Dolphin X Malware Targets 300+ Apps, Uses AI for Victim Profiling

A newly identified Windows malware, Dolphin X, is raising significant concerns due to its extensive data theft capabilities and advanced profiling features. Marketed as both an information stealer and a remote access trojan (RAT), Dolphin X provides cybercriminals with a comprehensive toolkit to infiltrate and exploit compromised systems.

Unlike traditional malware that primarily targets browser passwords, Dolphin X extends its reach to a wide array of sensitive data. It can extract credentials from over 300 applications, including browser logins, cryptocurrency wallets, password managers, cloud command-line tools, SSH keys, and developer environment files. This broad spectrum of targets poses substantial risks to both individuals and organizations, especially when compromised devices store credentials for critical cloud services or production systems.

Security researchers at Varonis discovered Dolphin X while monitoring underground forums. The malware is notable for its integration of artificial intelligence to profile victims. By analyzing collected activity data, Dolphin X enables attackers to identify and prioritize high-value targets, thereby optimizing their malicious operations.

The malware’s operator panel boasts several advanced features designed to enhance its effectiveness and stealth. These include process injection, registry and scheduled-task persistence, User Account Control (UAC) bypass methods, and the ability to patch security monitoring tools like the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW). Additionally, Dolphin X supports SOCKS5 proxy functionality, allowing attackers to route their traffic through infected machines, further obfuscating their activities.

One of the distinguishing aspects of Dolphin X is its remote build process. Operators configure settings such as command-and-control addresses, installation paths, persistence mechanisms, and evasion techniques through the operator panel. These configurations are then sent to a remote backend that compiles the customized payload, which is subsequently delivered to the target system. This method not only streamlines the deployment process but also incorporates mutation settings to alter each generated file, enhancing the malware’s ability to evade detection.

The emergence of Dolphin X underscores the evolving sophistication of cyber threats. Its combination of extensive credential theft, AI-driven victim profiling, and advanced evasion techniques represents a significant escalation in malware capabilities. Organizations and individuals must remain vigilant, implementing robust security measures and staying informed about such developments to protect against these increasingly complex threats.