Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
Dolphin X is a Windows-based stealer and remote access trojan that targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. It collects a wide range of credentials such as browser logins, SSH keys, .env files, and cloud tokens. A notable feature is its AI Profiler, which automatically scores infected victims based on their application usage and browsing activity to help attackers identify high-value targets. The malware is distributed via a builder operated on a remote server, offering optional mutation engines to evade detection. It poses a significant risk to developers and organizations by potentially exposing entire production environments through compromised DevOps credentials. No known exploits in the wild or patches are currently documented.
AI Analysis
Technical Summary
Dolphin X is a newly discovered Windows stealer and remote access trojan that targets more than 300 applications, including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. It exfiltrates credentials such as browser logins, SSH keys, .env files, and cloud tokens. The malware includes an AI Profiler feature that automatically scores victims based on application usage, browsing activity, and installed software, enabling attackers to prioritize high-value targets via daily summaries. The malware builder is remotely hosted, compiling agents and offering mutation engines to evade detection. The threat actor behind Dolphin X uses the alias Kontraktnik. This malware poses a significant threat to developers and organizations by potentially exposing access to entire production environments through stolen DevOps credentials. There is no indication of known exploits in the wild or available patches.
Potential Impact
The malware enables attackers to steal a broad range of sensitive credentials from infected Windows systems, including browser logins, cryptocurrency wallets, password managers, SSH keys, .env files, and cloud tokens. This can lead to unauthorized access to user accounts, cryptocurrency theft, and compromise of cloud and DevOps environments. The AI Profiler feature enhances attacker efficiency by identifying high-value targets, increasing the risk of impactful breaches. The presence of mutation engines suggests attempts to evade detection, complicating defense efforts. No known exploits in the wild have been reported yet.
Mitigation Recommendations
No official patches or fixes are available as this is malware rather than a software vulnerability. Mitigation should focus on standard endpoint protection measures including updated antivirus and anti-malware solutions capable of detecting Dolphin X variants. Monitoring for indicators of compromise such as the domains 'thedolphinx.top' and 'backend.thedolphinx.top' and the file hash '726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0' is recommended. Organizations should also enforce strong credential hygiene, multi-factor authentication, and limit exposure of sensitive credentials such as SSH keys and cloud tokens. Since no vendor advisory states otherwise, these steps are prudent.
Indicators of Compromise
- domain: thedolphinx.top
- hash: 726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0
- url: http://backend.thedolphinx.top:8443
- domain: backend.thedolphinx.top
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
Description
Dolphin X is a Windows-based stealer and remote access trojan that targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. It collects a wide range of credentials such as browser logins, SSH keys, .env files, and cloud tokens. A notable feature is its AI Profiler, which automatically scores infected victims based on their application usage and browsing activity to help attackers identify high-value targets. The malware is distributed via a builder operated on a remote server, offering optional mutation engines to evade detection. It poses a significant risk to developers and organizations by potentially exposing entire production environments through compromised DevOps credentials. No known exploits in the wild or patches are currently documented.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Dolphin X is a newly discovered Windows stealer and remote access trojan that targets more than 300 applications, including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. It exfiltrates credentials such as browser logins, SSH keys, .env files, and cloud tokens. The malware includes an AI Profiler feature that automatically scores victims based on application usage, browsing activity, and installed software, enabling attackers to prioritize high-value targets via daily summaries. The malware builder is remotely hosted, compiling agents and offering mutation engines to evade detection. The threat actor behind Dolphin X uses the alias Kontraktnik. This malware poses a significant threat to developers and organizations by potentially exposing access to entire production environments through stolen DevOps credentials. There is no indication of known exploits in the wild or available patches.
Potential Impact
The malware enables attackers to steal a broad range of sensitive credentials from infected Windows systems, including browser logins, cryptocurrency wallets, password managers, SSH keys, .env files, and cloud tokens. This can lead to unauthorized access to user accounts, cryptocurrency theft, and compromise of cloud and DevOps environments. The AI Profiler feature enhances attacker efficiency by identifying high-value targets, increasing the risk of impactful breaches. The presence of mutation engines suggests attempts to evade detection, complicating defense efforts. No known exploits in the wild have been reported yet.
Mitigation Recommendations
No official patches or fixes are available as this is malware rather than a software vulnerability. Mitigation should focus on standard endpoint protection measures including updated antivirus and anti-malware solutions capable of detecting Dolphin X variants. Monitoring for indicators of compromise such as the domains 'thedolphinx.top' and 'backend.thedolphinx.top' and the file hash '726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0' is recommended. Organizations should also enforce strong credential hygiene, multi-factor authentication, and limit exposure of sensitive credentials such as SSH keys and cloud tokens. Since no vendor advisory states otherwise, these steps are prudent.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.varonis.com/blog/dolphin-x-stealer"]
- Adversary
- Kontraktnik
- Pulse Id
- 6a61203a6b39de0e8d3d7247
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainthedolphinx.top | — | |
domainbackend.thedolphinx.top | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://backend.thedolphinx.top:8443 | — |
Threat ID: 6a61429b9c2644c7f8c94c83
Added to database: 07/22/2026, 22:22:19 UTC
Last enriched: 07/22/2026, 22:42:29 UTC
Last updated: 07/23/2026, 02:30:51 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.