Some new malware wants to be a talent agent for cybercriminals. Dubbed Dolphin X, this remote-access trojan advertises an AI-powered profiling feature that supposedly scores infected machines so attackers know which victims are worth stalking first. A security researcher from Varonis Threat Labs examined the malware’s operator panel and builder in a contained lab and reported on what the control panel claims it can do — but they didn’t run the actual malware on a live machine.

What Dolphin X claims to do

The control panel is reportedly jam-packed with bells and whistles — the seller lists hundreds of features across multiple categories. Highlights the malware boasts include credential theft and a surveillance-focused profiling tool that churns out daily summaries for operators.

  • Big feature count: the panel shows dozens of capabilities across many categories (the seller advertises many hundreds of options).
  • Credential targeting: the panel claims to scrape logins and secrets from a long list of software, including multiple browsers, crypto wallet extensions, desktop wallets, password managers, and cloud command-line tools.
  • Developer and cloud secrets: purported targets include .env files, SSH keys, cloud access tokens, browser login data, and other developer credentials.
  • Surveillance tab: an advertised “AI behavioral profiler” analyzes behavior and app usage and provides prioritized victim lists.
  • Technical signs: the panel contains strings suggesting an integrated profiling workflow such as Auto-Start AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage.

Why this matters (and why to be skeptical)

The killer idea here is automation: credential-stealing tools can harvest credentials for hundreds or thousands of accounts, and manually sorting that heap for the really juicy targets is tedious. Dolphin X claims to take that grunt work off attackers’ hands by scoring and ranking victims so operators can chase the machines that likely hold crypto, cloud access, corporate accounts, or other valuable assets.

That said, the Varonis researcher examined the panel and the builder in isolation and did not execute a live agent in a real infection, so the collection and ranking capabilities are claimed rather than independently proven. Also, the vendor doesn’t disclose what underlying AI (if any) actually generates the rankings, so the inner magic remains a mystery.

Bottom line: this is another example of threat actors using automation and analytics to make their operations more efficient. Defenders should assume attackers will try to prioritize high-value victims and plan accordingly — harden credentials, rotate keys, enable multifactor authentication, monitor unusual access to cloud and crypto assets, and keep an eye on suspicious mass-exfiltration patterns.

And if nothing else, remember that even cybercriminals like a good spreadsheet: if you steal a lot of secrets, you still want an easy way to figure out which ones pay the rent.