A recently discovered remote access trojan called Dolphin X malware has introduced an artificial intelligence feature that scores and ranks infected victims, enabling cybercriminals to efficiently identify which targets deserve priority attention. The malware was discovered and analyzed by Varonis Threat Labs researcher Daniel Kelley after being promoted on a cybercrime forum by a vendor operating under the alias “Kontraktnik.”
According to Varonis, the operator panel advertises 329 features organized across ten different categories. Among these capabilities is a credential-stealing function that reportedly targets more than 300 applications. However, the standout feature is an “AI Profiler” that examines data harvested from compromised systems and assigns each victim a risk score.
How Does the AI Profiler Function?
The AI Profiler serves as an automated sorting mechanism for cybercriminals dealing with massive amounts of stolen credentials. When credential-stealing malware compromises hundreds or thousands of online accounts, manually reviewing them all becomes impractical. Dolphin X addresses this operational challenge by automatically categorizing and ranking infected computers based on their potential value.
The operator panel indicates that the AI Profiler processes victims’ application usage, risk scores and tags, browser domains, and installed software to generate ranked profiles. These rankings are delivered to attackers through daily summaries containing ranked victim profiles, allowing them to focus on machines that might provide access to valuable accounts, cryptocurrency holdings, corporate networks, cloud environments, or production systems.
What Evidence Confirms the AI Feature?
Varonis obtained the Dolphin X operator panel and examined it within an isolated laboratory environment. The researchers analyzed the malware builder and its network traffic rather than executing a live Dolphin X agent on an infected computer. Daniel Kelley confirmed that the AI Profiler exists in the operator panel and discovered technical strings supporting the profiling workflow, including Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage.
These technical indicators suggest the profiling workflow is genuinely implemented and the panel can process the necessary data to rank victims. However, Varonis could not determine which artificial intelligence engine powers the ranking system without analyzing a live Dolphin X malware sample.
What Else Does This Malware Target?
Beyond its AI profiling capability, Dolphin X functions as a comprehensive credential stealer. The operator panel shows it targets more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools. The malware also claims to steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and developer credentials.
Because Varonis analyzed the operator panel, builder, and network traffic rather than a live malware sample running on an infected machine, the researcher could not independently verify the advertised collection capabilities.
Source: BleepingComputer