The newly emerged Dolphin X remote access Trojan boasts advanced AI-driven profiling features that allow cybercriminals to prioritize their targeted victims based on user behavior analytics.
This invasive malware was thoroughly examined by Daniel Kelley from Varonis Threat Labs. It’s being marketed on underground cybercrime forums under the alias Kontraktnik as a comprehensive remote access Trojan.
Varonis has identified that the operator panel flaunts an impressive 329 features across 10 distinct categories, which notably includes a robust credential-stealing tool that targets over 300 applications.
Among its many features, the standout component is the AI Profiler, which meticulously analyzes data obtained from compromised systems and assigns a risk score to each victim.
According to Varonis, “Beyond credential theft, the panel incorporates a monitoring tab featuring an AI profiler, promoted as an ‘AI behavioral profiler with app usage tracking, risk scores, and daily summaries.’”
In a controlled lab environment, Varonis obtained and scrutinized the Dolphin X operator panel, studying both the malware builder and its network activities without executing the live malware.
AI Profiler: Victim Ranking for Attack Optimization
This credential-stealing malware enables attackers to commandeer access to countless online accounts, complicating efforts to identify high-value targets manually.
Dolphin X’s operator panel claims that its AI profiler can evaluate victims’ application usage, risk scores, tags, browser domains, and installed software to curate ranked profiles.

Source: Varonis
Attackers receive these rankings in a daily report, which aids them in prioritizing devices likely to yield access to valuable accounts, cryptocurrencies, corporate networks, cloud environments, or production systems.
“This feature seems engineered to assist operators in efficiently triaging their victims,” Kelly elaborates.
Varonis’ Daniel Kelley confirmed to BleepingComputer that the AI Profiler is embedded within the operator panel, revealing technical strings that corroborate the profiling process: Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage.
These technical indicators confirm that a comprehensive profiling mechanism is functioning behind the scenes, crucial for victim assessment.
However, Varonis couldn’t verify which AI algorithm powers the ranking system without analyzing live Dolphin X malware samples.
Dolphin X also functions as a credential theft mechanism, with its operator panel indicating a focus on over 300 applications, which include 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools.
Additionally, it claims to exfiltrate sensitive items like .env files, SSH keys, cloud access tokens, browser login details, cryptocurrency wallet information, and other developer credentials.
Artificial intelligence continues to gain traction among threat actors, facilitating cybercrime services such as Spam GPT and AI-driven autonomous cyber attacks.
Dolphin X, on the other hand, harnesses AI not for launching attacks but to systematically manage operational challenges by processing vast quantities of stolen data, thereby categorizing infected users as high-value victims.
Security teams document only 54% of successful attacks and issue warnings for just 14%. The remaining incidents go unnoticed in the network.
Picus’ whitepaper illustrates how to validate your SIEM and EDR rules through breach and attack simulations to ensure threats don’t evade detection.
Source: www.bleepingcomputer.com




