Threat · curated 22 Jul 2026
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
First reported · updated · 2 reports theregister.com
Coverage timeline
Why it matters
Dolphin X shows criminals bolting AI-driven victim triage onto commodity infostealers, letting operators automatically prioritize the machines most likely to yield corporate, cloud, or cryptocurrency access.
Dolphin X is a new Windows remote access trojan advertised on a cybercrime forum by a vendor using the alias "Kontraktnik" and analyzed by Varonis Threat Labs. Alongside credential-stealing that targets 300+ applications, it markets an "AI Profiler" that scores and ranks infected victims by app usage, browser domains, and installed software to help operators triage high-value targets; Varonis confirmed profiling strings in the operator panel but could not determine what underlying AI it uses.