Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First

A remote access trojan sold on a cybercrime forum claims to score infected computers by their value, helping criminals go after the richest targets first.

ThreatVectr Newsdesk· 4 min read
Full-frame overhead view of a modern silver laptop on a dark wooden desk, screen showing a blurred generic system password dialog with a red warning glow, apps
Share

Key points

  • Varonis Threat Labs found a new malware called Dolphin X being sold on a cybercrime forum by a vendor using the name Kontraktnik.
  • The malware includes an "AI Profiler" that ranks infected computers by how valuable they are to attackers, delivering daily summaries.
  • The operator panel lists 329 features and claims to steal credentials from more than 300 applications, including 100 cryptocurrency wallet extensions and 30 cloud command-line tools.
  • Varonis analysed the builder and network traffic but did not run a live sample, so the advertised capabilities are not fully verified.
  • Dolphin X specifically targets developer secrets like .env files, SSH keys, and cloud access tokens, which are the keys to production systems.

There is a new piece of criminal software making the rounds, and it comes with a sales pitch straight out of a marketing deck. It is called Dolphin X, and its authors say it uses artificial intelligence to tell criminals which of their victims are worth robbing first.

The malware was spotted by researcher Daniel Kelley at Varonis Threat Labs, who found it advertised on a cybercrime forum by a seller using the alias "Kontraktnik". First reported by BleepingComputer, the tool is a remote access trojan, meaning software that quietly gives an attacker full control of an infected computer.

What does the AI actually do?

It sorts victims. When criminals infect thousands of machines, they end up drowning in stolen passwords and files, and most of it is junk. The AI Profiler reads what apps a person uses, what sites they visit, and what software is installed, then hands the operator a ranked list each day of who is worth attacking further.

Think of it as a tool that reads through a mountain of stolen data and flags the accountant with access to the company bank account, or the developer whose laptop has the keys to a cloud server. The seller describes it as an "AI behavioral profiler with app usage tracking, risk score, and daily summary."

Kelley found technical strings in the panel like ProfilerStart, risk_score, and risk_factors, which suggest the sorting workflow is genuinely wired in. What Varonis could not confirm is which AI engine actually generates the rankings, because the team studied the builder and its network traffic rather than detonating a live sample.

What is it trying to steal?

Almost everything of value on a modern computer. The operator panel claims Dolphin X targets more than 300 applications. The failure mode here is depressingly familiar for anyone running cloud workloads: it goes straight for developer secrets.

Target category Number claimed
Browsers (Chromium and Gecko) 9
Cryptocurrency wallet extensions 100
Desktop crypto wallets 65
Password managers 10
Cloud command-line tools 30+

On top of that, the malware advertises theft of .env files (plain text files developers use to store passwords and API keys), SSH keys (the credentials that let engineers log into servers), cloud access tokens, and browser login data. In practice, one infected developer laptop can hand an attacker the keys to an entire production environment.

Should ordinary people be worried?

Not directly, but yes indirectly. Dolphin X is aimed at the kind of person who has crypto wallets, corporate logins, or admin access to cloud systems. If you are that person, assume that any infostealer infection on your machine is now being triaged by a robot, and act accordingly. Rotate credentials, and treat any weird software prompt with suspicion.

For everyone else, the risk shows up second-hand: the companies that hold your data are the ones being ranked by these tools. One thing the post-mortem will say, when a big breach lands next year, is that the attacker had thousands of stolen sessions and the AI told them exactly which one to use.

AI is now doing the boring work of cybercrime. Sorting, triaging, prioritising. The operational takeaway: your stolen credentials are no longer sitting in a dusty text file waiting to be forgotten. Something is reading them.

© 2026 Threat Vectr