Sneaky Windows stealer targets 300 apps, gives crims AI profiler to max profits

Bender1 pts0 comments

Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits

Jump to main content

Search

REG AD

Security

Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits

Move over Flipper. There's a new Dophin X in town

Jessica Lyons

Jessica<br>Lyons

Cybersecurity Editor

Published<br>wed 22 Jul 2026 // 14:00 UTC

EXCLUSIVE A Windows information-stealer targeting more than 300 applications comes equipped with a novel surveillance tool: an AI profiler that ranks infected victims so crooks know who to target first.<br>Varonis Threat Labs spotted the new stealer and remote access trojan (RAT), called Dolphin X, for sale on a cybercrime forum, and shared their research exclusively with The Register.<br>The ad for the malware claims it can target upwards of 300 applications and has the ability to bypass browser passwords and steal enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets.

REG AD

REG AD

Dolphin X also promises users a super-sneaky surveillance feature called the AI Profiler. It scores infected users by app usage, browsing history, and installed software, and sends the cybercriminals a daily summary that ranks victims’ based on the likely payoff from an attack.<br>“There's two things that stand out,” Daniel Kelley, a senior threat researcher with Varonis, told The Register. “The first thing is the AI profiler. That's something I've never seen before. And then it’s also the breadth of applications that it steals - and it’s not even just applications. It’s everything, you name it: it will steal files, or credentials, cryptocurrencies. It’s probably one of the biggest stealers I’ve ever seen, and covers the biggest attack surface.”

MORE CONTEXT

Frontier LLMs couldn't help Hugging Face fight off evil agents

'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes

Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them

C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest

A malware vendor using the alias “Kontraktnik” posted Dolphin X for sale, promising: “You can use it as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, as a loader.”<br>The crimeware currently only runs under Windows, but “we are working on Debian,” Kontraktnik claimed, adding that the malware also only supports English and Russian.

It’s probably one of the biggest stealers I’ve ever seen, and covers the biggest attack surface

Kelley suspects the developer is Russian-speaking, and told us that the stealer includes an option not to infect any users in the Commonwealth of Independent States (CIS) countries, a common choice among Russian-based ransomware and cybercrime gangs.<br>Kelley and his team obtained and analyzed the malware builder, operator panel and its network traffic, but didn't examine a malware sample. Varonis therefore can’t guarantee that all of the developer’s claims are true.<br>However, “when we looked at the builder, it had everything to suggest the features were legitimate,” he said. “We couldn’t test out the malware itself, but I would say it probably lives up to most of its expectations.”<br>Feedback left on the forum where the malware is sold supports that analysis. As of Tuesday, the sales thread has passed 3,000 views, we’re told, with Kontraktnik closing at least two confirmed deals. Both of these included positive feedback from the buyers.

REG AD

Three-tier subscription model<br>Beyond the 300 + apps it targets, Dolphin X's operator panel lists 329 features across 10 categories. Buyers can subscribe to one of three tiers, each unlocking new features, or buy a lifetime subscription.<br>The minimalist suscription costs about $80 per month, which buys rewriting and altering capabilities across Windows Portable Executable (PE) timestamp, Rich headers, and section padding, along with capabilities allowing the malware to exploit the brittle YARA rules to bypass detection and hash-based blocklists.<br>The middle tier advertises shuffling the import table, which would change the binary's import hash between builds. The top level sub (about $230 per month) claims to rewrite the code’s control flow, substitute instructions, and re-encrypt embedded strings with a new random key each time, thus making stable byte sequences harder to identify.<br>Lifetime subscription cost about $1,140 for basic access, $2,280 for mid-tier malware, or $3,420 for perpetual pro-level Pwnage.<br>“It really lowers the barrier to entry,” Kelley said, adding that in the not-so-distant past, cybercriminals needed a certain level of technical expertise to develop and use different types of malware. “Now it's set up in a way where it's almost like SaaS. Anyone can purchase it. Anyone can take it out of the package and use it.”<br>All of this suggests two takeaways for defenders, according to the security sleuths....

malware stealer windows profiler sneaky targets

Related Articles