-
Threats detected: Varonis Threat Labs researcher Daniel Kelley discovered Dolphin X, a Windows stealer and RAT sold by the vendor under the alias “Kontraktnik.”
-
Huge range: The malware targets over 300 applications, including browsers, crypto wallets, SSH keys, .env files, and cloud tokens.
-
AI profiling: “AI Profiler” scores infected users to help attackers prioritize high-value victims.
A new Windows Stealer and Remote Access Trojan (RAT) is being promoted on cybercrime forums by a vendor operating under the alias ‘Kontraktnik’ and is being sold as a multi-purpose malware. Users advertise that it can be used as a stealer or as HVNC. [Hidden Virtual Network Computing]as a DDoS botnet, and as a loader.
Varonis Threat Labs discovered Dolphin X malware that goes far beyond browser passwords to harvest credentials across an enterprise’s attack surface.
Dolphin X targets over 300 applications
According to the listing, Dolphin A single archive can contain data retrieved from:
- 9 browsers,
- Over 100 wallet extensions,
- 65 desktop wallet,
- 10 password managers,
- 30 cloud command line tools.
On developer machines, long-lived credentials in .env files and SSH directories allow you to expose cloud consoles, build pipelines, and production data in one pass.
AI profiler ranks high-value victims
Dolphin X includes an “AI profiler” that scores infected users based on application usage, browsing activity, and installed software. Attackers receive rankings in a daily summary and can filter through thousands of infected machines to focus on the most valuable targets first.
Server-side changes and 329 features
The operator panel lists 329 functions across 10 categories. Clients send build configurations rather than compiling locally. Backend.The Dolphinx[.]Top:8443Meanwhile, the operator configures the agent’s C2 address, installation path, persistence, and evasion options. Routing all builds through the vendor’s servers allows you to modify each binary before it is returned.
”This is probably one of the biggest thieves I’ve ever seen and covers the biggest attack surface.“Senior threat researcher Daniel Kelly told The Register. He said the AI Profiler feature was his.”never seen before“With this kind of information thief.
Kelly told the builder:It had everything to suggest that the feature was legitimate.“And that is.”probably meets most of its expectations. ”
Last week, it was reported that fake NVIDIA software distributed new LabubaRAT malware that hijacks Windows PCs.
