"There's two things that stand out," Daniel Kelley, a senior threat researcher with Varonis, told The Register. "The first thing is the AI profiler. That's something I've never seen before. And then it’s also the breadth of applications that it steals..."
Dolphin X: capabilities and claims
Varonis Threat Labs identified a new Windows information‑stealer and remote access trojan (RAT) offered for sale under the alias "Kontraktnik." The seller's advert claims Dolphin X can target more than 300 applications and exfiltrate a wide set of valuables: browser passwords, enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens and DevOps secrets, as well as arbitrary files and other credentials. The vendor also markets the builder and operator panel as multi‑purpose: "You can use it as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, as a loader."
AI Profiler: ranking victims by likely payoff
Among the advertised features is an unusual "AI Profiler" that scores infected users by app usage, browsing history and installed software. According to Varonis' writeup shared with The Register, the profiler generates a daily summary ranking victims based on the likely payoff from follow‑on attacks, giving operators guidance on which compromised machines to exploit first.
Evasion toolkit and subscription tiers
The Dolphin X operator panel lists 329 features across 10 categories and is sold on a three‑tier subscription model (plus lifetime options). The basic monthly subscription costs about $80 and offers capabilities such as rewriting Windows Portable Executable (PE) timestamps, altering Rich headers, and section padding, and features intended to evade brittle YARA rules and hash‑blocklists. The mid tier (price listed ≈ $230 per month for the top level) advertises additional protections such as shuffling the import table to change import hashes between builds. The top subscription promises more aggressive transformations—rewriting control flow, substituting instructions and re‑encrypting embedded strings with a new random key each build—measures intended to make stable byte sequences harder to identify. Lifetime subscriptions were quoted at about $1,140 for basic access, $2,280 for mid‑tier, or $3,420 for perpetual pro‑level access.
Varonis analysis, marketplace signals, and limits of testing
Varonis obtained and analyzed the malware builder, operator panel and its network traffic, but the lab did not run a live malware sample. Because of that constraint, Varonis said it cannot guarantee every claim in the vendor advert is true; still, the analyst team judged the builder's contents "had everything to suggest the features were legitimate." The sales thread on the forum had passed roughly 3,000 views and, as of Tuesday in Varonis' reporting, Kontraktnik had closed at least two confirmed deals—each accompanied by positive feedback on the forum.
Other concrete vendor details: Dolphin X currently runs only under Windows, supports English and Russian, and—according to Kontraktnik—development on Debian is "working on" progress. Kelley suspects the developer is Russian‑speaking, and the builder includes an option not to infect users in Commonwealth of Independent States (CIS) countries, a choice the Varonis team noted is common among some Russian‑based ransomware and cybercrime offerings.
What this means for technologists, procurement managers, and end users
- Technologists and security teams: Varonis' report emphasizes shifting detection focus from file signatures to behavior. The researchers note that malware like Dolphin X includes packing and transformation features to bypass signature‑based defenses; as an example, Varonis highlights that "explorer.exe running under a non‑default desktop is a strong indicator of an HVNC session," a behavioral signal that is meaningful regardless of binary packing or hash.
- Procurement and enterprise managers: The criminal‑market SaaS model and three‑tier pricing are intended to lower the technical barrier to entry. "It really lowers the barrier to entry," Kelley said, arguing that a packaged builder/operator environment lets less technically adept buyers deploy complex capabilities without deep development expertise.
- End users and credential custodians: Varonis recommends keeping long‑lived credentials off disk where possible, since infostealers are designed to grab "everything in one pass" and anything stored locally should be treated as potentially exposed.
Varonis places Dolphin X in a broader trend: the lab previously uncovered other AI‑integrated crimeware, including a phishing kit called Bluekit and an email attack tool dubbed SpamGPT, and Kelley described AI integration across criminal tooling as "a huge trend." In the case of Dolphin X, the combination of a wide attack surface (329 listed features and more than 300 targeted apps) with an AI profiler that prioritizes victims presents defenders with two linked challenges: preventing mass credential exposure, and detecting the behavioral signals of post‑compromise reconnaissance and remote control.
For defenders the immediate, concrete steps Varonis suggests are simple and specific: treat locally stored long‑lived credentials as risky, and tune detection toward behaviors that indicate HVNC, lateral movement and credential harvesting rather than relying primarily on hash or signature matches. Whether organizations can operationalize that pivot fast enough against a marketed tool that bundles evasion and AI‑powered prioritization is the practical test the report leaves on the table.




