Dolphin X Malware Uses AI Profiler to Score Victims and Prioritize High-Value Targets

Reviewed byNidhi Govil

2 Sources

Share

A new remote access trojan called Dolphin X employs an AI Profiler to automatically rank infected users by value, helping cybercriminals identify which victims to target first. Varonis Threat Labs discovered the malware being sold on the dark web with subscription tiers starting at $80 per month, featuring 329 capabilities including credential theft from over 300 applications.

AI-Powered Malware Automates Victim Prioritization

Dolphin X malware represents a troubling evolution in cybercrime, combining traditional remote access trojan capabilities with an AI Profiler that automatically scores and ranks infected users. Varonis Threat Labs researcher Daniel Kelley uncovered the threat while monitoring cybercrime forums, where a vendor using the alias Kontraktnik advertises it as an all-in-one solution for attackers

1

. The malware's operator panel boasts 329 features across ten categories, but its standout capability lies in helping attackers prioritize targets for exploitation through artificial intelligence.

Source: BleepingComputer

Source: BleepingComputer

The AI Profiler analyzes information collected from infected computers and assigns each victim risk scores based on their application usage, browser domains, and installed software. This automated sorting system addresses a practical problem for cybercriminals: when credential-stealing malware harvests credentials for hundreds or thousands of online accounts, manually reviewing them all becomes impractical

1

. The profiler processes victims' data and delivers daily summaries containing ranked profiles, allowing attackers to identify machines that may provide access to valuable accounts, cryptocurrency wallets, corporate networks, cloud environments, or production systems.

Technical Capabilities Beyond AI Profiling

While the AI Profiler draws attention, Dolphin X functions as a comprehensive threat platform. The remote access trojan operates as an infostealer, Hidden Virtual Network Computing (HVNC) tool, DDoS botnet, and loader

2

. Its credential-stealing capabilities target more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and over 30 cloud command-line tools

1

.

The malware also claims to steal files, SSH keys, cloud access tokens, browser login data, and DevOps secrets. Varonis emphasized the breadth of this collection scope: "Dolphin X's collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials. On the wrong machine, a single infection could expose access to an entire production environment"

2

.

Dark Web Distribution and Weaponized AI

Dolphin X is now available on the dark web through subscription tiers, making weaponized AI accessible to a broader range of threat actors. The basic tier costs $80 per month, while the top tier runs approximately $230 per month. Lifetime subscriptions range from $1,140 for basic access to $3,420 for premium features

2

.

Varonis analyzed the operator panel, malware builder, and network traffic in an isolated lab rather than executing a live sample. Kelley confirmed technical strings supporting the profiling workflow, including references that indicate the panel can process data needed to rank victims

1

. However, without analyzing a live Dolphin X sample, researchers could not determine which artificial intelligence engine powers the ranking system.

Implications for Enterprise Security

Source: TechRadar

Source: TechRadar

This development signals how AI-powered malware is being integrated into cybercrime tooling to solve operational challenges. Rather than using AI to create new attack vectors, Dolphin X applies it to process large amounts of stolen data and automatically sort infected users into high-value targets

1

. Organizations should watch for increased sophistication in targeted attacks as threat actors leverage such tools to identify employees with access to critical systems, cryptocurrency holdings, or cloud infrastructure. The automation of victim triage means attackers can operate more efficiently, potentially reducing the window between initial infection and targeted exploitation of the most valuable compromised accounts.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved