← All stories
● Covered by 2 sources · 2 reportsMedium impact1 negative1 neutral

Dolphin X Malware Uses AI Profiling to Rank High-Value Targets

🔄 Updated 23d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Dolphin X is a new remote access trojan advertised on a cybercrime forum.
  • It includes an "AI Profiler" to score and rank infected users.
  • The profiler analyzes application usage, risk scores, and installed software.
  • Varonis Threat Labs analyzed the malware's operator panel and builder.
  • Dolphin X is advertised by a vendor named "Kontraktnik".
  • The operator panel lists 329 features across ten categories.
  • The credential-stealing feature targets more than 300 applications.
  • The AI Profiler is in the surveillance tab of the operator panel.
  • The AI Profiler tracks app usage, risk score, and daily summary.
  • Varonis analyzed the malware builder and network traffic, not a live agent.
  • Dolphin X exfiltrates browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens.

Dolphin X Malware Emerges with AI Profiling

A new remote access trojan (RAT) called Dolphin X has been identified, featuring an "AI Profiler" designed to assess and rank infected users. This malware is being advertised on cybercrime forums by a vendor using the alias "Kontraktnik," promoting it as an all-in-one remote access tool.

AI Profiler Functionality

The Dolphin X operator panel lists 329 features, including a credential-stealing capability targeting over 300 applications. The notable "AI Profiler" analyzes data collected from compromised computers to assign a risk score to each victim. This feature is described as an "AI behavioral profiler with app usage tracking, risk score, and daily summary."

Automating Victim Prioritization

Credential-stealing malware often yields a large volume of compromised accounts, making manual review for high-value targets time-consuming. Dolphin X's AI Profiler automates this process by categorizing and ranking infected machines. This allows attackers to quickly identify victims who may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems.

Analysis by Varonis Threat Labs

Varonis Threat Labs researcher Daniel Kelley analyzed the Dolphin X malware. Varonis obtained the operator panel and examined the malware builder and network traffic in an isolated lab environment. Kelley confirmed the presence of the AI Profiler in the operator panel and found technical strings supporting its profiling workflow, such as "Auto-Start AI Profiler" and "risk_score."

Updates

🕒 2026-07-24 · new reporting from SecurityWeek
  • Dolphin X is advertised by a vendor named "Kontraktnik".
  • The operator panel lists 329 features across ten categories.
  • The credential-stealing feature targets more than 300 applications.
  • The AI Profiler is in the surveillance tab of the operator panel.
  • The AI Profiler tracks app usage, risk score, and daily summary.
  • Varonis analyzed the malware builder and network traffic, not a live agent.
  • Dolphin X exfiltrates browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A new infostealer, Dolphin X, uses AI to profile victims and targets over 300 applications for data exfiltration. Additionally, Abbott disclosed a cybersecurity incident, a cyberattack disrupted internet services in 23 Maine towns, and Palo Alto Networks detailed an exploit chain in Siemens ROX II OT switches.

A new remote access trojan named Dolphin X incorporates an "AI Profiler" feature to score and rank infected users, helping cybercriminals prioritize victims. This development allows attackers to automate the identification of high-value targets from a large pool of compromised accounts, potentially increasing the efficiency of cyberattacks.