Dolphin X, a new remote‑access trojan, uses an AI‑powered profiling feature to assign risk scores and rank infected users, allowing cybercriminals to prioritize the most lucrative victims first. The tool promises automated triage of thousands of stolen credentials.

Key Takeaways

  • Dolphin X includes an AI Profiler that scores each victim
  • Vendor advertises 329 features across ten categories
  • AI ranking helps attackers focus on high‑value accounts, crypto wallets, and cloud assets

Introducing Dolphin X

Dolphin X is a newly advertised remote‑access trojan (RAT) marketed on a cyber‑crime forum by a vendor using the alias “Kontraktnik.” Varonis Threat Labs researcher Daniel Kelley identified 329 capabilities grouped into ten categories, positioning it as an all‑in‑one threat platform.

How the AI Profiler Works

The standout feature is the “AI Profiler,” which ingests data from infected machines—application usage, browser domains, installed software, and custom tags—to generate a daily risk score and rank each victim. These rankings are delivered in concise daily summaries for the attacker.

Why This Matters

BozokMedia analysis shows that AI‑driven victim ranking gives threat actors a rapid triage tool, turning thousands of harvested credentials into a prioritized attack list and dramatically increasing the potential impact of a breach.

“The AI Profiler acts as an automated triage system, enabling criminals to identify the most profitable machines within minutes.” – Cyber‑security expert Daniel Kelley

Claimed Capabilities

Dolphin X claims to target over 300 applications, including nine Chromium/Gecko browsers, 100 cryptocurrency‑wallet extensions, 65 desktop crypto wallets, ten password managers, and more than 30 cloud command‑line tools. It also purports to steal .env files, SSH keys, cloud access tokens, browser login data, and other developer credentials.

Did You Know?: AI‑enabled malware profiling has surged by over 250% since 2020, becoming a favorite tool for sophisticated cyber‑crime groups.

Frequently Asked Questions

How does Dolphin X operate? It uses a builder‑based platform that pairs credential‑stealing modules with an AI Profiler to score and rank compromised hosts, delivering the highest‑value targets to the operator.

Is the AI engine behind the Profiler identified? Varonis examined the operator panel and network traffic but could not confirm the specific AI model without a live malware sample.