Skip to main content
Emerging ThreatsMalware & Ransomware

Dolphin X Malware Exploits AI to Prioritize High-Value Targets

Laptop open on a plain surface with a blank screen showing soft glow.

The Dolphin X operator panel lists 329 features across ten categories — and one of those features is an "AI Profiler" that promises to sort, score and rank infected computers so attackers can find the richest victims first.

Dolphin X operator panel and the AI Profiler

Varonis Threat Labs researcher Daniel Kelley found Dolphin X advertised on a cybercrime forum by a vendor using the alias "Kontraktnik," promoting the tool as an "all-in-one remote access trojan." According to Varonis, the operator panel includes an "AI Profiler" described by the seller as an "AI behavioral profiler with app usage tracking, risk score, and daily summary." The panel claims the profiler will produce ranked victim profiles and deliver daily summaries that list victims by score, allowing operators to prioritize machines that "may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems."

How the profiling workflow appears to work

Varonis examined the operator panel, the malware builder, and related network traffic inside an isolated lab environment and documented strings and labels that support a profiling workflow. Researcher Daniel Kelley identified technical strings such as Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage. Varonis interprets these artifacts as evidence that the panel can process application usage, browser domains, installed software and other collected artefacts to generate the ranked profiles shown to attackers.

Credential-stealing claims and targeted applications

Beyond the profiler, the Dolphin X operator panel advertises large-scale credential collection. The vendor claims the malware targets more than 300 applications, including nine Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers and more than 30 cloud command-line tools. Dolphin X also claims the ability to steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information and other developer credentials — material that, according to the panel, would feed into the profiler’s rankings.

What Varonis confirmed — and what remains unproven

Varonis obtained and analyzed the Dolphin X operator panel and builder and inspected network traffic, but the researcher did not execute a live Dolphin X agent on an infected machine. Because their work examined the panel and builder rather than a running malware sample, Varonis did not independently confirm the malware’s advertised collection capabilities. Varonis also noted it could not determine what artificial intelligence engine, if any, produces the rankings without analysis of a live sample. Kelley told BleepingComputer that in practice "the feature appears designed to help operators triage victims," linking the profiler’s outputs to the operational problem of sorting very large pools of stolen credentials and system artefacts.

What this means for technologists, enterprises, and end users

  • Technologists and security teams: The profiler is described as an automation layer for triage — a system that would turn broad credential theft into prioritized investigation targets by scoring application usage, installed software and browser domains. Security operations that rely on manual review of stolen credentials could see their workload reshaped if attackers adopt automated ranking.
  • Procurement and enterprise leaders: Dolphin X’s advertised targets include cloud command-line tools, developer credentials and production systems — items the operator panel explicitly cites as high-value outcomes. Organizations with exposed developer tools, cloud tokens or crypto infrastructure are the categories the panel claims attackers will flag via daily ranked summaries.
  • End users and individual account holders: The panel advertises theft of browser login data, SSH keys, .env files, cryptocurrency wallet extensions and desktop wallets. Those categories of data are among the inputs the profiler purports to analyze when assigning risk scores to infected machines.

Artificial intelligence has already begun to appear in cybercrime services, the Varonis write-up notes, and Dolphin X frames AI not as an offensive autonomy but as an operational tool: a sorter that reduces hundreds or thousands of stolen credentials to a ranked list of promising victims. What remains open and consequential is concrete: which AI engine, if any, is doing the scoring, and whether the profiling outputs are accurate when fed real-world stolen data. Varonis’ analysis establishes the panel’s intent and mechanics, but without a live sample the question of real-world efficacy — and thus the true change in attacker capability — is still unresolved.

https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/