Dolphin X: AI-Powered Windows Infostealer/RAT Uses Behavioral Profiling to Prioritize High-Value Victims — Threadlinqs Intelligence
As of 2026-07-24, Dolphin X: AI-Powered Windows Infostealer/RAT Uses Behavioral Profiling to Prioritize High-Value Victims is a high-severity malware threat attributed to Kontraktnik, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1672 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Kontraktnik · FINANCIAL
Varonis Threat Labs uncovered Dolphin X, a Windows infostealer and RAT advertised by the vendor "Kontraktnik" on a cybercrime forum, that targets 300+ applications (browsers, crypto wallets, password
Dolphin X is a Windows-based information stealer and remote access trojan (RAT) first publicly disclosed by Varonis Threat Labs on 2026-07-22/23 and advertised on a cybercrime forum by a vendor operating under the alias "Kontraktnik." Varonis analyzed the malware builder, the operator/command panel, and observed network traffic in an isolated lab; no live-infection sample was examined, and the underlying binary loader was not fully reverse engineered by the time of publication.
The stealer's headline capability is an integrated "AI Profiler": after exfiltrating data, the panel automatically scores each infected host using signals such as installed software, browsing activity, and application usage, then generates ranked daily summaries. This lets an operator managing thousands of simultaneous infections quickly triage which machines belong to developers, cryptocurrency holders, or otherwise carry high-value access, rather than manually sifting through raw stealer logs.
Dolphin X targets more than 300 applications across ten panel categories, including 9 Chromium- and Gecko-based browsers, 100+ cryptocurrency wallet browser extensions, 65 desktop cryptocurrency wallets (including MetaMask via PBKDF2-derived key extraction and Exodus via Windows DPAPI abuse), 10 password managers, and 30+ cloud CLI tools, alongside SSH private keys and .env files carrying DevOps and cloud secrets. Varonis researcher Daniel Kelley characterized it as "probably one of the biggest stealers" the team has analyzed by target-application breadth. Because the stealer explicitly hunts SSH keys, cloud CLI tokens, and .env DevOps credentials, an infection on a single developer workstation can cascade into full production-environment compromise.
Delivery is not fully documented in public reporting, but the build model is notable: rather than compiling payloads locally, the operator submits a build configuration to a vendor-controlled backend (backend.thedolphinx[.]top:8443), which compiles the binary server-side. This keeps mutation and obfuscation logic under vendor control and lets Kontraktnik gate stronger evasion behind paid tiers. An opt-in, three-tier mutation engine progressively adds: (1) control-flow rewriting, instruction substitution, and re-encryption of embedded strings with a fresh key per build; (2) import-table shuffling to change the import hash between builds; and (3) PE timestamp rewriting, Rich header modification, and section padding alteration — explicitly marketed to defeat YARA rules and hash-based blocklists.
Beyond credential theft, the panel advertises the payload can also function as a Hidden VNC (HVNC) tool, a DDoS botnet node, and a generic loader. Persistence is achieved via Registry Run keys/Startup folder entries and Scheduled Tasks. Reported defense-evasion behavior includes AMSI/ETW patching, direct syscalls to bypass user-mode API hooking, eight distinct UAC-bypass methods, and process injection into browser/wallet processes to intercept in-memory credential material. Collected data (browser-stored passwords via DPAPI decryption, password-manager vaults, wallet files, SSH keys, .env secrets, cloud tokens) is bundled into a single archive for exfiltration. The malware also supports a SOCKS5 reverse-proxy C2 channel for interactive access to compromised hosts.
Commercially, Dolphin X is sold as malware-as-a-service via monthly subscriptions (~$80/month basic, ~$230/month mid-tier) and lifetime licenses ($1,140 basic / $2,280 mid / $3,420 pro), with the mutation-engine tiers and additional features gated by plan. The vendor's forum listing had drawn 3,000+ views and at least two confirmed sales as of 2026-07-22. Indicators suggest a Russian-speaking developer: the panel supports only English and Russian, and the malware's targeting logic is reported to explicitly avoid infecting hosts geolocated to CIS (Commonwealth of Independent States) countries — a common operational-security pattern intended to avoid prosecution ri
Target sectors: technology, softwaredevelopment, finance, cryptocurrency, managedserviceproviders, cloudservices
Target regions: Global, North America, Europe, Asia Pacific
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1587, T1583, T1547, T1053, T1548, T1685, T1027, T1106, T1055, T1036