Date: 07/27/2026
Severity: High
Summary
Dolphin X is a stealer and RAT that targets 300+ applications, stealing browser credentials, cryptocurrency wallets, cloud tokens, SSH keys, and developer secrets. Its standout AI Profiler automatically analyzes infected systems to identify and prioritize high-value victims, helping attackers focus on the most valuable targets. The malware also supports HVNC, malware loading, and DDoS capabilities, highlighting the growing use of AI to enhance credential theft and post-compromise operations.
Indicators of Compromise (IOC) List
Domain/Urls | backend.thedolphinx.top thedolphinx.top |
Hash | 726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "backend.thedolphinx.top" or url like "backend.thedolphinx.top" or siteurl like "backend.thedolphinx.top" or domainname like "thedolphinx.top" or url like "thedolphinx.top" or siteurl like "thedolphinx.top" |
Detection Query 2 : | sha256hash IN ("726e7fe23560fe03ea36163d5f510b494f41a78bf811c92ff219f64b4bfe2be0")
|
Reference:
https://www.varonis.com/blog/dolphin-x-stealer