Executive Summary
Varonis Threat Labs has identified a sophisticated new Windows-based infostealer and Remote Access Trojan (RAT) dubbed 'Dolphin X', which is being marketed on cybercrime forums by an actor known as 'Kontraktnik'. The malware distinguishes itself through an 'AI Profiler' feature that automatically scores and triages infected victims based on their application usage and browsing history. This allows attackers to efficiently prioritize high-value targets, such as developers or system administrators, from within a large botnet.
The technical workflow of Dolphin X relies on a remote-build architecture where the operator's configuration is sent to a backend server (backend.thedolphinx[.]top) for compilation. This backend serves as a choke point for a multi-tiered mutation engine that applies obfuscation techniques ranging from PE header modifications to control-flow rewrites and instruction substitution. The malware's primary objective is the exfiltration of sensitive data from over 300 applications, including cryptocurrency wallets, SSH keys, cloud tokens, and .env files.
Dolphin X represents a growing trend of integrating AI into malware toolsets to scale offensive operations. Its focus on DevOps and cloud infrastructure credentials means a single infection on a developer workstation could lead to the complete compromise of production environments and CI/CD pipelines. Organizations are advised to move away from long-lived local credentials and pivot detection strategies toward behavioral indicators rather than brittle file hashes.
