# Kontraktnik

> As of 2026-07-25, Kontraktnik is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware. ATT&CK coverage spans 53 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1055 (Process Injection).

- **Nation:** Russia
- **Tracked threats:** 4
- **Categories:** MALWARE
- **As of:** 2026-07-25

## ATT&CK techniques observed

53 techniques observed across 4 of 4 tracked threats. Tactics: Credential Access (9), Command and Control (6), Collection (5), Discovery (5), Resource Development (5), Stealth (formerly Defense Evasion) (5).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 4 of 4 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1518](https://intel.threadlinqs.com/technique/T1518) Software Discovery — Discovery — observed in 4 of 4 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 4 of 4 tracked threats
- [T1560](https://intel.threadlinqs.com/technique/T1560) Archive Collected Data — Collection — observed in 4 of 4 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 4 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 3 of 4 tracked threats
- [T1106](https://intel.threadlinqs.com/technique/T1106) Native API — Execution — observed in 3 of 4 tracked threats
- [T1498](https://intel.threadlinqs.com/technique/T1498) Network Denial of Service — Impact — observed in 3 of 4 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 3 of 4 tracked threats

## Tracked threats

- [Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications](https://intel.threadlinqs.com/threat/TL-2026-1698) — HIGH
- [Dolphin X: AI-Powered Windows Infostealer/RAT Uses Behavioral Profiling to Prioritize High-Value Victims](https://intel.threadlinqs.com/threat/TL-2026-1672) — HIGH
- [Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel](https://intel.threadlinqs.com/threat/TL-2026-1695) — HIGH
- [Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx\[.\]top)](https://intel.threadlinqs.com/threat/TL-2026-1621) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Kontraktnik
