A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias "Kontraktnik," promoting it as an all-in-one remote access trojan.
According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications.
However, one of its notable features is an "AI Profiler" that analyzes information collected from infected computers and assigns each victim a risk score.
"Beyond credential collection, the panel includes a surveillance tab containing the AI Profiler. The seller describes it as an 'AI behavioral profiler with app usage tracking, risk score, and daily summary,'" explains Varonis.
Varonis obtained the Dolphin X operator panel and analyzed it in an isolated lab, noting they examined the malware builder and its network traffic rather than executing a live Dolphin X agent on an infected computer.
AI Profiler ranks victims for attackers
Credential-stealing malware can allow attackers to steal credentials for hundreds, if not thousands, of online accounts, making it difficult to manually review them all for high-value targets.
Dolphin X’s AI Profiler claims to automate this process by acting as a sorting system that scores, categorizes, and ranks infected computers so that the attackers know which are the most high-value to target further.
The operator panel claims that the AI Profiler can process victims’ application usage, risk scores and tags, browser domains, and installed software to produce ranked profiles.
These scores are given to attackers in daily summaries containing ranked victim profiles, allowing them to prioritize machines that may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems.
"In practice, the feature appears designed to help operators triage victims," explains Kelley.
Varonis researcher Daniel Kelley confirmed to BleepingComputer that the AI Profiler is present in the operator panel and discovered technical strings supporting the profiling workflow, including Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage.
The researcher said these strings indicate that the profiling workflow is actually included and that the panel can process the data needed to rank victims.
However, Varonis could not determine what artificial intelligence engine is being used to produce the rankings without analyzing a live Dolphin X malware sample.
The malware also operates as a credential stealer, with the operator panel showing that it targets more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools.
Dolphin X also claims to steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials.
As Varonis analyzed the Dolphin X operator panel, builder, and related network traffic rather than a live malware sample executing on an infected machine, the malware’s advertised collection capabilities were not independently confirmed by the researcher.
Artificial intelligence has become a popular tool among threat actors, with it being used to launch cybercrime services such as SpamGPT and AI agents conducting autonomous cyberattacks.
Dolphin X platform instead uses AI to solve an operational problem by processing large amounts of stolen data and automatically sorting infected users into highest-value victims.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get the whitepaper