Dolphin X Windows infostealer and RAT with AI victim profiling
Malware Activity
Summary
Hide ▲
Show ▼
The newly discovered Dolphin X malware is using AI-powered profiling to rank infected users and steer attackers toward higher-value victims, improving theft efficiency across a broad Windows target set. It is built as a Windows infostealer and RAT that targets more than 300 applications and steals credentials and sensitive files, including cryptocurrency wallets, .env files, SSH keys, cloud tokens and DevOps credentials. The operator’s scoring system gives criminals a fast way to separate low-value infections from machines likely to provide better access or data.
Related Happenings
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Vidar infostealer market rise and distribution expansion
Malware Activity
H score30
First: 28.04.2026 22:07
Last: 28.04.2026 22:07
Sources 1
About this happening:
Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Vidar infostealer market rise and distribution expansion
Malware ActivityAbout this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Remcos RAT variant with real-time surveillance and evasion
Malware Activity
H score28
First: 19.02.2026 18:30
Last: 19.02.2026 18:30
Sources 1
About this happening:
A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...
Remcos RAT variant with real-time surveillance and evasion
Malware ActivityAbout this happening: A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...
Remcos RAT runtime decryption and dynamic API loading analysis
Technical Analysis
H score23
First: 19.02.2026 18:30
Last: 19.02.2026 18:30
Sources 1
About this happening:
A newly observed Remcos RAT variant now uses runtime decryption and dynamic Windows API loading to reduce detection and frustrate static analysis on Windows systems*...
Remcos RAT runtime decryption and dynamic API loading analysis
Technical AnalysisAbout this happening: A newly observed Remcos RAT variant now uses runtime decryption and dynamic Windows API loading to reduce detection and frustrate static analysis on Windows systems*...
Timeline
-
23.07.2026 13:19 2 articles · 1h ago
Varonis identifies Dolphin X Windows infostealer with AI victim scoring
Initial DisclosureVaronis Threat Labs identified Dolphin X as a newly discovered Windows infostealer and RAT, and found that its AI Profiler scores infected users using application usage, browsing activity, and installed software to help attackers focus on higher-value victims. The malware is advertised on a cybercrime forum, targets more than 300 applications, and steals cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps credentials; Varonis also observed an operator panel that assigns victim scores and sends daily ranking summaries.
Show sources
- New Dolphin X Stealer Employs AI Profiling to Prioritize Targets — www.infosecurity-magazine.com — 23.07.2026 13:19
- New Dolphin X Stealer Employs AI Profiling to Prioritize Targets — www.infosecurity-magazine.com — 23.07.2026 13:19