DolphinX Malware Steals Credentials From 300+ Apps, Profiles Victims With AI
Key Takeaways Dolphin X is a newly discovered Windows malware functioning as both an information stealer and a remote access trojan (RAT). It targets over 300 applications, including browsers,...
Key Takeaways
- Dolphin X is a newly discovered Windows malware functioning as both an information stealer and a remote access trojan (RAT).
- It targets over 300 applications, including browsers, cryptocurrency wallets, password managers, and developer tools.
- A unique “AI Profiler” feature allows attackers to prioritize victims based on their perceived value, optimizing post-compromise activities.
- The malware offers advanced evasion techniques and a remote build service, making detection challenging for traditional signature-based defenses.
- Individuals and organizations face significant risks, especially from compromised developer workstations holding sensitive cloud and production credentials.
New Dolphin X Malware Emerges with AI-Powered Victim Profiling
A sophisticated new Windows malware, dubbed Dolphin X, has been identified, posing a substantial threat beyond typical credential theft. This versatile tool is being actively marketed within underground criminal forums as a combined information stealer and remote access trojan (RAT), offering attackers extensive control and visibility over compromised systems. Its capabilities extend far beyond basic browser password extraction, encompassing a wide array of sensitive data sources.
Table Of Content
The malware’s broad targeting includes critical data such as browser logins, cryptocurrency wallets, popular password managers, cloud command-line interface (CLI) tools, SSH keys, and various files found in developer environments. This comprehensive data exfiltration capability presents a severe risk to both individuals and enterprises. A single infected device could potentially yield credentials for cloud services or even production systems, leading to widespread breaches.
Security researchers at Varonis said in a report that they uncovered Dolphin X while monitoring an advertisement posted by a seller operating under the alias “Kontraktnik” on an illicit forum. The researchers conducted their analysis within an isolated laboratory environment, examining the malware’s operator panel and its associated network traffic. A key distinguishing feature of Dolphin X is its integration of large-scale credential harvesting with an innovative AI-based victim profiling mechanism.
Instead of treating all infected machines equally, Dolphin X’s operators can leverage the collected activity data to discern which systems hold greater value. This allows them to focus their post-exploitation efforts on high-priority targets, maximizing their criminal gains.
Extensive Credential Collection Capabilities
Dolphin X boasts support for credential collection from over 300 applications. According to its advertised features, a single compromised system can yield an archive containing data from nine different browsers, more than 100 wallet extensions, 65 desktop cryptocurrency wallets, 10 password managers, and 30 cloud command-line tools. This extensive reach makes the malware a potent threat, capable of facilitating far more than simple account takeovers.
Attackers can acquire browser cookies, saved login credentials, cryptocurrency wallet information, and critical secrets often stored locally by developers, such as cloud tokens and SSH keys. This mirrors risks previously highlighted in reports concerning the compromise of browser credentials and crypto wallets. Developer workstations are particularly appealing targets, as their project folders frequently contain sensitive .env files, private keys, and long-lived credentials. If these secrets are exfiltrated, criminals could gain unauthorized access to cloud consoles, build pipelines, internal code repositories, or even critical production data.
Beyond data exfiltration, the Dolphin X operator panel advertises a suite of advanced features. These include process injection, mechanisms for registry and scheduled-task persistence, User Account Control (UAC) bypass methods, patching of Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) to evade detection, and SOCKS5 proxy support. These functionalities enable attackers to maintain covert presence, undermine local security defenses, and route malicious traffic through compromised machines, further complicating incident response.
The malware’s build process is conducted remotely, enhancing its stealth and adaptability. The operator panel transmits selected configuration settings—including the command-and-control (C2) address, installation path, persistence options, and evasion techniques—to a remote backend, which then compiles and returns the customized payload. This “malware-as-a-service” (MaaS) model, which packages credential theft for broader criminal use, is a growing trend in the cybercrime landscape.
Furthermore, the service offers “mutation settings” designed to alter each generated executable. These include control-flow obfuscation, instruction substitution, string re-encryption, modification of import tables, and altered file metadata. Such techniques aim to bypass traditional signature-based detection mechanisms that rely on static file hashes, making it harder for security solutions to identify and block the malware.
AI Profiling Elevates Attack Sophistication
A standout feature of Dolphin X is its “AI Profiler,” which monitors application usage, browsing history, and installed software on victim machines. This data is then used to assign a “risk score” to each victim. Operators receive a daily summary that ranks compromised systems, enabling them to strategically prioritize their efforts on individuals or organizations deemed most valuable or profitable.
While this AI feature does not grant the malware full autonomy, it significantly boosts the efficiency of criminal operations. A threat actor managing a large botnet of thousands of infected devices can leverage automated scoring to quickly identify high-value targets—such as developers, finance professionals, cryptocurrency holders, or system administrators—over less lucrative victims. This targeted approach maximizes the impact of each successful infection.
The increasing integration of AI into cybercrime tools is a trend that HackersRadar continues to monitor, as explored in previous coverage of artificial intelligence cyber attacks. In the case of Dolphin X, the AI component primarily serves for victim triage and prioritization, rather than for autonomous malware generation or direct intrusion execution.
What You Should Do
- Minimize Local Storage of Sensitive Data: Reduce the amount of sensitive information stored directly on local machines, especially long-lived credentials within project directories or local credential stores.
- Revoke and Replace Compromised Credentials: Immediately treat any credential found on an infected endpoint as compromised. Revoke these credentials where possible and promptly replace them across all affected services.
- Implement Behavior-Based Monitoring: Prioritize security solutions that offer behavior-based monitoring over those relying solely on known file hashes, as Dolphin X employs mutation techniques to evade static detection. Varonis specifically highlighted that
explorer.exerunning under a non-default desktop environment can be a strong indicator of an HVNC session, regardless of the malware’s packing method. - Practice Strong Cyber Hygiene: Educate users to avoid downloading unknown files or clicking suspicious links.
- Enforce Multi-Factor Authentication (MFA): Mandate MFA for all accounts, particularly for critical systems and cloud services, to add an essential layer of security against stolen credentials.
- Limit Credential Permissions: Implement the principle of least privilege, ensuring that credentials only have the minimum necessary permissions required for their function.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Host and port | backend.thedolphinx[.]top:8443 |
Licensing, telemetry, and remote-build service |
| Domain | thedolphinx[.]top |
Parent domain for the vendor backend |
| SHA-256 | 726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0 |
Dolphin X operator panel client executable |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.