A sophisticated new Remote Access Trojan (RAT) known as Dolphin X has emerged on the cybercrime landscape, distinguishing itself with a purported Artificial Intelligence-powered profiling feature. This advanced capability aims to automate the process of identifying and ranking infected users based on their perceived value, enabling cybercriminals to strategically target those most likely to yield significant returns. The discovery and initial analysis of this potent malware have been conducted by Daniel Kelley, a researcher at Varonis Threat Labs, who observed its promotion on a clandestine cybercrime forum by a vendor operating under the alias "Kontraktnik." This vendor is marketing Dolphin X as a comprehensive, all-in-one solution for malicious actors seeking to establish and exploit remote access to compromised systems.
The Dolphin X operator panel, as detailed by Varonis, is remarkably feature-rich, boasting an extensive list of 329 functionalities distributed across ten distinct categories. Among these are robust credential-stealing capabilities, with claims of targeting an impressive repertoire of over 300 different applications. However, it is the novel "AI Profiler" that has captured the attention of cybersecurity professionals, representing a significant evolution in how cybercriminals approach victimology. This AI component is designed to meticulously analyze data gleaned from infected computers, assigning each compromised user a quantifiable risk score. This scoring mechanism allows attackers to move beyond a scattergun approach and instead focus their efforts on the most lucrative targets.
The Genesis and Development of Dolphin X
While the precise origins of Dolphin X are not yet fully established, its emergence on cybercrime forums suggests a deliberate and coordinated effort by its developers to create a high-impact, user-friendly tool for a broad spectrum of threat actors. The vendor "Kontraktnik" appears to be actively marketing Dolphin X, indicating a commercial intent and a drive to attract a significant user base within the illicit underground. The inclusion of an AI-driven profiling system suggests a forward-thinking approach to malware development, mirroring the broader trend of artificial intelligence adoption across various sectors, including the criminal domain.
Varonis Threat Labs, in their proactive security research, managed to obtain access to the Dolphin X operator panel. Their analysis was conducted in a secure, isolated laboratory environment, focusing on the malware builder and its associated network traffic. Critically, Varonis did not execute a live Dolphin X agent on an infected computer, a common practice to avoid direct exposure to active malware. This cautious approach allowed them to examine the architecture and advertised capabilities of the RAT without posing an immediate risk to their own systems or network infrastructure.

AI Profiler: A New Frontier in Victim Prioritization
The core innovation of Dolphin X lies in its AI Profiler, a feature that promises to revolutionize the way cybercriminals assess and exploit their victims. Credential-stealing malware, by its very nature, can harvest an overwhelming volume of sensitive information from a compromised system. This often includes login credentials for a vast array of online accounts, making it a monumental task for attackers to manually sift through the data to identify high-value targets. The AI Profiler aims to solve this operational bottleneck by acting as an intelligent sorting and prioritization system.
According to Varonis’s analysis, the AI Profiler’s functionality extends to analyzing a victim’s application usage patterns, their assigned risk scores and tags, the browser domains they visit, and the software installed on their systems. This comprehensive data collection allows Dolphin X to generate ranked profiles of infected users, presenting attackers with a clear hierarchy of potential targets. The operator panel reportedly provides daily summaries that include these ranked victim profiles, empowering attackers to strategically allocate their resources and focus on machines that are most likely to grant access to valuable assets. These assets could include sensitive corporate networks, cloud environments, production systems, lucrative cryptocurrency holdings, or other high-value accounts.
Daniel Kelley, the Varonis researcher who spearheaded the analysis, elaborated on the practical implications of this feature. "In practice, the feature appears designed to help operators triage victims," Kelley stated. His examination of the operator panel confirmed the presence of the AI Profiler and uncovered specific technical strings that support the underlying profiling workflow. These strings, such as Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage, provide strong evidence that the profiling mechanism is indeed implemented and capable of processing the necessary data to rank victims.
However, Varonis was unable to definitively identify the specific artificial intelligence engine powering these rankings without analyzing a live Dolphin X malware sample. This leaves open questions about the sophistication and potential biases of the AI model being employed. Despite this limitation, the mere presence of such a feature signifies a significant advancement in the automation of cybercrime operations.
Beyond AI: A Comprehensive Credential Stealing Arsenal

While the AI Profiler is a headline-grabbing feature, Dolphin X is also a highly capable credential stealer in its own right. The operator panel indicates a broad attack surface, with the malware designed to target credentials from over 300 applications. This extensive list includes:
- Web Browsers: Targeting nine different Chromium and Gecko-based browsers, likely encompassing popular options like Chrome, Firefox, Edge, and Brave, to steal saved logins and session cookies.
- Cryptocurrency Wallets: A significant focus is placed on cryptocurrency theft, with Dolphin X designed to compromise 100 cryptocurrency wallet extensions for web browsers and 65 desktop cryptocurrency wallets. This highlights the growing attractiveness of digital assets as a target for cybercriminals.
- Password Managers: The malware also targets popular password managers, aiming to gain access to the master passwords and stored credentials within these security applications.
- Cloud Command-Line Tools: With over 30 cloud command-line tools on its target list, Dolphin X aims to pilfer credentials necessary for accessing and manipulating cloud infrastructure, such as AWS CLI, Azure CLI, and Google Cloud SDK.
Furthermore, Dolphin X claims to be adept at stealing critical developer-related credentials and sensitive files. This includes .env files, which often contain API keys and database credentials; SSH keys, used for secure remote server access; cloud access tokens, which grant temporary access to cloud services; and general browser login data. The ability to exfiltrate such a wide array of sensitive information makes Dolphin X a formidable threat to individuals and organizations alike.
It is important to reiterate that Varonis’s analysis was based on the operator panel, builder, and network traffic, not on a live execution of the malware. Therefore, the full extent of Dolphin X’s collection capabilities, as advertised by the vendor, has not been independently verified through direct observation of its actions on an infected system.
The Growing Role of AI in Cybercrime
The emergence of Dolphin X is emblematic of a broader trend: the increasing adoption of artificial intelligence by threat actors to enhance their malicious activities. AI is no longer confined to defensive cybersecurity applications; it is rapidly becoming a tool for offensive cyber operations. Recent examples illustrate this growing trend:
- SpamGPT: A malicious service that reportedly leverages AI to generate highly convincing spam emails, bypassing traditional spam filters and increasing the success rate of phishing campaigns.
- AI Agents in Autonomous Attacks: Reports have surfaced of AI agents capable of conducting autonomous cyberattacks, from reconnaissance and vulnerability exploitation to lateral movement and data exfiltration, all with minimal human intervention.
In contrast to these applications where AI directly performs attack actions, Dolphin X utilizes AI to solve an operational challenge within the cybercrime ecosystem. By automating the processing of vast quantities of stolen data and intelligently sorting infected users into categories of perceived value, Dolphin X streamlines the attacker’s workflow and maximizes their efficiency. This shift towards AI-driven operational efficiency in cybercrime poses a significant challenge for defenders, requiring them to not only contend with novel attack vectors but also with the enhanced capabilities of attackers who can leverage intelligent automation.

Implications for Cybersecurity
The advent of Dolphin X, with its AI-powered victim profiling, signals a concerning evolution in the sophistication of readily available cybercrime tools. For cybersecurity professionals, this presents several critical implications:
- Increased Efficiency of Attackers: The ability to automatically identify and prioritize high-value targets means that attackers can achieve their objectives faster and with less effort. This could lead to a surge in targeted attacks, as even less sophisticated threat actors can now leverage intelligent systems to guide their actions.
- Enhanced Evasion Techniques: While not directly observed in Varonis’s analysis, it is plausible that the AI profiler could also be used to identify less valuable targets, potentially allowing attackers to avoid triggering detection systems by focusing on "quieter" intrusions.
- Greater Focus on Endpoint Security and Data Analytics: The reliance on comprehensive data collection from infected endpoints underscores the importance of robust endpoint detection and response (EDR) solutions. Furthermore, organizations need advanced data analytics capabilities to detect anomalous user behavior and identify potential compromises that might be masked by sophisticated threat actors.
- The Need for Proactive Threat Intelligence: Understanding the capabilities and trends in malware development, such as the integration of AI, is crucial for staying ahead of evolving threats. Varonis’s research exemplifies the value of proactive threat intelligence in identifying and analyzing emerging risks.
- The Democratization of Sophisticated Cybercrime: By packaging advanced features like AI profiling into a user-friendly operator panel, Dolphin X potentially lowers the barrier to entry for individuals seeking to engage in large-scale cybercrime. This could lead to an increase in the volume and complexity of attacks.
The continuous innovation in the cybercrime underground, particularly the integration of cutting-edge technologies like artificial intelligence, necessitates a parallel evolution in defensive strategies. As threat actors become more efficient and strategic, so too must cybersecurity measures adapt to counter these increasingly sophisticated threats. The battle against cybercrime is becoming a race between evolving offensive AI capabilities and the development of equally intelligent and adaptive defensive AI solutions. The Dolphin X RAT serves as a stark reminder of this escalating technological arms race in the digital realm.







