Cybersecurity faces a new threat where attackers no longer act blindly. Specialists at Varonis Threat have discovered a new remote access trojan named Dolphin X. The main feature of this program is the built-in AI Profiler system, which uses artificial intelligence to automatically rank infected devices. Now, hackers can receive a ready-made list of the most valuable targets, sorted by priority.

Technology in the Service of Cybercriminals

Information about the emergence of Dolphin X became known after Daniel Kelley from Varonis Threat discovered an advertisement for the malware on one of the cybercrime forums. The seller, hiding under the pseudonym Kontraktnik, positioned the program as a universal remote access tool.

An analysis of the control panel conducted by experts revealed impressive functionality: the system includes 329 functions distributed across ten categories. Among them are powerful tools for stealing credentials from more than 300 different applications.

How the AI Profiler Module Works

The key element of the trojan is the AI Profiler module. This algorithm analyzes data collected from infected computers and assigns an individual risk rating to each system. To build the profile, data on installed applications, visited domains, and other risk factors are used.

The result of the system's work is a daily list of victims, which operators receive already sorted. This allows cybercriminals to focus on systems that will bring maximum profit, saving time on sifting through less significant targets.

Research Limitations and Hidden Capabilities

It is important to note that the research was conducted without running a real sample of Dolphin X on a test system. Experts studied the control panel, the malware builder, and the associated network traffic. Daniel Kelley confirmed the presence of technical strings in the code related to the operation of AI Profiler, however, it was not possible to determine exactly which AI engine is used to generate the ratings.

In addition to ranking victims, the trojan's functionality claims the ability to steal critically important data: .env files, SSH keys, cloud access tokens, browser authorization data, and information about cryptocurrency wallets. Varonis emphasizes that the claimed data collection capabilities were not confirmed in practice, as the original trojan sample was not available for testing.