2 Sources
[1]
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias "Kontraktnik," promoting it as an all-in-one remote access trojan. According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications. However, one of its notable features is an "AI Profiler" that analyzes information collected from infected computers and assigns each victim a risk score. "Beyond credential collection, the panel includes a surveillance tab containing the AI Profiler. The seller describes it as an 'AI behavioral profiler with app usage tracking, risk score, and daily summary,'" explains Varonis. Varonis obtained the Dolphin X operator panel and analyzed it in an isolated lab, noting they examined the malware builder and its network traffic rather than executing a live Dolphin X agent on an infected computer. AI Profiler ranks victims for attackers Credential-stealing malware can allow attackers to steal credentials for hundreds, if not thousands, of online accounts, making it difficult to manually review them all for high-value targets. Dolphin X's AI Profiler claims to automate this process by acting as a sorting system that scores, categorizes, and ranks infected computers so that the attackers know which are the most high-value to target further. The operator panel claims that the AI Profiler can process victims' application usage, risk scores and tags, browser domains, and installed software to produce ranked profiles. These scores are given to attackers in daily summaries containing ranked victim profiles, allowing them to prioritize machines that may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems. "In practice, the feature appears designed to help operators triage victims," explains Kelley. Varonis researcher Daniel Kelley confirmed to BleepingComputer that the AI Profiler is present in the operator panel and discovered technical strings supporting the profiling workflow, including , , , , , and . The researcher said these strings indicate that the profiling workflow is actually included and that the panel can process the data needed to rank victims. However, Varonis could not determine what artificial intelligence engine is being used to produce the rankings without analyzing a live Dolphin X malware sample. The malware also operates as a credential stealer, with the operator panel showing that it targets more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools. Dolphin X also claims to steal files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials. As Varonis analyzed the Dolphin X operator panel, builder, and related network traffic rather than a live malware sample executing on an infected machine, the malware's advertised collection capabilities were not independently confirmed by the researcher. Artificial intelligence has become a popular tool among threat actors, with it being used to launch cybercrime services such as SpamGPT and AI agents conducting autonomous cyberattacks. Dolphin X platform instead uses AI to solve an operational problem by processing large amounts of stolen data and automatically sorting infected users into highest-value victims.
[2]
This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target
* Varonis Threat Labs uncovered Dolphin X, a powerful RAT with 329 features across 10 categories * Its standout "AI Profiler" ranks victims by usage and sends summaries to attackers daily * Malware is sold on the dark web via subscription tiers, starting at $80 per month What if malware could talk to its operator and tell it which of the infected victims is worth paying attention to, and which not? A few years ago, this might have been science fiction but today, thanks to breakthroughs in Artificial Intelligence (AI), not only is it possible, it's also already available on the black market. Security researchers Varonis Threat Labs recently disclosed finding a rather revolutionary remote access trojan (RAT) called Dolphin X. Even without advanced AI capabilities, the RAT is quite potent, acting as an infostealer, a Hidden Virtual Network Computing (HVNC), a DDoS botnet, or a loader. Just its infostealer capabilities are nothing short of impressive - it can target more than 300 applications to steal browser passwords, enterprise credentials, cryptocurrency wallet data, DevOps secrets, and different sensitive files, and it comes with 329 features split into 10 categories. AI Profiler However, the AI capability is the one that stunned the researchers. Called "AI Profiler", the feature ranks victims by app usage, browsing history, and more, sending a daily summary to the attackers. The malware is now being offered on the dark web, where other criminals can subscribe to one of three tiers. The basic tier costs $80 per month, while the top tier is around $230 per month. Lifetime subscription costs $1,140 for basic access, and goes up to $3,420 for the top tier. "Dolphin X's collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials," Varonis said in its write-up. "On the wrong machine, a single infection could expose access to an entire production environment." "Its use of AI is also interesting because it shows us how AI is being integrated into more cybercrime tooling." Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Share
Copy Link
A new remote access trojan called Dolphin X employs an AI Profiler to automatically rank infected users by value, helping cybercriminals identify which victims to target first. Varonis Threat Labs discovered the malware being sold on the dark web with subscription tiers starting at $80 per month, featuring 329 capabilities including credential theft from over 300 applications.
Dolphin X malware represents a troubling evolution in cybercrime, combining traditional remote access trojan capabilities with an AI Profiler that automatically scores and ranks infected users. Varonis Threat Labs researcher Daniel Kelley uncovered the threat while monitoring cybercrime forums, where a vendor using the alias Kontraktnik advertises it as an all-in-one solution for attackers
1
. The malware's operator panel boasts 329 features across ten categories, but its standout capability lies in helping attackers prioritize targets for exploitation through artificial intelligence.
Source: BleepingComputer
The AI Profiler analyzes information collected from infected computers and assigns each victim risk scores based on their application usage, browser domains, and installed software. This automated sorting system addresses a practical problem for cybercriminals: when credential-stealing malware harvests credentials for hundreds or thousands of online accounts, manually reviewing them all becomes impractical
1
. The profiler processes victims' data and delivers daily summaries containing ranked profiles, allowing attackers to identify machines that may provide access to valuable accounts, cryptocurrency wallets, corporate networks, cloud environments, or production systems.While the AI Profiler draws attention, Dolphin X functions as a comprehensive threat platform. The remote access trojan operates as an infostealer, Hidden Virtual Network Computing (HVNC) tool, DDoS botnet, and loader
2
. Its credential-stealing capabilities target more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and over 30 cloud command-line tools1
.The malware also claims to steal files, SSH keys, cloud access tokens, browser login data, and DevOps secrets. Varonis emphasized the breadth of this collection scope: "Dolphin X's collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials. On the wrong machine, a single infection could expose access to an entire production environment"
2
.Dolphin X is now available on the dark web through subscription tiers, making weaponized AI accessible to a broader range of threat actors. The basic tier costs $80 per month, while the top tier runs approximately $230 per month. Lifetime subscriptions range from $1,140 for basic access to $3,420 for premium features
2
.Varonis analyzed the operator panel, malware builder, and network traffic in an isolated lab rather than executing a live sample. Kelley confirmed technical strings supporting the profiling workflow, including references that indicate the panel can process data needed to rank victims
1
. However, without analyzing a live Dolphin X sample, researchers could not determine which artificial intelligence engine powers the ranking system.Related Stories

Source: TechRadar
This development signals how AI-powered malware is being integrated into cybercrime tooling to solve operational challenges. Rather than using AI to create new attack vectors, Dolphin X applies it to process large amounts of stolen data and automatically sort infected users into high-value targets
1
. Organizations should watch for increased sophistication in targeted attacks as threat actors leverage such tools to identify employees with access to critical systems, cryptocurrency holdings, or cloud infrastructure. The automation of victim triage means attackers can operate more efficiently, potentially reducing the window between initial infection and targeted exploitation of the most valuable compromised accounts.Summarized by
Navi
[1]
04 Sept 2025•Technology

01 Jul 2026•Technology

30 May 2025•Technology

1
Technology

2
Technology

3
Science and Research
