Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

0
Medium
Published: 07/22/2026 (07/22/2026, 19:55:38 UTC)
Source: AlienVault OTX General

Description

Dolphin X is a Windows-based stealer and remote access trojan that targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. It collects a wide range of credentials such as browser logins, SSH keys, .env files, and cloud tokens. A notable feature is its AI Profiler, which automatically scores infected victims based on their application usage and browsing activity to help attackers identify high-value targets. The malware is distributed via a builder operated on a remote server, offering optional mutation engines to evade detection. It poses a significant risk to developers and organizations by potentially exposing entire production environments through compromised DevOps credentials. No known exploits in the wild or patches are currently documented.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 22:42:29 UTC

Technical Analysis

Dolphin X is a newly discovered Windows stealer and remote access trojan that targets more than 300 applications, including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. It exfiltrates credentials such as browser logins, SSH keys, .env files, and cloud tokens. The malware includes an AI Profiler feature that automatically scores victims based on application usage, browsing activity, and installed software, enabling attackers to prioritize high-value targets via daily summaries. The malware builder is remotely hosted, compiling agents and offering mutation engines to evade detection. The threat actor behind Dolphin X uses the alias Kontraktnik. This malware poses a significant threat to developers and organizations by potentially exposing access to entire production environments through stolen DevOps credentials. There is no indication of known exploits in the wild or available patches.

Potential Impact

The malware enables attackers to steal a broad range of sensitive credentials from infected Windows systems, including browser logins, cryptocurrency wallets, password managers, SSH keys, .env files, and cloud tokens. This can lead to unauthorized access to user accounts, cryptocurrency theft, and compromise of cloud and DevOps environments. The AI Profiler feature enhances attacker efficiency by identifying high-value targets, increasing the risk of impactful breaches. The presence of mutation engines suggests attempts to evade detection, complicating defense efforts. No known exploits in the wild have been reported yet.

Mitigation Recommendations

No official patches or fixes are available as this is malware rather than a software vulnerability. Mitigation should focus on standard endpoint protection measures including updated antivirus and anti-malware solutions capable of detecting Dolphin X variants. Monitoring for indicators of compromise such as the domains 'thedolphinx.top' and 'backend.thedolphinx.top' and the file hash '726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0' is recommended. Organizations should also enforce strong credential hygiene, multi-factor authentication, and limit exposure of sensitive credentials such as SSH keys and cloud tokens. Since no vendor advisory states otherwise, these steps are prudent.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.varonis.com/blog/dolphin-x-stealer"]
Adversary
Kontraktnik
Pulse Id
6a61203a6b39de0e8d3d7247
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainthedolphinx.top
domainbackend.thedolphinx.top

Hash

ValueDescriptionCopy
hash726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0

Url

ValueDescriptionCopy
urlhttp://backend.thedolphinx.top:8443

Threat ID: 6a61429b9c2644c7f8c94c83

Added to database: 07/22/2026, 22:22:19 UTC

Last enriched: 07/22/2026, 22:42:29 UTC

Last updated: 07/23/2026, 02:30:51 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses