Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel

Dolphin X Windows Infostealer Adds AI-Driven Victim (TL-2026-1695) is a high-severity malware campaign, first published 2026-07-22. It is attributed to Kontraktnik (Russia) with low confidence, affects Microsoft Windows (desktop and server), maps to 22 MITRE ATT&CK techniques (T1005, T1010, T1027), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-1695

Threat ID
TL-2026-1695
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kontraktnik
Attribution confidence
LOW
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
technology, softwaredevelopment, finance, cryptocurrency
Target regions
Global (CIS countries excluded via built-in geofencing option)
Detection rules
9
Indicators of compromise
17

Malware and tooling in Dolphin X Windows Infostealer Adds AI-Driven Victim

Malware and tooling: Dolphin X, Dolphin X AI Profiler, Dolphin X DDoS Botnet Module, Dolphin X Loader Module, Dolphin X Polymorphic Mutation Engine

Dolphin X is a Windows infostealer/RAT/HVNC/DDoS-loader sold as malware-as-a-service by cybercrime-forum vendor "Kontraktnik," harvesting credentials from 300+ applications (9 browsers, 100+ wallet extensions, 65 desktop wallets, 10 password managers, 30 cloud CLI tools) plus SSH keys, .env files, and cloud tokens. Its 329-feature operator panel includes an AI behavioral profiler that risk-scores victims to flag high-value hosts (cloud CLI, IDE, admin-console access) for follow-on exploitation, plus an opt-in three-tier polymorphic build-mutation engine and multiple defense-evasion techniques (AMSI/ETW patching, direct syscalls, UAC bypass) for detection evasion.

How Dolphin X Windows Infostealer Adds AI-Driven Victim works

Dolphin X is a Windows-focused credential-stealer, remote access trojan, Hidden-VNC (HVNC) tool, DDoS-capable botnet client, and secondary-payload loader offered as a subscription malware-as-a-service (MaaS) product. It is advertised on a cybercrime forum by a vendor using the handle "Kontraktnik," who markets it as an all-in-one stealer/RAT with 329 discrete features spread across ten operator-panel categories. Varonis Threat Labs researcher Daniel Kelley obtained access to the operator panel, builder, and its network traffic in an isolated lab and published the first technical analysis on 2026-07-22; broader trade-press coverage followed on 2026-07-22/23 (The Register, GBHackers, BleepingComputer, Hackread, CyberInsider, SOCPrime, Infosecurity Magazine).

The credential-looter module alone claims over 300 application targets: nine Chromium/Gecko browsers, more than 100 cryptocurrency wallet browser extensions, 65 desktop cryptocurrency wallets, 10 password managers, and 30 cloud command-line tools, plus generic theft of SSH private keys, `.env` files, and cloud/DevOps access tokens.

The operator panel's standout feature is an "AI Profiler" (panel strings include `Auto-Start AI Profiler`, `ProfilerStart`, `ProfilerGetData`, `risk_score`, `risk_factors`, `categoryusage`) that tracks victim application usage, browsing activity, and installed software to compute a per-victim risk score and deliver daily-ranked summaries to the operator. This lets an attacker running a large botnet skip manual triage and jump straight to hosts flagged as developer workstations, cryptocurrency holders, or other high-value targets with cloud CLI, IDE, or admin-console access. Varonis could not determine what underlying AI/ML engine drives the scoring without a live malware sample, since analysis was limited to the panel and builder.

Evasion is delivered through an opt-in, disabled-by-default, three-tier polymorphic mutation engine gated by subscription level: the basic tier rewrites PE timestamps, the Rich header, and section padding to defeat brittle YARA rules and hash blocklists; the mid tier additionally shuffles the import table to change the binary's import hash between builds; the top (Pro) tier adds control-flow rewriting, instruction substitution, and re-encryption of embedded strings with a fresh key per build to defeat stable byte-sequence signatures. Builds are not compiled locally — operators configure C2 endpoint, install path, persistence, and evasion options in a desktop client, submit the configuration to `backend.thedolphinx.top:8443`, and the vendor's backend compiles and returns the finished Windows executable, letting the vendor mutate every sample before delivery.

Additional documented capabilities include Hidden-VNC (HVNC) hands-on-keyboard remote access (observable as `explorer.exe` instances running under non-default desktops), a DDoS botnet function, and a loader function for staging secondary payloads. Defense-evasion and privilege-escalation features include AMSI bypass via in-memory patching of `AmsiScanBuffer`, ETW patching, direct syscalls to bypass user-mode API hooks, and eight distinct launcher-host UAC-bypass techniques. Persistence is achieved via registry Run keys/Startup folder or scheduled tasks, and C2/egress traffic can be tunneled through a built-in SOCKS5 proxy.

Pricing is tiered: monthly subscriptions run roughly $80 (basic) to $230 (mid), with lifetime options at $1,140 (basic), $2,280 (mid), and $3,420 (Pro); the Pro tier is required to unlock the top mutation tier. The panel supports English and Russian, and includes a built-in option to exclude CIS-country systems from infection — a common feature in Russian-speaking cybercrime tooling used to avoid domestic law-enforcement attention. As of the July 2026 reporting window, the forum listing had accrued 3,000+ views and at least two confirmed sales with positive buyer feedback; Linux/Debian support is advertised as planned but not yet shipped.

MITRE ATT&CK techniques used in TL-2026-1695

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Discovery

T1010 Application Window Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Execution

T1106 Native API

Impact

T1498 Network Denial of Service

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Dolphin X Windows Infostealer Adds AI-Driven Victim

  • Microsoft — Windows (desktop and server)
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016-2022
  • Various — Web browsers (9 Chromium/Gecko-based browsers targeted)
    Vulnerable versions: all versions with stored credentials
  • Various — Cryptocurrency wallet browser extensions (100+ targeted)
    Vulnerable versions: all
  • Various — Desktop cryptocurrency wallets (65 targeted)
    Vulnerable versions: all
  • Various — Password managers (10 targeted)
    Vulnerable versions: all
  • Various — Cloud CLI tools (30+ targeted, e.g. AWS/Azure/GCP CLIs)
    Vulnerable versions: all

Remediation for Dolphin X Windows Infostealer Adds AI-Driven Victim

Immediate actions

  • Block/sinkhole DNS and egress to thedolphinx.top and backend.thedolphinx.top:8443 at the perimeter and via DNS security controls
  • Hunt for explorer.exe processes running under non-default desktops, a behavioral indicator of Dolphin X's HVNC hidden-desktop remote-control activity
  • Isolate and rebuild (do not just clean) any host suspected of Dolphin X infection given the DDoS/loader/HVNC capabilities
  • Rotate all credentials reachable from a suspected host: browser-saved passwords, password-manager vaults, cryptocurrency wallet keys, SSH private keys, cloud CLI/API tokens, and secrets in .env files

Workarounds

  • Restrict outbound TCP/8443 to known-good destinations to disrupt the vendor's licensing/telemetry/remote-build channel
  • Enable browser and password-manager extension allowlisting/hardening to reduce the attack surface for the 100+ wallet extensions and 10 password managers Dolphin X targets

Longer-term hardening

  • Shift endpoint detection from static hash/signature matching to behavioral analytics, since the built-in polymorphic mutation engine is designed specifically to defeat hash blocklists and brittle YARA rules
  • Instrument EDR for AMSI/ETW-tamper detection (in-memory AmsiScanBuffer patching, ETW patching) and anomalous direct-syscall usage
  • Eliminate long-lived plaintext credentials from disk, especially SSH keys and secrets stored in project directories (.env files), which Dolphin X specifically targets
  • Move cloud/DevOps authentication to short-lived, scoped tokens instead of long-lived static CLI credentials to reduce blast radius if a developer workstation is compromised
  • Enforce application allowlisting and restrict local admin rights to reduce the impact of the malware's eight documented UAC-bypass techniques

Weaknesses (CWE) in Dolphin X Windows Infostealer Adds AI-Driven Victim

CWE-522, CWE-312, CWE-798

Timeline of Dolphin X Windows Infostealer Adds AI-Driven Victim

  • The Register publishes "Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits," the first same-day trade-press pickup of the Varonis findings.
  • Kontraktnik's cybercrime-forum listing for Dolphin X is observed by Varonis with 3,000+ views and at least two confirmed sales with positive buyer feedback as of the reporting window, indicating the listing predates the public research by an unspecified interval.
  • Varonis Threat Labs researcher Daniel Kelley publishes the primary technical analysis of Dolphin X ("Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI") after obtaining access to the operator panel, builder, and network traffic in an isolated lab environment; the analysis is the sourcing basis for every subsequent trade-press article.
  • Cyber Security News's Tushar Subhra Dutta publishes "New Dolphin X Malware Steals Credentials From 300+ Apps and Profiles Victims With AI," independently tabulating the published IOCs (thedolphinx.top, backend.thedolphinx.top:8443, and the panel-client SHA-256) and proposing supplementary MITRE ATT&CK mappings for the profiler/persistence behaviors.
  • Infosecurity Magazine publishes "New Dolphin X Stealer Employs AI Profiling to Prioritize Targets," reiterating defender guidance to avoid long-lived local credentials and prioritize behavioral over signature-based detection.
  • CyberInsider's Amar Ćemanović publishes "New Dolphin X infostealer uses AI to identify high-value victims," covering the server-side mutation engine and cloud-based build system.
  • GBHackers publishes "Windows Stealer Uses AI Profiling to Score Victims and Prioritize High-Value Targets," the source feed article that triggered this hunt.
  • SOC Prime republishes the Varonis findings as an active-threat bulletin, adding detection-engineering guidance: prioritize behavioral detection over file-based signatures, harden access controls on cloud consoles/build pipelines, and hunt for explorer.exe running under non-default desktops.
  • BleepingComputer's Lawrence Abrams publishes "New Dolphin X malware uses AI to rank high-value targets" at 5:20 PM ET, reporting on the 329-feature operator panel, credential-theft scope, and defense-evasion techniques (AMSI/ETW patching, direct syscalls, UAC bypass).
  • Hackread's Waqas publishes "New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims," the last dated wave of independent trade-press pickup, describing the paid mutation options as a hash-based-detection evasion mechanism.
  • TL-Intel-Harness RESEARCH phase completes deep-dive analysis, MITRE ATT&CK mapping, and IOC extraction for TL-2026-1695.

Sources cited for Dolphin X Windows Infostealer Adds AI-Driven Victim

Threats related to Dolphin X Windows Infostealer Adds AI-Driven Victim

Detection coverage for TL-2026-1695

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1695 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats