• 3 min read
Dolphin X malware claims AI can rank victims
Dolphin X malware claims to use AI to score infected users, rank high-value victims, and prioritize stolen credentials for attackers.

Image: BleepingComputer
A new Dolphin X remote access trojan (RAT) claims to use AI to profile infected users, assign them risk scores, and rank the victims attackers should target first.
Varonis Threat Labs researcher Daniel Kelley analyzed the malware after spotting it advertised on a cybercrime forum by a vendor using the alias “Kontraktnik.” The seller promotes Dolphin X as an all-in-one RAT. According to Varonis, its operator panel lists 329 features across 10 categories, including credential theft targeting more than 300 applications.
Dolphin X’s AI Profiler
The panel includes an “AI Profiler” under its surveillance tools. It reportedly analyzes data collected from infected computers and produces a risk score for each victim, helping operators sort large volumes of stolen information.
“Beyond credential collection, the panel includes a surveillance tab containing the AI Profiler. The seller describes it as an 'AI behavioral profiler with app usage tracking, risk score, and daily summary.'”
The system claims to process application usage, browser domains, installed software, risk scores, and tags. It then delivers daily summaries with ranked victim profiles, allowing attackers to prioritize systems that may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems.

Recommended reading
GitHub cuts public bug bounty payouts
Operator panel showing the AI Profiler option. Source: Varonis
“In practice, the feature appears designed to help operators triage victims,” Kelley said.
Kelley confirmed to BleepingComputer that the AI Profiler appears in the operator panel and found technical strings supporting the workflow, including Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage. Varonis said these strings indicate the profiling workflow is included and that the panel can process the data needed to rank victims.
However, the researchers could not identify the AI engine generating the rankings. Varonis examined the Dolphin X operator panel, malware builder, and related network traffic in an isolated lab; it did not execute a live Dolphin X agent on an infected computer.
Credential theft capabilities remain unconfirmed
Dolphin X also claims extensive credential-stealing capabilities, including access to:
- Nine Chromium and Gecko browsers
- 100 cryptocurrency wallet extensions
- 65 desktop crypto wallets
- 10 password managers
- More than 30 cloud command-line tools
The malware additionally claims to steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials. Because Varonis did not analyze a live sample running on an infected machine, those advertised collection capabilities were not independently confirmed.
Threat actors have increasingly used AI to support cybercrime, including services such as SpamGPT and agents designed to conduct autonomous cyberattacks. Dolphin X’s claimed use is more operational: processing large amounts of stolen data and automatically identifying the victims attackers consider most valuable.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through environments unseen. The Picus whitepaper describes how breach-and-attack simulation can test SIEM and EDR rules so threats are less likely to evade detection.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


