Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel — Threadlinqs Intelligence
As of 2026-07-25, Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel is a high-severity malware threat attributed to Kontraktnik (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1695 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Kontraktnik · Russia · FINANCIAL
Dolphin X is a Windows infostealer/RAT/HVNC/DDoS-loader sold as malware-as-a-service by cybercrime-forum vendor "Kontraktnik," harvesting credentials from 300+ applications (9 browsers, 100+ wallet
Dolphin X is a Windows-focused credential-stealer, remote access trojan, Hidden-VNC (HVNC) tool, DDoS-capable botnet client, and secondary-payload loader offered as a subscription malware-as-a-service (MaaS) product. It is advertised on a cybercrime forum by a vendor using the handle "Kontraktnik," who markets it as an all-in-one stealer/RAT with 329 discrete features spread across ten operator-panel categories. Varonis Threat Labs researcher Daniel Kelley obtained access to the operator panel, builder, and its network traffic in an isolated lab and published the first technical analysis on 2026-07-22; broader trade-press coverage followed on 2026-07-22/23 (The Register, GBHackers, BleepingComputer, Hackread, CyberInsider, SOCPrime, Infosecurity Magazine).
The credential-looter module alone claims over 300 application targets: nine Chromium/Gecko browsers, more than 100 cryptocurrency wallet browser extensions, 65 desktop cryptocurrency wallets, 10 password managers, and 30 cloud command-line tools, plus generic theft of SSH private keys, `.env` files, and cloud/DevOps access tokens.
The operator panel's standout feature is an "AI Profiler" (panel strings include `Auto-Start AI Profiler`, `ProfilerStart`, `ProfilerGetData`, `risk_score`, `risk_factors`, `categoryusage`) that tracks victim application usage, browsing activity, and installed software to compute a per-victim risk score and deliver daily-ranked summaries to the operator. This lets an attacker running a large botnet skip manual triage and jump straight to hosts flagged as developer workstations, cryptocurrency holders, or other high-value targets with cloud CLI, IDE, or admin-console access. Varonis could not determine what underlying AI/ML engine drives the scoring without a live malware sample, since analysis was limited to the panel and builder.
Evasion is delivered through an opt-in, disabled-by-default, three-tier polymorphic mutation engine gated by subscription level: the basic tier rewrites PE timestamps, the Rich header, and section padding to defeat brittle YARA rules and hash blocklists; the mid tier additionally shuffles the import table to change the binary's import hash between builds; the top (Pro) tier adds control-flow rewriting, instruction substitution, and re-encryption of embedded strings with a fresh key per build to defeat stable byte-sequence signatures. Builds are not compiled locally — operators configure C2 endpoint, install path, persistence, and evasion options in a desktop client, submit the configuration to `backend.thedolphinx.top:8443`, and the vendor's backend compiles and returns the finished Windows executable, letting the vendor mutate every sample before delivery.
Additional documented capabilities include Hidden-VNC (HVNC) hands-on-keyboard remote access (observable as `explorer.exe` instances running under non-default desktops), a DDoS botnet function, and a loader function for staging secondary payloads. Defense-evasion and privilege-escalation features include AMSI bypass via in-memory patching of `AmsiScanBuffer`, ETW patching, direct syscalls to bypass user-mode API hooks, and eight distinct launcher-host UAC-bypass techniques. Persistence is achieved via registry Run keys/Startup folder or scheduled tasks, and C2/egress traffic can be tunneled through a built-in SOCKS5 proxy.
Pricing is tiered: monthly subscriptions run roughly $80 (basic) to $230 (mid), with lifetime options at $1,140 (basic), $2,280 (mid), and $3,420 (Pro); the Pro tier is required to unlock the top mutation tier. The panel supports English and Russian, and includes a built-in option to exclude CIS-country systems from infection — a common feature in Russian-speaking cybercrime tooling used to avoid domestic law-enforcement attention. As of the July 2026 reporting window, the forum listing had accrued 3,000+ views and at least two confirmed sales with positive buyer feedback; Linux/Debian support is advertised as planned but not yet shipped.
Weaknesses (CWE)
CWE-522, CWE-312, CWE-798
Target sectors: technology, softwaredevelopment, finance, cryptocurrency
Target regions: Global (CIS countries excluded via built-in geofencing option)
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1106, T1547, T1053, T1548, T1562, T1027, T1070, T1036, T1055, T1555