New Dolphin X malware uses AI to rank high-value targets

Applications of AI


cyber dolphin

The new Dolphin X remote access Trojan claims to use AI-powered profiling capabilities to score and rank infected users, helping cybercriminals identify which victims to target first.

This malware was analyzed by researcher Daniel Kelley from Varonis Threat Labs. He found the malware being advertised on cybercrime forums using the alias “Kontraktnik” and being promoted as an all-in-one remote access Trojan.

Varonis said the operator panel lists 329 features across 10 categories, including a credential-stealing feature that claims to target more than 300 applications.

image

However, one notable feature is its “AI Profiler,” which analyzes information collected from infected computers and assigns a risk score to each victim.

“Aside from collecting credentials, the panel includes a monitoring tab with an AI profiler, which the seller describes as an ‘AI behavioral profiler with app usage tracking, risk scores, and daily summaries,’” Varonis explains.

Varonis obtained a Dolphin X operator panel and analyzed it in an isolated lab, noting that it inspected the malware builder and its network traffic rather than running a live Dolphin

AI Profiler ranks victims against attackers

Credential-stealing malware allows attackers to steal credentials for hundreds, if not thousands, of online accounts, making it difficult to manually review every account for high-value targets.

Dolphin

Operator Panel claims that its AI profiler can process victims’ application usage, risk scores and tags, browser domains, and installed software to generate ranked profiles.

Operator panel showing AI Profiler options
Operator panel showing AI Profiler options
Source: Varonis

These scores are given to attackers in a daily overview that includes ranked victim profiles, allowing them to prioritize machines that are likely to provide access to valuable accounts, cryptocurrencies, corporate networks, cloud environments, or production systems.

“In reality, this feature appears to be designed to help operators triage victims,” ​​Kelly explains.

Varonis researcher Daniel Kelley confirmed to BleepingComputer that AI Profiler is present in the Operator Panel and discovered the following technical strings to support the profiling workflow: Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factorsand categoryusage.

The researchers said these strings indicate that a profiling workflow is indeed involved, and that the panel is able to process the data needed to rank victims.

However, Varonis could not determine what artificial intelligence engine was used to create the rankings without analyzing live Dolphin X malware samples.

The malware also acts as a credential stealer, with its operator panel showing targeting over 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and over 30 cloud command-line tools.

Dolphin X also claims theft. .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials.

Because Varonis analyzed the Dolphin

Artificial intelligence has become a popular tool among threat actors and is being used to launch cybercrime services such as SpamGPT and AI agents that carry out autonomous cyberattacks.

Instead, the Dolphin X platform uses AI to solve operational problems by processing large amounts of stolen data and automatically classifying infected users into the highest-value victims.

Article image

Security teams document 54% of successful attacks and issue a warning on only 14%. The rest moves invisibly through the environment.

Picus’ whitepaper shows how to test your SIEM and EDR rules in breach and attack simulations to ensure threats go undetected.

Get the white paper



Source link