Dolphin X RAT Leverages AI for Victim Prioritization and Credential Theft
A new remote access trojan (RAT), **Dolphin X**, is making waves in cybercrime forums, boasting an 'AI Profiler' feature designed to score and rank infected users. This sophisticated malware aims to streamline victim selection for threat actors, enabling them to prioritize high-value targets based on stolen data and system analysis.
A new remote access trojan (RAT) dubbed **Dolphin X** is being advertised on cybercrime forums, claiming to incorporate an AI-powered profiling feature. This functionality is designed to score and rank infected users, helping cybercriminals identify and prioritize high-value victims.
The malware was brought to light by **Varonis Threat Labs** researcher **Daniel Kelley**, who observed it being promoted by a vendor operating under the alias "Kontraktnik." The vendor markets **Dolphin X** as an all-in-one remote access trojan.
According to **Varonis**, the operator panel for **Dolphin X** lists an extensive 329 features across ten categories. This includes a robust credential-stealing capability that reportedly targets over 300 applications.
### AI Profiler: Automating Victim Prioritization
One of the most notable features of **Dolphin X** is its "AI Profiler." This component analyzes information gathered from compromised machines and assigns each victim a 'risk score'.
"Beyond credential collection, the panel includes a surveillance tab containing the AI Profiler. The seller describes it as an 'AI behavioral profiler with app usage tracking, risk score, and daily summary,'" **Varonis** explains.
**Varonis** obtained and analyzed the **Dolphin X** operator panel in an isolated lab environment. Their investigation focused on the malware builder and its network traffic, rather than executing a live **Dolphin X** agent.
Credential-stealing malware often yields vast amounts of data, making it challenging for attackers to manually sift through hundreds or thousands of accounts to pinpoint valuable targets. **Dolphin X**'s AI Profiler claims to automate this process, acting as a sophisticated sorting system.

*Source: Varonis*
The operator panel indicates that the AI Profiler can process data points such as victimsβ application usage, risk scores and tags, browser domains, and installed software to generate ranked profiles.
These scores are compiled into daily summaries for attackers, providing them with ranked victim profiles. This allows threat actors to prioritize machines that might offer access to high-value accounts, cryptocurrency, corporate networks, cloud environments, or production systems.
"In practice, the feature appears designed to help operators triage victims," explains **Kelley**.
**Varonis** researcher **Daniel Kelley** confirmed the presence of the AI Profiler in the operator panel and identified technical strings supporting its workflow, including `Auto-Start AI Profiler`, `ProfilerStart`, `ProfilerGetData`, `risk_score`, `risk_factors`, and `categoryusage`. These strings suggest that the profiling workflow is indeed integrated, and the panel is equipped to process the necessary data for victim ranking.
However, without analyzing a live **Dolphin X** malware sample, **Varonis** could not ascertain the specific artificial intelligence engine used to generate these rankings.
### Extensive Credential Theft Capabilities
Beyond its profiling features, **Dolphin X** also functions as a potent credential stealer. The operator panel indicates it targets over 300 applications, including:
* 9 Chromium and Gecko browsers
* 100 cryptocurrency wallet extensions
* 65 desktop crypto wallets
* 10 password managers
* More than 30 cloud command-line tools
**Dolphin X** also claims to steal `.env` files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials.
It is important to note that since **Varonis**'s analysis focused on the **Dolphin X** operator panel, builder, and network traffic rather than a live malware sample, the full extent of the advertised collection capabilities was not independently confirmed by the researchers.
Artificial intelligence is increasingly being adopted by threat actors. Examples include cybercrime services like **SpamGPT** and the use of AI agents for autonomous cyberattacks. The **Dolphin X** platform, however, innovates by employing AI to solve an operational challenge: efficiently processing large volumes of stolen data to automatically sort and identify the most valuable victims.