Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top) — Threadlinqs Intelligence
As of 2026-07-22, Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top) is a high-severity malware threat attributed to Kontraktnik, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1621 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Kontraktnik · FINANCIAL
Dolphin X is a Windows infostealer sold as malware-as-a-service on cybercrime forums by vendor "Kontraktnik," targeting 300+ applications (browsers, password managers, crypto wallets, SSH keys, .env
Varonis Threat Labs (analyst Daniel Kelley) obtained access to the Dolphin X builder and operator panel — not a live sample — after the tool appeared for sale on a cybercrime forum under the alias "Kontraktnik," with the sales thread exceeding 3,000 views and at least two confirmed deals with positive vendor feedback as of the report. Dolphin X is a Windows-only .NET/native hybrid stealer (Debian-based operator tooling claimed by the vendor) marketed with the pitch "you can use it as a stealer, as an HVNC, as a DDoS botnet, as a loader," positioning it as a multi-purpose access-and-monetization platform rather than a single-purpose credential grabber.
The build pipeline is fully server-side: the operator configures the agent's C2 address, install path, persistence method, and evasion tier inside the panel, and the client submits that configuration to backend.thedolphinx[.]top:8443, where the binary is compiled and mutated before delivery. Nothing compiles on the operator's own machine, which both lowers the bar for less technical affiliates and complicates static-signature tracking since every build can be uniquely mutated server-side.
Collection scope spans nine Chromium/Gecko browsers, 100+ browser wallet extensions (including MetaMask), 65 desktop wallet applications (including Exodus), 10 password managers, and 30+ cloud CLI tools, in addition to SSH private keys, .env files, and general DevOps secrets — consolidated into a single exfiltration archive per victim. Browser credential theft relies on DPAPI decryption of locally stored secrets.
Defense evasion is built around a three-tier mutation engine (default disabled, top tier gated behind the PRO pricing plan): Tier 1 rewrites control flow, substitutes instructions, and re-encrypts embedded strings with a random per-build key; Tier 2 adds import-table shuffling; Tier 3 rewrites the PE timestamp, Rich header, and section padding. The malware also performs AMSI and ETW patching and issues direct syscalls to bypass user-mode API hooks, and exfiltrates over a SOCKS5 reverse-proxy channel. Persistence is achieved via Registry Run keys, the Windows Startup folder, or scheduled tasks, and the builder offers eight distinct launcher-host UAC bypass techniques for privilege escalation. Varonis notes that explorer.exe running under a non-default desktop is a strong host indicator of an active HVNC session.
The AI Profiler is the differentiating feature: rather than dumping raw stolen data on the operator, it applies a behavioral-scoring model against installed software, app usage patterns, and browsing history to rank victims by likely monetary payoff, then delivers a daily digest so lower-skilled affiliates can triage which infections to work first — effectively industrializing post-compromise victim selection for a MaaS customer base.
Pricing is tiered: Basic at roughly $80/month or $1,140 lifetime, Mid at roughly $230/month or $2,280 lifetime, and Pro at roughly $3,420 lifetime (Pro unlocking the full three-tier mutation engine; no monthly Pro rate was disclosed in reporting). Varonis catalogs the tool's total feature set at 329 discrete features organized across 10 functional categories. The tool includes a CIS-country infection-avoidance option and ships with English and Russian language support, both patterns consistent with a Russian-speaking cybercrime-forum vendor base. The vendor markets the current build as Windows-only but has publicly stated a Linux/Debian-targeting port is in development, indicating planned cross-platform expansion. No CVE, live-captured sample, or confirmed victim telemetry is available at time of publication; this record documents builder/panel capability as analyzed by Varonis (senior threat researcher Daniel Kelley, quoted as calling it probably one of the biggest stealers he has seen, covering the biggest attack surface), not observed in-the-wild exploitation.
Weaknesses (CWE)
CWE-522, CWE-311, CWE-434
Target sectors: technology, finance, cryptocurrency, software-development, government administration, health, retail, education
Target regions: Global
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1569, T1547.001, T1053.005, T1548.002, T1547.001, T1562.001, T1027, T1106, T1055