Dolphin X Stealer Leverages AI Profiler to Prioritize High-Value Victims
A new Windows information-stealer and RAT, dubbed Dolphin X, uses an AI profiler to rank victims, offering a sophisticated, subscription-based tool for cybercriminals.

A novel Windows information-stealer and remote access trojan (RAT), named Dolphin X, has surfaced on cybercrime forums, according to Varonis Threat Labs. This malware distinguishes itself by targeting over 300 applications, aiming to pilfer credentials, cryptocurrency, sensitive files, and secrets such as cloud tokens and DevOps credentials. Its most striking feature is an AI-powered profiler designed to assess and rank infected victims, enabling attackers to focus their efforts on those most likely to yield significant profit.
The AI Profiler analyzes a victim's installed applications, browsing history, and overall software usage to assign a score. This allows cybercriminals to receive a daily summary that prioritizes high-value targets, a capability that Varonis researchers describe as unprecedented. Beyond credential theft, Dolphin X also claims to offer functionalities such as Hidden Virtual Network Computing (HVNC), a DDoS botnet, and a loader for other malware. The malware currently operates exclusively on Windows, with claims of future Debian support, and primarily supports English and Russian languages.
Developed by an actor using the alias "Kontraktnik," Dolphin X is offered through a Software-as-a-Service (SaaS) model, significantly lowering the barrier to entry for less technically proficient cybercriminals. This subscription-based approach allows attackers to access tiered features, ranging from basic file and credential stealing to more advanced capabilities for evading detection and manipulating binary characteristics.
Varonis obtained and analyzed the malware builder, operator panel, and network traffic, though they did not examine a live malware sample. While Varonis cannot definitively confirm all vendor claims, the builder's structure suggests the advertised features are likely legitimate. Positive feedback from early buyers on the cybercrime forum further supports the malware's purported capabilities, with the sales thread attracting significant attention.
Dolphin X employs a three-tier subscription model, with monthly costs ranging from approximately $80 to $230, and lifetime subscriptions available for up to $3,420. The higher tiers offer more sophisticated evasion techniques, such as shuffling the import table, rewriting control flow, and re-encrypting embedded strings to hinder signature-based detection and analysis. This tiered approach allows attackers to scale their operations and sophistication based on their investment.
The implications for defenders are twofold. Firstly, the pervasive nature of information-stealers like Dolphin X underscores the need to minimize the local storage of sensitive credentials. Anything stored on disk should be considered potentially exposed. Secondly, security teams must shift their focus from solely relying on file signatures to behavioral analysis for threat detection. Malware like Dolphin X is designed to bypass signature-based defenses, making behavioral indicators, such as unusual process execution, critical for identifying malicious activity.
This development aligns with a broader trend of cybercriminals integrating AI into their tools and operations. Varonis researchers have previously identified other AI-powered malware, including the phishing kit Bluekit and the email attack tool SpamGPT. The increasing sophistication and accessibility of these AI-enhanced tools pose a significant challenge for cybersecurity professionals, as they enable more efficient and targeted attacks.