A new remote access trojan called Dolphin X claims to use artificial intelligence to identify and rank high-value victims after infection.

The malware includes an “AI Profiler” feature that analyses information collected from compromised devices, assigns risk scores and helps attackers decide which victims to target first.

A researcher examined the Dolphin X operator panel, malware builder and related network traffic in an isolated environment. However, the analysis did not include a live malware sample running on an infected device.

AI Profiler sorts infected victims

Dolphin X is advertised as an all-in-one remote access trojan by a seller using the alias “Kontraktnik” on a cybercrime forum.

Its operator panel lists 329 features across 10 categories. One feature, the AI Profiler, appears in the surveillance section of the panel.

The tool claims to track application use, risk scores and daily activity summaries. It can also process browser domains, installed software and victim tags to create ranked profiles.

This approach could help attackers handle the large amount of data collected by credential-stealing malware. Instead of manually reviewing every compromised device, operators can prioritise systems that may provide access to corporate networks, cloud environments, cryptocurrency accounts or production systems.

The panel generates daily summaries that place victims in order of perceived value.

Technical strings support profiling workflow

The researcher confirmed that the AI Profiler appears in the Dolphin X control panel. They also found technical strings that support the profiling workflow.

These included:

  • Auto-Start AI Profiler
  • ProfilerStart
  • ProfilerGetData
  • risk_score
  • risk_factors
  • categoryusage

The strings indicate that the platform can collect and process data needed to categorise victims. However, researchers could not determine which AI engine, if any, creates the rankings without analysing a live Dolphin X sample.

Dolphin X claims broad credential-stealing capabilities

The Dolphin X malware also promotes extensive information-stealing features. Its panel claims to target more than 300 applications.

The advertised targets include Chromium and Gecko-based browsers, cryptocurrency wallet extensions, desktop crypto wallets, password managers and cloud command-line tools.

Dolphin X also claims it can steal .env files, SSH keys, cloud access tokens, browser login data, cryptocurrency wallet information and other developer credentials.

Researchers did not independently confirm these collection capabilities because they analysed the management panel, builder and network traffic rather than executing the malware on a victim device.

AI helps attackers prioritise stolen data

Artificial intelligence is increasingly appearing in cybercrime services, including tools used for phishing, spam generation and automated attack activity.

Dolphin X uses AI for a different purpose. Rather than focusing on initial intrusion, its claimed profiling feature aims to sort stolen information and highlight the victims that attackers may consider most valuable.


0 responses to “Dolphin X Malware Uses AI to Rank High-Value Victims”