Dolphin X Windows infostealer and RAT with AI victim profiling
Malware Activity
Summary
Hide ▲
Show ▼
Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher-value victims. Varonis Threat Labs researcher Daniel Kelley found the malware advertised on a cybercrime forum by Kontraktnik and analyzed the operator panel, builder, and network traffic rather than a live infected-machine sample. The panel claims 329 features across ten categories and credential theft from more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools. It also claims to collect .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials, with daily summaries of ranked victim profiles guiding attacker triage.
Related Happenings
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware Activity
H score31
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal ...
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware ActivityAbout this happening: OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal ...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Vidar infostealer market rise and distribution expansion
Malware Activity
H score30
First: 28.04.2026 22:07
Last: 28.04.2026 22:07
Sources 1
About this happening:
Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Vidar infostealer market rise and distribution expansion
Malware ActivityAbout this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
VENON Rust-based banking malware targeting Brazilian Windows users
Malware Activity
H score20
First: 12.03.2026 19:31
Last: 12.03.2026 19:31
Sources 1
About this happening:
Researchers disclosed VENON, a new Rust-based banking malware aimed at Brazilian Windows users, raising the risk of credential theft through fake banking overlays....
VENON Rust-based banking malware targeting Brazilian Windows users
Malware ActivityAbout this happening: Researchers disclosed VENON, a new Rust-based banking malware aimed at Brazilian Windows users, raising the risk of credential theft through fake banking overlays....
Timeline
-
23.07.2026 13:19 3 articles · 13d ago
Varonis identifies Dolphin X Windows infostealer with AI victim scoring
Initial DisclosureVaronis Threat Labs identified Dolphin X as a newly discovered Windows infostealer and RAT, and found that its AI Profiler scores infected users using application usage, browsing activity, and installed software to help attackers focus on higher-value victims. The malware is advertised on a cybercrime forum, targets more than 300 applications, and steals cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps credentials; Varonis also observed an operator panel that assigns victim scores and sends daily ranking summaries.
Show sources
- New Dolphin X Stealer Employs AI Profiling to Prioritize Targets — www.infosecurity-magazine.com — 23.07.2026 13:19
- New Dolphin X Stealer Employs AI Profiling to Prioritize Targets — www.infosecurity-magazine.com — 23.07.2026 13:19
- New Dolphin X malware uses AI to rank high-value targets — www.bleepingcomputer.com — 24.07.2026 00:20