Varonis Threat Labs reported that Dolphin X, a Windows information stealer and remote-access trojan sold on a cybercrime forum by the actor "Kontraktnik," is designed to harvest data from more than 300 applications. Advertised targets include browser passwords, enterprise credentials, cryptocurrency wallets, password managers, .env files, SSH keys, cloud tokens, and other DevOps secrets, creating risk for both personal accounts and corporate cloud environments. Researchers said the malware is offered in multiple subscription tiers and appears tailored for broad credential theft rather than simple consumer-focused infostealing.
The operation stands out for an "AI Profiler" in its operator panel that scores infected users by likely value based on installed software, browsing activity, and application usage, helping criminals prioritize the most profitable victims. Varonis also found that builds are compiled remotely through backend.thedolphinx[.]top:8443 and can use mutation features such as PE rewriting, import-table shuffling, control-flow rewriting, and string re-encryption to frustrate signature-based detection. While the researchers analyzed the builder, panel, and network traffic rather than a live malware sample, they assessed many of the advertised capabilities as credible and advised defenders to reduce long-lived credentials stored on disk and rely more heavily on behavior-based detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Varonis publicly disclosed that Dolphin X includes an "AI Profiler" to rank infected users by likely value and is designed to steal browser passwords, enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets. The disclosure highlighted anti-detection features such as binary mutation and code rewriting intended to evade signature-based defenses.
Varonis Threat Labs analyzed Dolphin X through its builder, operator panel, and network traffic rather than a live malware sample. The researchers identified remote build infrastructure at backend.thedolphinx[.]top:8443 and assessed that many of the malware's advertised capabilities appeared legitimate.
Varonis reported that the Windows infostealer and RAT Dolphin X was being sold on a cybercrime forum by a seller using the alias "Kontraktnik." The malware was marketed in subscription tiers and advertised theft capabilities against more than 300 applications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcevaronis.com
Open sourcetheregister.com
Open sourcevaronis.com
Open sourcevaronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.