Dolphin X stealer targets 300+ applications with AI-powered victim profiling

Malware now uses AI to automatically identify high-value targets and prioritize data theft based on victim financial profiles, increasing efficiency of credential theft campaigns.

Abstract illustration of data filtering and prioritization systems
AI-generated illustration · Sylvaris

Windows stealer expands target scope dramatically

A newly identified Windows information stealer called Dolphin X targets more than 300 applications across browsers, cryptocurrency wallets, messaging platforms, and enterprise tools. The malware collects credentials, session tokens, and wallet keys from a significantly broader range of software than previous stealer variants.

Security researchers report that Dolphin X includes modules specifically designed to extract data from enterprise collaboration tools, developer environments, and financial applications. The broad targeting suggests the malware is designed for both individual credential theft and corporate espionage operations.

AI profiler ranks victims by financial value

Dolphin X includes what researchers describe as an AI-powered profiling component that analyzes stolen data to estimate victim financial value. The system examines bank account information, cryptocurrency holdings, and application usage patterns to automatically prioritize victims for follow-on exploitation.

The profiler generates a score for each compromised system, allowing attackers to focus their efforts on the most lucrative targets. This represents a shift from bulk credential harvesting to automated triage of stolen data based on potential return on investment.

Distribution through software cracks and pirated tools

The malware spreads primarily through cracked software, pirated development tools, and fake game installers distributed on file-sharing platforms. Attackers bundle Dolphin X with legitimate-appearing applications to bypass initial user suspicion.

Unlike previous stealers that required command-and-control infrastructure for data exfiltration, Dolphin X can operate semi-autonomously, performing local victim assessment before transmitting prioritized data sets. This reduces network traffic and makes detection more difficult for enterprise security tools.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.