Find notable cyber news and cases, enriched with sources, timelines, and signals.

Dolphin X Windows infostealer and RAT with AI victim profiling

Malware Activity
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher-value victims. Varonis Threat Labs researcher Daniel Kelley found the malware advertised on a cybercrime forum by Kontraktnik and analyzed the operator panel, builder, and network traffic rather than a live infected-machine sample. The panel claims 329 features across ten categories and credential theft from more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools. It also claims to collect .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials, with daily summaries of ranked victim profiles guiding attacker triage.

Related Happenings

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
H score31 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal ...

Y2K Operators Millenium RAT social-engineering distribution campaign

Campaign
H score73 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

About this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...

Venom Stealer MaaS continuous credential theft and exfiltration

Malware Activity
H score29 First: 01.04.2026 16:30 Last: 01.04.2026 16:30 Sources 1

About this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...

VENON Rust-based banking malware targeting Brazilian Windows users

Malware Activity
H score20 First: 12.03.2026 19:31 Last: 12.03.2026 19:31 Sources 1

About this happening: Researchers disclosed VENON, a new Rust-based banking malware aimed at Brazilian Windows users, raising the risk of credential theft through fake banking overlays....

Timeline

  1. 23.07.2026 13:19 3 articles · 13d ago

    Varonis identifies Dolphin X Windows infostealer with AI victim scoring

    Initial Disclosure

    Varonis Threat Labs identified Dolphin X as a newly discovered Windows infostealer and RAT, and found that its AI Profiler scores infected users using application usage, browsing activity, and installed software to help attackers focus on higher-value victims. The malware is advertised on a cybercrime forum, targets more than 300 applications, and steals cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps credentials; Varonis also observed an operator panel that assigns victim scores and sends daily ranking summaries.

    Show sources