Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New Dolphin X Stealer Employs AI Profiling to Prioritize Targets

July 24, 2026

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

July 24, 2026

Iranian Hackers Target Siemens and Schneider Industrial Systems

July 23, 2026
Facebook X (Twitter) Instagram
Friday, July 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New Dolphin X Stealer Employs AI Profiling to Prioritize Targets
News

New Dolphin X Stealer Employs AI Profiling to Prioritize Targets

Team-CWDBy Team-CWDJuly 24, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A newly discovered Windows infostealer and remote access trojan (RAT), dubbed Dolphin X, is using an AI-powered profiling system to help cybercriminals identify their most valuable victims, according to researchers at Varonis Threat Labs.

Advertised on a cybercrime forum, the malware is designed to target more than 300 applications and steal a wide range of sensitive data, including cryptocurrency wallets, .env files, SSH keys, cloud tokens and DevOps credentials.

However, researchers said Dolphin X’s standout feature is an “AI Profiler” that automatically ranks infected users based on factors such as application usage, browsing activity and installed software.

Varonis obtained and analyzed the malware’s operator panel in an isolated lab environment and found the tool assigns scores to victims, allowing attackers to quickly identify those most likely to provide valuable access or data.

This tool is useful because a cybercriminal could control thousands of infected machines, which Varonis noted is far more than they could review manually.

Attackers are sent a daily summary of rankings which Varonis said helps them identify high-value users.

Overall, the panel lists 329 features across ten categories and researchers noted that the most important figure is the collection scope: more than 300 application targets appear under the credential-looter category. 

“These targets range from browser logins and cryptocurrency wallets to SSH keys and cloud tokens, with the collected data staged in a single archive,” Varonis researchers wrote.

In terms of defender recommendations, Varonis said security team responses should prioritize two items:

  1. Keep long-lived credentials off disk wherever possible, especially out of project directories and local credential stores. Infostealers are designed to grab everything in one pass, so anything stored locally should be treated as potentially exposed
  2. Focus detection on behavior rather than file signatures. For example, explorer.exe running under a non-default desktop is a strong indicator of an HVNC session, regardless of how the malware binary is packed or what hash it uses



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Team-CWD
  • Website

Related Posts

News

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

July 24, 2026
News

Iranian Hackers Target Siemens and Schneider Industrial Systems

July 23, 2026
News

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

July 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

AI-powered financial scams swamp social media

September 11, 2025

Children and chatbots: What parents should know

January 23, 2026

Mobile app permissions (still) matter more than you may think

February 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.