The brand new Dolphin X distant entry Trojan claims to make use of AI-powered profiling capabilities to attain and rank contaminated customers, serving to cybercriminals determine which victims to focus on first.
This malware was analyzed by researcher Daniel Kelley from Varonis Risk Labs. He discovered the malware being marketed on cybercrime boards utilizing the alias “Kontraktnik” and being promoted as an all-in-one distant entry Trojan.
Varonis stated the operator panel lists 329 options throughout 10 classes, together with a credential-stealing characteristic that claims to focus on greater than 300 purposes.
Nonetheless, one notable characteristic is its “AI Profiler,” which analyzes info collected from contaminated computer systems and assigns a danger rating to every sufferer.
“Except for gathering credentials, the panel features a monitoring tab with an AI profiler, which the vendor describes as an ‘AI behavioral profiler with app utilization monitoring, danger scores, and each day summaries,’” Varonis explains.
Varonis obtained a Dolphin X operator panel and analyzed it in an remoted lab, noting that it inspected the malware builder and its community visitors quite than operating a reside Dolphin
AI Profiler ranks victims in opposition to attackers
Credential-stealing malware permits attackers to steal credentials for tons of, if not hundreds, of on-line accounts, making it tough to manually evaluate each account for high-value targets.
Dolphin
Operator Panel claims that its AI profiler can course of victims’ utility utilization, danger scores and tags, browser domains, and put in software program to generate ranked profiles.

Supply: Hero
These scores are given to attackers in a each day overview that features ranked sufferer profiles, permitting them to prioritize machines which are possible to supply entry to beneficial accounts, cryptocurrencies, company networks, cloud environments, or manufacturing techniques.
“In actuality, this characteristic seems to be designed to assist operators triage victims,” Kelly explains.
Varonis researcher Daniel Kelley confirmed to BleepingComputer that AI Profiler is current within the Operator Panel and found the next technical strings to assist the profiling workflow: Auto-Begin AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factorsand categoryusage.
The researchers stated these strings point out {that a} profiling workflow is certainly concerned, and that the panel is ready to course of the info wanted to rank victims.
Nonetheless, Varonis couldn’t decide what synthetic intelligence engine was used to create the rankings with out analyzing reside Dolphin X malware samples.
The malware additionally acts as a credential stealer, with its operator panel displaying concentrating on over 300 purposes, together with 9 Chromium and Gecko browsers, 100 cryptocurrency pockets extensions, 65 desktop crypto wallets, 10 password managers, and over 30 cloud command-line instruments.
Dolphin X additionally claims theft. .env information, SSH keys, cloud entry tokens, browser login information, cryptocurrency pockets info, and different developer credentials.
As a result of Varonis analyzed the Dolphin
Synthetic intelligence has grow to be a preferred device amongst risk actors and is getting used to launch cybercrime companies comparable to SpamGPT and AI brokers that perform autonomous cyberattacks.
As a substitute, the Dolphin X platform makes use of AI to resolve operational issues by processing massive quantities of stolen information and robotically classifying contaminated customers into the highest-value victims.
Safety groups doc 54% of profitable assaults and subject a warning on solely 14%. The remainder strikes invisibly by the setting.
Picus’ whitepaper reveals the right way to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
