Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications — Threadlinqs Intelligence
As of 2026-07-25, Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications is a high-severity malware threat attributed to Kontraktnik, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1698 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Kontraktnik · FINANCIAL
Dolphin X is a Windows infostealer, RAT, cryptocurrency clipper, and DDoS bot sold as malware-as-a-service by the underground-forum vendor "Kontraktnik," targeting 300+ applications (browsers, crypto
Varonis Threat Labs (researcher Daniel Kelley) discovered Dolphin X after obtaining access to its operator panel, builder, and network traffic in an isolated lab. It is advertised on cybercrime forums by an alias, "Kontraktnik" (suspected Russian-speaking, panel and forum thread in English/Russian only), as an all-in-one Windows package combining an infostealer, remote access trojan, Hidden VNC (HVNC) module, cryptocurrency clipboard hijacker, SOCKS5 reverse proxy, loader, and DDoS bot. Subscription pricing runs roughly EUR69.95-$230/month across tiers, with lifetime options from $1,140 (basic) to $3,420 (pro); the sales thread has exceeded 3,000 views with at least two confirmed deals and positive buyer feedback as of late July 2026. Builds are configured via a desktop client and then compiled server-side at backend.thedolphinx[.]top:8443, a centralized choke point that also handles licensing and telemetry and lets the vendor gate a three-tier mutation engine (control-flow rewriting, instruction substitution, string re-encryption with random keys, import-table shuffling, and PE timestamp/Rich header/section-padding rewriting) behind higher-priced tiers so every compiled build is functionally unique and defeats hash/signature detection.
The credential-theft surface spans 300+ applications: 9 Chromium- and Gecko-based browsers (passwords, cookies, autofill), 100+ cryptocurrency wallet browser extensions, 65 desktop crypto wallets, 10 password managers, 30+ cloud CLI tools (AWS/Azure/GCP), plus SSH private keys, .env files, cloud access tokens, DevOps credentials, WiFi passwords, Windows Credential Manager entries, and session data for platforms such as Discord, Telegram, and Steam. A single collection run aggregates all of this into one archive, giving an operator a path from a single infected endpoint straight into an organization's cloud and CI/CD estate. Beyond credential theft, Dolphin X offers full remote-desktop control, a reverse shell, an HVNC module for covert desktop interaction (explorer.exe spawned under a non-default desktop is the primary host indicator), and a cryptocurrency clipper that silently swaps copied wallet addresses for attacker-controlled ones.
The malware's differentiator is its "AI Profiler," a surveillance tab inside the operator panel that automatically analyzes each infected machine's application usage, browsing activity, and installed software to assign a numeric risk score and set of risk factors, then emails/pushes operators a daily ranked summary. Code strings recovered from the panel binary — Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, categoryusage — confirm the profiling workflow is implemented, not just marketing copy. This lets an operator running thousands of simultaneous infections skip manual triage and jump straight to machines most likely to belong to developers, DevOps staff, finance workers, or cryptocurrency holders.
Defense evasion includes AMSI and ETW patching, eight distinct UAC-bypass techniques, direct syscalls, and process injection into browser and wallet processes; persistence is achieved via Registry Run keys/startup folder and scheduled tasks. The builder includes geofencing to avoid infecting hosts in Commonwealth of Independent States (CIS) countries, a common operational-security pattern among Russian-speaking cybercrime operators to avoid domestic prosecution. Varonis's analysis was limited to the operator panel, builder, and network traffic rather than executing a live sample, so advertised collection capabilities (and any in-the-wild infection volume) remain vendor-claimed and not independently confirmed at publication; however, confirmed forum sales indicate the tool is already in criminal hands. Varonis's core defensive guidance: get long-lived credentials off disk and out of project directories, and shift detection from file signatures (defeated by the mutation engine) to behavior — HVNC desktop-switch indicators, cloud-
Target sectors: technology, finance, cryptocurrency, softwaredevelopment, cloudservices
Target regions: Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1587.001, T1583.001, T1566.001, T1189, T1204.002, T1059, T1547.001, T1053.005, T1548.002, T1548.002