The cybersecurity landscape has added a new threat that combines classic data-stealing techniques with artificial intelligence. Dolphin X, a remote access trojan and data stealer, was discovered by Varonis Threat Labs after being advertised on underground forums by a vendor using the alias 'Kontraktnik.' This malware is not limited to extracting browser passwords; its reach spans over 300 applications, including cryptocurrency wallets, .env files, SSH keys, cloud service tokens, and DevOps credentials. What makes it especially dangerous is its 'AI Profiler,' a module that scores victims based on their application usage, browsing activity, and installed software, allowing attackers to prioritize high-value targets. For businesses, this represents a critical risk: a single compromised machine can expose the credentials that manage entire cloud environments, from AWS to Azure.
From a technical perspective, Dolphin X operates with a control panel that functions as a remote configuration wizard. The operator sets the C2 server address, installation path, persistence, and evasion options; then the client sends the configuration to a backend that compiles the binary. This centralized process allows the seller to modify each build before delivery, implementing an optional mutation engine with three tiers. The basic tier modifies timestamps and PE headers, the intermediate tier shuffles the import table, and the advanced tier (reserved for the PRO plan) rewrites control flow, substitutes instructions, and re-encrypts strings with fresh keys. This renders traditional static signatures—such as YARA rules or hash lists—practically useless. The collection scope is organized into ten categories with over 329 features, and captured data is packed into a single archive that can contain data from nine browsers, more than a hundred wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools. On a developer machine, .env files and SSH keys often hold long-lived credentials that grant access to cloud consoles, CI/CD pipelines, and production data.
The business impact is immediate. If an employee with cloud admin privileges unknowingly downloads this malware, the attacker can gain access to the entire company infrastructure. Dolphin X does not discriminate between personal and professional accounts; it steals everything it finds. Therefore, defense strategies must evolve. The primary recommendation from experts is to keep long-lived credentials off local disk whenever possible, especially outside project directories and local credential stores. Additionally, it is crucial to focus detection on behavior rather than file signatures. For example, the execution of explorer.exe on a non-default desktop is a strong indicator of an HVNC (Hidden Virtual Network Computing) session, regardless of how the binary is packed. Security tools should monitor anomalous activities such as mass access to configuration files, reading of SSH keys, or copying of cloud tokens within a single process.
In this context, having a technology partner that understands both cybersecurity and software development is more important than ever. Q2BSTUDIO offers comprehensive cybersecurity services, including pentesting, security audits, and consulting to protect critical infrastructures. But security cannot be treated in isolation. The company also specializes in developing custom software, integrating secure practices from design. When dealing with threats like Dolphin X that target cloud environments, expertise in cloud services AWS and Azure becomes essential. Q2BSTUDIO helps organizations migrate and manage their cloud workloads with minimum access policies, automatic credential rotation, and continuous monitoring. Furthermore, for those looking to optimize data without sacrificing security, BI and Power BI services enable building dashboards that visualize risks in real time. And when it comes to artificial intelligence, the company develops custom AI agents that can automate anomaly detection and incident response—exactly what is needed to counter tools like Dolphin X’s AI Profiler.
The integration of artificial intelligence into cybercrime is not new — we have already seen cases with SpamGPT and Bluekit — but Dolphin X marks a turning point by automating victim prioritization. Attackers no longer need to manually review thousands of infected machines; the malware itself delivers a ranked list of the most promising targets. This forces defenses to be equally intelligent. One approach is to implement behavior-based detection systems with machine learning, capable of identifying data collection patterns even if the binary changes constantly. It is also advisable to review permissions of installed applications on endpoints and limit the use of long-lived tokens in development environments. Companies that have already adopted a zero-trust strategy have an advantage, as they assume any device may be compromised and design controls accordingly.
Finally, it is important to note that the response should not be purely technical. Employee awareness remains the first line of defense. Dolphin X, like most infostealers, is typically distributed via phishing, deceptive downloads, or exploits. Training staff to recognize suspicious links and avoid executing unverified files drastically reduces the attack surface. Additionally, companies should have an incident response plan that includes immediate revocation of cloud credentials if an infection is detected. In summary, Dolphin X represents an evolution in information-stealing malware by combining massive reach with AI-driven profiling. For organizations, the key lies in adopting a holistic cybersecurity approach that integrates technology, processes, and people. Q2BSTUDIO, with its expertise in custom development, cloud, BI, cybersecurity, and artificial intelligence, positions itself as a strategic ally to face these challenges and build resilient infrastructures.




