

Instead of treating all infected machines equally, Dolphin X’s operators can leverage the collected activity data to discern which systems hold greater value. This allows them to focus their post-exploitation efforts on high-priority targets, maximizing their criminal gains.

Extensive Credential Collection Capabilities

Dolphin X boasts support for credential collection from over 300 applications. According to its advertised features, a single compromised system can yield an archive containing data from nine different browsers, more than 100 wallet extensions, 65 desktop cryptocurrency wallets, 10 password managers, and 30 cloud command-line tools. This extensive reach makes the malware a potent threat, capable of facilitating far more than simple account takeovers.

Attackers can acquire browser cookies, saved login credentials, cryptocurrency wallet information, and critical secrets often stored locally by developers, such as cloud tokens and SSH keys. This mirrors risks previously highlighted in reports concerning the compromise of browser credentials and crypto wallets. Developer workstations are particularly appealing targets, as their project folders frequently contain sensitive .env files, private keys, and long-lived credentials. If these secrets are exfiltrated, criminals could gain unauthorized access to cloud consoles, build pipelines, internal code repositories, or even critical production data.

Beyond data exfiltration, the Dolphin X operator panel advertises a suite of advanced features. These include process injection, mechanisms for registry and scheduled-task persistence, User Account Control (UAC) bypass methods, patching of Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) to evade detection, and SOCKS5 proxy support. These functionalities enable attackers to maintain covert presence, undermine local security defenses, and route malicious traffic through compromised machines, further complicating incident response.

The malware’s build process is conducted remotely, enhancing its stealth and adaptability. The operator panel transmits selected configuration settings—including the command-and-control (C2) address, installation path, persistence options, and evasion techniques—to a remote backend, which then compiles and returns the customized payload. This “malware-as-a-service” (MaaS) model, which packages credential theft for broader criminal use, is a growing trend in the cybercrime landscape.

Furthermore, the service offers “mutation settings” designed to alter each generated executable. These include control-flow obfuscation, instruction substitution, string re-encryption, modification of import tables, and altered file metadata. Such techniques aim to bypass traditional signature-based detection mechanisms that rely on static file hashes, making it harder for security solutions to identify and block the malware.

AI Profiling Elevates Attack Sophistication

A standout feature of Dolphin X is its “AI Profiler,” which monitors application usage, browsing history, and installed software on victim machines. This data is then used to assign a “risk score” to each victim. Operators receive a daily summary that ranks compromised systems, enabling them to strategically prioritize their efforts on individuals or organizations deemed most valuable or profitable.

While this AI feature does not grant the malware full autonomy, it significantly boosts the efficiency of criminal operations. A threat actor managing a large botnet of thousands of infected devices can leverage automated scoring to quickly identify high-value targets—such as developers, finance professionals, cryptocurrency holders, or system administrators—over less lucrative victims. This targeted approach maximizes the impact of each successful infection.

The increasing integration of AI into cybercrime tools is a trend that HackersRadar continues to monitor, as explored in previous coverage of artificial intelligence cyber attacks. In the case of Dolphin X, the AI component primarily serves for victim triage and prioritization, rather than for autonomous malware generation or direct intrusion execution.

What You Should Do

  • Minimize Local Storage of Sensitive Data: Reduce the amount of sensitive information stored directly on local machines, especially long-lived credentials within project directories or local credential stores.
  • Revoke and Replace Compromised Credentials: Immediately treat any credential found on an infected endpoint as compromised. Revoke these credentials where possible and promptly replace them across all affected services.
  • Implement Behavior-Based Monitoring: Prioritize security solutions that offer behavior-based monitoring over those relying solely on known file hashes, as Dolphin X employs mutation techniques to evade static detection. Varonis specifically highlighted that explorer.exe running under a non-default desktop environment can be a strong indicator of an HVNC session, regardless of the malware’s packing method.
  • Practice Strong Cyber Hygiene: Educate users to avoid downloading unknown files or clicking suspicious links.
  • Enforce Multi-Factor Authentication (MFA): Mandate MFA for all accounts, particularly for critical systems and cloud services, to add an essential layer of security against stolen credentials.
  • Limit Credential Permissions: Implement the principle of least privilege, ensuring that credentials only have the minimum necessary permissions required for their function.

Indicators of Compromise (IoCs):-

Type Indicator Description
Host and port backend.thedolphinx[.]top:8443 Licensing, telemetry, and remote-build service
Domain thedolphinx[.]top Parent domain for the vendor backend
SHA-256 726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0 Dolphin X operator panel client executable

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Ubuntu snap-confine Race Condition CVE-2023-46238 Lets Attackers Gain Root Privileges

Next Post

High-Severity Brokering File System Flaw Exposes Windows 11, Server 2025

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Kimi K3 AI Agent Discovers Zero-Day Exploits in Redis Server
July 23, 2026
TrickBot Malware Uses DNS for Covert Command and Control
July 23, 2026
Microsoft Defender for O365 Gains Prompt Injection Protection
July 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us