exclusive The Windows information stealer, which targets more than 300 applications, includes a new monitoring tool called AI Profiler, which ranks infected victims so scammers know who to target first.
Varonis Threat Labs has discovered a new theft and remote access Trojan (RAT) called Dolphin X that is being sold on cybercrime forums and has exclusively shared its findings. register.
Advertisements for this malware claim it can target over 300 applications and have the ability to bypass browser passwords and steal corporate credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets.
Dolphin X also promises users a very sneaky monitoring feature called AI Profiler. It scores infected users by app usage, browsing history, and installed software, and sends cybercriminals a daily summary ranking victims based on the likelihood of payback from the attack.
“Two things stand out,” said Daniel Kelly, senior threat researcher at Varonis. register. “First of all, it’s an AI profiler. This is something I’ve never seen before. And it steals a wide range of applications. And it’s not just applications. It steals everything. It steals files, credentials, cryptocurrencies. This is probably one of the biggest thieves I’ve ever seen, and it covers the biggest attack surface.”
A malware vendor using the alias “Kontraktnik” posted Dolphin X for sale and promised: “It can be used as a stealer or as an HVNC. [Hidden Virtual Network Computing]as a DDoS botnet, as a loader. ”
The crimeware currently only runs on Windows, but “we are working on Debian,” Kontraktnik claimed, adding that the malware also only supports English and Russian.
This is probably one of the biggest thieves I’ve ever seen and covers the biggest attack surface.
Kelly suspects the developer speaks Russian, and said the stealer includes an option to not infect users in Commonwealth of Independent States (CIS) countries, a common choice among Russia-based ransomware and cybercriminal organizations.
Kelly and his team obtained and analyzed the malware builder, operator panel, and its network traffic, but did not examine the malware samples. Therefore, Varonis cannot guarantee that all claims made by the Developer are true.
But “when we looked at the builder, they had everything to suggest that the feature was legitimate,” he said. “While we were not able to test the malware itself, we believe it probably met most of our expectations.”
Feedback left on forums where the malware is sold supports that analysis. As of Tuesday, the sales thread had more than 3,000 views, and Kontraktnik reportedly closed at least two confirmed deals. Both of these included positive feedback from buyers.
3-tier subscription model
In addition to over 300 eligible apps, Dolphin X’s control panel lists 329 features across 10 categories. Buyers can subscribe to one of three tiers, unlocking new features at each tier, or purchase a lifetime subscription.
A minimal subscription costs about $80 per month and buys rewrite and modification capabilities across Windows Portable Executable (PE) timestamps, rich headers, and section padding, as well as the ability to allow malware to exploit vulnerable YARA rules to evade detection and hash-based blocklists.
The middle tier advertises an import table shuffle that changes the binary import hash between builds. The top-level subsystem (approximately $230 per month) rewrites the control flow of the code, replacing instructions and re-encrypting the embedded string with a new random key each time, which it claims makes it difficult to identify stable byte sequences.
Lifetime subscriptions cost approximately $1,140 for basic access, $2,280 for mid-tier malware, and $3,420 for permanent pro-level Pwnage.
“This really lowers the barrier to entry,” Kelly said, adding that in the not-so-distant past, cybercriminals needed a certain level of technical expertise to develop and use different types of malware. “Right now, it’s more like a SaaS. Anyone can buy it. Anyone can take it out of the package and use it.”
According to the guard, all of this suggests two takeaways for defenders. First, if possible, store long-lived credentials off-disk. “Infostealers are designed to retrieve everything in one pass, so anything stored locally should be treated as potentially compromised,” the report warns.
Anyone can purchase. Anyone can take it out of the package and use it.
Second: This and other malware include the ability to bypass signature-based detection, so threat detection focuses on file behavior rather than file signatures. “For example, explorer.exe running on a non-default desktop is a strong indicator of an HVNC session, regardless of how the malware binary is packed or the hashes used,” the authors write.
Varonis threat hunters have previously discovered other AI-powered malware, including an all-in-one phishing kit called Bluekit and an email attack tool called SpamGPT.
“This is a big trend,” Kelly said. “Cybercriminals have found many unique ways to integrate AI and use it to make their lives much easier, but there are problems with this.” ®
