Dolphin X Stealer Targets 300+ Apps and Profiles Users With AI

    Date: 07/27/2026

    Severity: High

    Summary

    Dolphin X is a stealer and RAT that targets 300+ applications, stealing browser credentials, cryptocurrency wallets, cloud tokens, SSH keys, and developer secrets. Its standout AI Profiler automatically analyzes infected systems to identify and prioritize high-value victims, helping attackers focus on the most valuable targets. The malware also supports HVNC, malware loading, and DDoS capabilities, highlighting the growing use of AI to enhance credential theft and post-compromise operations. 

    Indicators of Compromise (IOC) List  

    Domain/Urls

    backend.thedolphinx.top

    thedolphinx.top

    Hash

    726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "backend.thedolphinx.top" or url like "backend.thedolphinx.top" or siteurl like "backend.thedolphinx.top" or domainname like "thedolphinx.top" or url like "thedolphinx.top" or siteurl like "thedolphinx.top"

    Detection Query 2 :

    sha256hash IN ("726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0")

    Reference: 

    https://www.varonis.com/blog/dolphin-x-stealer   


    Tags

    MalwareStealerRATcryptocurrencyAIHVNCDDoS AttacksCredential HarvestingCloud Infrastructure

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags