The discovery of Dolphin X, a Windows stealer targeting over 300 applications and using an AI-driven victim profiler, marks a significant development in the cyber threat landscape. Security researchers have validated components of this malware, which is being sold on underground forums and is already attracting criminal buyers. Its combination of extensive data theft capabilities and automated prioritisation of high-value targets presents new challenges for organisations.
Inside the Dolphin X Windows stealer campaign
Dolphin X was first identified by Varonis Threat Labs, who examined its builder, operator panel and network communication. The malware, exclusively for Windows systems, is currently for sale on cybercrime forums. The developer, using the alias Kontraktnik, claims Dolphin X can compromise more than 300 applications and supports a range of attack features including credential theft, remote access, and even DDoS and loader functionality.
Discovery and timeline
- Discovery: Varonis Threat Labs reported Dolphin X in July 2026, after analysing its builder and operator panel. The malware has not yet been widely observed in the wild, but is attracting attention on criminal forums.
- Vendor activity: The malware was posted for sale by Kontraktnik, who claims to be working on a Debian version, but at present Dolphin X is Windows-only and supports English and Russian languages.
- Forum interest: Over 3,000 views and at least two confirmed sales with positive feedback have been recorded as of late July 2026, indicating early traction among cybercriminal buyers.
Who is affected and which products are targeted?
Dolphin X is designed to infect Windows systems. Its operator panel lists 329 features across 10 categories, and the malware claims to target a broad range of applications—over 300 in total. The targets include:
- Web browsers (for password and session cookie theft)
- Enterprise login credentials
- Cryptocurrency wallets
- .env files (often used for application secrets)
- SSH keys
- Cloud tokens
- DevOps secrets
The malware appears to focus on both individual and enterprise targets, maximising potential profit by stealing diverse sensitive data.
AI-driven victim profiling
One of the most novel features is the AI Profiler. This tool analyses an infected user’s app usage, browsing history and installed software, then scores each victim. The profiler sends cybercriminal operators a daily summary, ranking victims by the potential value of exploiting them. This allows criminals to focus their efforts on high-yield targets, such as users with access to enterprise accounts, financial platforms or cryptocurrency assets.
Technical details and attack methods
Dolphin X is marketed as a multi-functional tool with flexible deployment options. Buyers can use it as a stealer, a remote access trojan (RAT), a Hidden Virtual Network Computing (HVNC) payload, a DDoS botnet or a loader for secondary malware. Its modular approach enhances its appeal for a broad range of attacks.
Malware obfuscation and subscription model
The malware is offered via a three-tier subscription model, each unlocking more advanced evasion features:
- Basic tier (approx. $80/month): Grants rewriting and altering capabilities for Windows PE timestamps, Rich headers and section padding. Helps bypass detection by exploiting YARA rule weaknesses and avoiding hash-based blocklists.
- Mid tier: Adds shuffling of the import table, changing the binary’s import hash and reducing signature-based detection.
- Top tier (approx. $230/month): Introduces rewriting of the code’s control flow, substitution of instructions and re-encryption of embedded strings with new random keys, making byte-sequence signature detection extremely difficult.
Lifetime access is also available, with prices ranging from $1,140 for basic to $3,420 for the full-featured version.
Bypassing CIS countries
Dolphin X includes an option to avoid infecting users in the Commonwealth of Independent States (CIS), a common tactic for Russian-speaking cybercriminals to reduce local law enforcement attention. This restriction, along with language support and forum activity, suggests the developer is Russian-speaking.
Claims versus validation
Varonis researchers did not obtain a live sample for execution, so while many features are confirmed via the builder and panel, not all claims are fully verified. However, the infrastructure and promotional materials suggest the advertised capabilities are largely credible. Feedback from early buyers on the forum corroborates the malware’s effectiveness.
Current exploitation status and outlook
As of July 2026, Dolphin X is not yet widespread in the wild but is being actively marketed and sold. The sophistication of its obfuscation techniques and the AI Profiler are likely to attract further criminal interest. Organisations using Windows platforms are at risk, especially those whose users are likely to handle valuable credentials or digital assets.
Why Dolphin X matters and what to do now
- The combination of large-scale credential theft and AI-driven targeting could lead to highly efficient, prioritised attacks against organisations and individuals.
- The breadth of applications targeted increases the potential impact, making traditional detection and response more challenging.
Organisations should monitor emerging threat intelligence on Dolphin X, ensure their endpoint security tools are updated, and pay attention to unusual credential or data access patterns.
Originally reported by theregister.com.




