Researchers say a new Windows malware service called Dolphin X is being sold to criminals to steal passwords, enterprise secrets, and cryptocurrency from infected users. Varonis says the stealer and remote-access trojan (RAT) claims support for more than 300 applications and theft of browser credentials, SSH keys, cloud tokens, .env files, DevOps secrets, and crypto wallets, plus an 'AI Profiler' that scores victims by app use, browsing history, and installed software so operators can prioritize the most profitable targets. The seller also advertises loader, hidden virtual desktop control, and distributed denial-of-service capabilities.
Why it matters: This could increase the damage from commodity malware by helping criminals quickly identify which infected people or employees are worth deeper follow-on attacks. Organizations should treat stealer infections as high risk, watch for credential and token theft on Windows endpoints, and rotate exposed passwords, keys, and cloud secrets if compromise is suspected.
SecurityWeek News
2026.07.24
92% relevant
This article reiterates that Dolphin X uses an AI behavioral profiler to score infected users and steal data from more than 300 applications, adding mainstream summary coverage of the malware’s targeting of browser passwords, wallets, SSH keys, and cloud tokens.
Lawrence Abrams
2026.07.23
99% relevant
This is the same underlying event: reporting on the Dolphin X malware platform and its AI-based profiling feature that scores infected victims, along with its claimed theft of credentials, cloud tokens, SSH keys, and cryptocurrency wallet data from 300+ applications.
2026.07.22
100% relevant
This article appears to be the first substantive reporting establishing Dolphin X as a distinct malware offering and documents its capabilities, sales model, and victim-ranking feature.
← Back to all stories