Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
Security researchers at Varonis Threat Labs have discovered a new Windows information-stealer and remote access trojan called Dolphin X being sold on a cybercrime forum, featuring an unusual "AI Profiler" tool that ranks infected victims by their likely payoff so criminals know whom to target first. Researchers describe it as one of the broadest stealers they have seen, capable of targeting over 300 applications and harvesting a huge range of data, from browser passwords to cryptocurrency wallets and cloud credentials, making it a significant new threat for both individuals and enterprises.
The malware, advertised by a vendor going by "Kontraktnik", can also function as an HVNC tool, DDoS botnet or loader, and its operator panel lists 329 features across 10 categories offered through a three-tier subscription model starting at roughly $80 a month, with lifetime options available. Varonis analysed the builder and operator panel but not a live sample, though positive buyer feedback and over 3,000 views on the sales thread suggest it is functional; researcher Daniel Kelley believes the developer is likely Russian-speaking, noting the malware includes an option to avoid infecting users in Commonwealth of Independent States countries, a common feature among Russia-based cybercrime tools.
- New Dolphin X malware steals data from 300+ Windows applications.
- Unique "AI Profiler" ranks victims by likely criminal profit.
- Sold via forum with tiered subscriptions from about $80/month.