A brand new Dolphin X distant entry trojan claims to make use of an AI-powered profiling function to attain and rank contaminated customers, serving to cybercriminals determine which victims ought to be focused first.
The malware was analyzed by Varonis Menace Labs researcher Daniel Kelley, who noticed it being marketed on a cybercrime discussion board by a vendor utilizing the alias “Kontraktnik,” selling it as an all-in-one distant entry trojan.
In accordance with Varonis, the operator panel lists 329 options throughout ten classes, together with a credential-stealing function that claims to focus on greater than 300 purposes.
Nevertheless, certainly one of its notable options is an “AI Profiler” that analyzes data collected from contaminated computer systems and assigns every sufferer a threat rating.
“Past credential assortment, the panel features a surveillance tab containing the AI Profiler. The vendor describes it as an ‘AI behavioral profiler with app utilization monitoring, threat rating, and each day abstract,'” explains Varonis.
Varonis obtained the Dolphin X operator panel and analyzed it in an remoted lab, noting they examined the malware builder and its community site visitors moderately than executing a stay Dolphin X agent on an contaminated laptop.
AI Profiler ranks victims for attackers
Credential-stealing malware can permit attackers to steal credentials for a whole lot, if not 1000’s, of on-line accounts, making it tough to manually overview all of them for high-value targets.
Dolphin X’s AI Profiler claims to automate this course of by performing as a sorting system that scores, categorizes, and ranks contaminated computer systems in order that the attackers know that are essentially the most high-value to focus on additional.
The operator panel claims that the AI Profiler can course of victims’ utility utilization, threat scores and tags, browser domains, and put in software program to provide ranked profiles.

Supply: Varonis
These scores are given to attackers in each day summaries containing ranked sufferer profiles, permitting them to prioritize machines which will present entry to worthwhile accounts, cryptocurrency, company networks, cloud environments, or manufacturing techniques.
“In follow, the function seems designed to assist operators triage victims,” explains Kelley.
Varonis researcher Daniel Kelley confirmed to BleepingComputer that the AI Profiler is current within the operator panel and found technical strings supporting the profiling workflow, together with Auto-Begin AI Profiler, ProfilerStart, ProfilerGetData, risk_score, risk_factors, and categoryusage.
The researcher mentioned these strings point out that the profiling workflow is definitely included and that the panel can course of the information wanted to rank victims.
Nevertheless, Varonis couldn’t decide what synthetic intelligence engine is getting used to provide the rankings with out analyzing a stay Dolphin X malware pattern.
The malware additionally operates as a credential stealer, with the operator panel displaying that it targets greater than 300 purposes, together with 9 Chromium and Gecko browsers, 100 cryptocurrency pockets extensions, 65 desktop crypto wallets, 10 password managers, and greater than 30 cloud command-line instruments.
Dolphin X additionally claims to steal .env information, SSH keys, cloud entry tokens, browser login knowledge, cryptocurrency pockets data, and different developer credentials.
As Varonis analyzed the Dolphin X operator panel, builder, and associated community site visitors moderately than a stay malware pattern executing on an contaminated machine, the malware’s marketed assortment capabilities weren’t independently confirmed by the researcher.
Synthetic intelligence has grow to be a preferred instrument amongst menace actors, with it getting used to launch cybercrime companies resembling SpamGPT and AI brokers conducting autonomous cyberattacks.
Dolphin X platform as a substitute makes use of AI to resolve an operational drawback by processing massive quantities of stolen knowledge and mechanically sorting contaminated customers into highest-value victims.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remainder transfer by means of your surroundings unseen.
The Picus whitepaper reveals how breach and assault simulation exams your SIEM and EDR guidelines so threats cease slipping by detection.


