Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    Claude’s voice mode is now available for Opus and Sonnet

    July 24, 2026

    Australian energy provider Origin says data breach exposes client data

    July 24, 2026

    Coinbase Unveils USDC Payment Tools for AI Agents

    July 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Claude’s voice mode is now available for Opus and Sonnet
    • Australian energy provider Origin says data breach exposes client data
    • Coinbase Unveils USDC Payment Tools for AI Agents
    • Curiosity Blog, Sols 4954–4960: Celebrating Our Rover Engineers Past and Present
    • Officials identify Corey Ruiz as man Madison police shot and killed
    • ‘The Odyssey’ Is About Western Moral Failure
    • Is video of Trump speech attendee mocking the president real?
    • Australia news live: ABC takes down two Four Corners episodes on drug trade over ‘veracity concerns’; Labor dodges gambling reform fight | Australia news
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Friday, July 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    New Dolphin X malware uses AI to rank high-value targets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 24, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.

    The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias “Kontraktnik,” promoting it as an all-in-one remote access trojan.

    According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications.

    image

    However, one of its notable features is an “AI Profiler” that analyzes information collected from infected computers and assigns each victim a risk score.

    “Beyond credential collection, the panel includes a surveillance tab containing the AI Profiler. The seller describes it as an ‘AI behavioral profiler with app usage tracking, risk score, and daily summary,'” explains Varonis.

    Varonis obtained the Dolphin X operator panel and analyzed it in an isolated lab, noting they examined the malware builder and its network traffic rather than executing a live Dolphin X agent on an infected computer.

    AI Profiler ranks victims for attackers

    Credential-stealing malware can allow attackers to steal credentials for hundreds, if not thousands, of online accounts, making it difficult to manually review them all for high-value targets.

    Dolphin X’s AI Profiler claims to automate this process by acting as a sorting system that scores, categorizes, and ranks infected computers so that the attackers know which are the most high-value to target further.

    The operator panel claims that the AI Profiler can process victims’ application usage, risk scores and tags, browser domains, and installed software to produce ranked profiles.

    Operator panel showing AI Profiler option
    Operator panel showing AI Profiler option
    Source: Varonis

    These scores are given to attackers in daily summaries containing ranked victim profiles, allowing them to prioritize machines that may provide access to valuable accounts, cryptocurrency, corporate networks, cloud environments, or production systems.

    “In practice, the feature appears designed to help operators triage victims,” explains Kelley.

    Varonis researcher Daniel Kelley confirmed to BleepingComputer that the AI Profiler is present in the operator panel and discovered technical strings supporting the profiling workflow, including Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage.

    The researcher said these strings indicate that the profiling workflow is actually included and that the panel can process the data needed to rank victims.

    However, Varonis could not determine what artificial intelligence engine is being used to produce the rankings without analyzing a live Dolphin X malware sample.

    The malware also operates as a credential stealer, with the operator panel showing that it targets more than 300 applications, including 9 Chromium and Gecko browsers, 100 cryptocurrency wallet extensions, 65 desktop crypto wallets, 10 password managers, and more than 30 cloud command-line tools.

    Dolphin X also claims to steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information, and other developer credentials.

    As Varonis analyzed the Dolphin X operator panel, builder, and related network traffic rather than a live malware sample executing on an infected machine, the malware’s advertised collection capabilities were not independently confirmed by the researcher.

    Artificial intelligence has become a popular tool among threat actors, with it being used to launch cybercrime services such as SpamGPT and AI agents conducting autonomous cyberattacks.

    Dolphin X platform instead uses AI to solve an operational problem by processing large amounts of stolen data and automatically sorting infected users into highest-value victims.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Dolphin highvalue Malware rank targets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Australian energy provider Origin says data breach exposes client data

    Is Patching Dead? Vulnerability Management in the Post-Mythos Era

    Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

    Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    Check Point hole grants unauthenticated attackers full SmartConsole admin privileges

    Flaws in Passkey Implementation Show Old Attacks Still Work

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Claude’s voice mode is now available for Opus and Sonnet

    July 24, 2026

    Australian energy provider Origin says data breach exposes client data

    July 24, 2026

    Coinbase Unveils USDC Payment Tools for AI Agents

    July 24, 2026

    Curiosity Blog, Sols 4954–4960: Celebrating Our Rover Engineers Past and Present

    July 24, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Claude’s voice mode is now available for Opus and Sonnet

    July 24, 2026

    Australian energy provider Origin says data breach exposes client data

    July 24, 2026

    Coinbase Unveils USDC Payment Tools for AI Agents

    July 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.