329 features across ten categories appear in the operator panel for a newly discovered Windows infostealer and remote access trojan, researchers at Varonis Threat Labs report — and the tool pairs that breadth with an “AI Profiler” that tells attackers which infected machines are worth investigating first.
Varonis Threat Labs' analysis of Dolphin X
Varonis Threat Labs obtained and examined the malware’s operator panel in an isolated laboratory environment after the tool was advertised on a cybercrime forum. The researchers describe the threat as a Windows infostealer and remote access trojan (RAT) dubbed Dolphin X. Their analysis found an operator interface built to collect and organize a wide range of credentials and sensitive files, and to hand attackers a prioritized list of victims.
AI Profiler: automated victim scoring and daily summaries
The standout capability in the panel is an “AI Profiler” that automatically ranks infected users. According to Varonis, the profiler assigns scores to victims by evaluating factors such as application usage, browsing activity and installed software, producing a daily summary of rankings sent to attackers. Varonis noted that the automated ranking is useful because a single attacker could control thousands of infected machines — far more than could be reviewed manually — and the profiler lets operators focus on those most likely to yield valuable access or data.
Collection scope: 329 features and 300+ application targets
The panel lists 329 features organized across ten categories, and the collection scope is extensive. Varonis researchers wrote, “These targets range from browser logins and cryptocurrency wallets to SSH keys and cloud tokens, with the collected data staged in a single archive.” The malware is designed to target more than 300 applications and steal a wide range of sensitive artefacts including cryptocurrency wallets, .env files, SSH keys, cloud tokens and DevOps credentials.
Operational indicators and suggested defenses for security teams
Varonis provided two explicit defensive recommendations grounded in how Dolphin X operates:
- “Keep long-lived credentials off disk wherever possible, especially out of project directories and local credential stores. Infostealers are designed to grab everything in one pass, so anything stored locally should be treated as potentially exposed.”
- “Focus detection on behavior rather than file signatures. For example, explorer.exe running under a non-default desktop is a strong indicator of an HVNC session, regardless of how the malware binary is packed or what hash it uses.”
Those guidance points follow directly from the malware’s architecture: a broad credential looter that stages collected data in a single archive, combined with remote access capabilities that can be masked by packing or changing file hashes.
How security teams, DevOps teams, and end users should respond
- Security teams and incident responders should prioritize behavioral detection and triage rules that flag atypical desktop contexts (for example, explorer.exe under non-default desktops) and rapid mass-exfiltration patterns, since signature-based detection may be evaded by packing and hash changes.
- DevOps and cloud teams should remove long-lived secrets from local files and project directories, and avoid storing cloud tokens, SSH keys and .env credentials on disk where an infostealer can retrieve them in one pass.
- End users who manage cryptocurrency wallets or developer credentials should assume locally stored secrets are vulnerable if a machine becomes infected and follow organizational guidance to shift secrets to more ephemeral or remote stores.
Dolphin X combines a broad, single-pass credential looter with an automated AI-driven triage system that turns mass infection into targeted opportunity. For defenders the practical takeaway is crisp: treat long-lived, on-disk credentials as already exposed and invest in behavioral detection that flags the session- and process-level anomalies the malware exploits. Varonis’ analysis makes clear that the technical scale of collection is matched by tools designed to focus attacker effort — and that matching focus will be necessary on the defensive side as well.
https://www.infosecurity-magazine.com/news/new-dolphin-x-stealer-ai-targets/




