Threat · curated 22 Jul 2026

Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits

Coverage timeline

22 Jul 2026theregister.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Dolphin X shows criminals weaponizing AI to triage and prioritize victims for maximum profit, a novel escalation in commodity malware that raises the stakes for defenders protecting credentials and secrets.

Varonis Threat Labs found Dolphin X, a Windows information-stealer and RAT for sale on a cybercrime forum that targets 300+ applications and steals browser passwords, enterprise credentials, crypto wallets, .env files, SSH keys, cloud tokens, and DevOps secrets. Its novel feature is an 'AI Profiler' that scores infected victims by app usage, browsing history, and installed software, sending operators a daily ranked summary of victims by likely payoff. The vendor 'Kontraktnik,' suspected Russian-speaking, markets it as a stealer, HVNC, DDoS botnet, and loader.