Dolphin X stealer targets 300+ applications with AI-powered victim profiling
Malware now uses AI to automatically identify high-value targets and prioritize data theft based on victim financial profiles, increasing efficiency of credential theft campaigns.
Windows stealer expands target scope dramatically
A newly identified Windows information stealer called Dolphin X targets more than 300 applications across browsers, cryptocurrency wallets, messaging platforms, and enterprise tools. The malware collects credentials, session tokens, and wallet keys from a significantly broader range of software than previous stealer variants.
Security researchers report that Dolphin X includes modules specifically designed to extract data from enterprise collaboration tools, developer environments, and financial applications. The broad targeting suggests the malware is designed for both individual credential theft and corporate espionage operations.
AI profiler ranks victims by financial value
Dolphin X includes what researchers describe as an AI-powered profiling component that analyzes stolen data to estimate victim financial value. The system examines bank account information, cryptocurrency holdings, and application usage patterns to automatically prioritize victims for follow-on exploitation.
The profiler generates a score for each compromised system, allowing attackers to focus their efforts on the most lucrative targets. This represents a shift from bulk credential harvesting to automated triage of stolen data based on potential return on investment.
Distribution through software cracks and pirated tools
The malware spreads primarily through cracked software, pirated development tools, and fake game installers distributed on file-sharing platforms. Attackers bundle Dolphin X with legitimate-appearing applications to bypass initial user suspicion.
Unlike previous stealers that required command-and-control infrastructure for data exfiltration, Dolphin X can operate semi-autonomously, performing local victim assessment before transmitting prioritized data sets. This reduces network traffic and makes detection more difficult for enterprise security tools.