Skip to content
Data Breach

New Dolphin X Malware Steals Credentials From 300+ Apps and Profiles Victims With AI

A newly identified Windows malware called Dolphin X is raising concerns because it can steal far more than browser passwords. The tool is marketed to criminals as both an information stealer and a remote access trojan, giving operators a broad view of compromised systems. Its reach includes browser...

· Jul 23, 2026 · 5 min read · 👁 0 views

A newly identified Windows malware called Dolphin X is raising concerns because it can steal far more than browser passwords.

The tool is marketed to criminals as both an information stealer and a remote access trojan, giving operators a broad view of compromised systems.

Its reach includes browser logins, cryptocurrency wallets, password managers, cloud command-line tools, SSH keys, and developer environment files.

This creates serious risk for individuals and businesses, particularly when one infected device holds credentials for cloud services or production systems.

Researchers at Varonis identified Dolphin X while tracking an underground forum advertisement posted by a seller using the alias “Kontraktnik.”

The researchers examined the malware’s operator panel and related network traffic in an isolated laboratory environment. The malware is notable for pairing large-scale credential theft with an AI-based profiling feature.

Forum post advertising Dolphin X as an all-in-one RAT (Source - Varonis)
Forum post advertising Dolphin X as an all-in-one RAT (Source – Varonis)

Rather than treating every infected computer equally, its operators can use collected activity data to identify systems that appear more valuable and focus their attention there.

Varonis said in a report shared with Cyber Security News (CSN) that Dolphin X is built to collect data from hundreds of applications while helping attackers sort victims by their likely value.

The report cautioned that the reviewed capabilities came from the operator panel and vendor documentation, not from observing a live infection on a victim machine.

New Dolphin X Malware

Dolphin X advertises support for more than 300 application targets under its credential collection feature.

A single archive can reportedly hold data from nine browsers, over 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools.

The scope makes the malware dangerous beyond ordinary account takeover. Attackers could obtain browser cookies, saved logins, wallet information, and secrets stored locally by developers, including cloud tokens and SSH keys.

Similar risks have been highlighted in reporting on browser credentials and crypto wallets.

Developer workstations are especially attractive because project folders can contain .env files, private keys, and long-lived credentials.

If those secrets are copied into a stolen archive, criminals may gain a path to cloud consoles, build systems, internal code repositories, or production data.

The operator panel also advertises process injection, registry and scheduled-task persistence, UAC bypass methods, AMSI and ETW patching, and SOCKS5 proxy support.

These functions could help an attacker remain active, weaken local defenses, and route traffic through a compromised machine.

Dolphin X is assembled through a remote build process rather than directly on an operator’s device.

The panel sends selected settings, including a command-and-control address, installation path, persistence choices, and evasion options, to a remote backend that returns the compiled payload.

The service also offers mutation settings intended to alter each generated file. These include control-flow changes, instruction substitution, string re-encryption, import-table changes, and modified file metadata, complicating simple hash-based blocking approaches.

The trend resembles recent malware as a service offerings that package credential theft for broader criminal use.

AI Profiling Raises the Stakes

Dolphin X includes an “AI Profiler” that tracks application use, browsing activity, and installed software before assigning a risk score to each victim.

Operators receive a daily summary that ranks systems, allowing them to focus manually on the people or organizations that appear most profitable.

This feature does not make the malware autonomous, but it may make criminal operations more efficient.

A group managing thousands of infected devices can use automated scoring to prioritize a developer, finance worker, cryptocurrency holder, or administrator over a less valuable target.

Server-side mutation options are off by default and partly gated (Source - Varonis)
Server-side mutation options are off by default and partly gated (Source – Varonis)

The use of AI in cybercrime tools continues to expand, as explored in coverage of artificial intelligence cyber attacks.

In Dolphin X, AI appears designed for victim triage rather than for creating malware or directly carrying out an intrusion.

Security teams should reduce the amount of sensitive information stored locally, especially long-lived credentials in project directories and local credential stores.

Any credential found on an infected endpoint should be treated as exposed, revoked where possible, and replaced promptly.

Surveillance tab exposing the AI Profiler options (Source - Varonis)
Surveillance tab exposing the AI Profiler options (Source – Varonis)

Defenders should also prioritize behavior-based monitoring instead of relying only on known file hashes.

Varonis specifically noted that explorer.exe running under a non-default desktop can be a strong sign of an HVNC session, regardless of how the malware file was packed.

Users can further reduce exposure by avoiding unknown downloads and suspicious links, while organizations should enforce multi-factor authentication and limit credential permissions.

These practical controls are increasingly important as phishing attacks shift toward infostealers that quietly collect data after execution.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Host and portbackend.thedolphinx[.]top:8443Licensing, telemetry, and remote-build service
Domainthedolphinx[.]topParent domain for the vendor backend
SHA-256726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0Dolphin X operator panel client executable

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you