A newly marketed Windows stealer and remote-access tool that combines large-scale credential theft, hidden virtual network computing (HVNC), SOCKS5 proxying, and an AI-based victim-ranking feature.
The malware is advertised by an actor known as “Kontraktnik” and reportedly targets more than 300 applications. Dolphin X is designed to steal far more than browser passwords.
Its advertised data-collection features include cryptocurrency wallets, browser extensions, password managers, .env files, SSH keys, cloud access tokens, and credentials used by developer command-line tools
The malware can reportedly gather data from nine browsers, over 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud CLI tools.
This creates major risk for developers and cloud administrators, because .env files and local SSH directories can contain long-lived credentials for cloud consoles, CI/CD systems, source repositories, and production environments.
Dolphin X packages stolen information into a single archive before exfiltration.

This aligns with MITRE ATT&CK technique T1560, Archive Collected Data, while its theft of browser credentials, password-store data, and credentials stored in files maps to T1555.003, T1555, and T1552.001.
A key feature called AI Profiler tracks application use, browsing behavior, and installed software to assign a score to each infected user.
Operators receive daily summaries that rank victims, allowing them to prioritize systems likely to yield high-value credentials or corporate access.
The operator panel also supports remote builds. Instead of compiling locally, attackers submit configuration settings including command-and-control address, installation path, persistence, and evasion options to the backend. thedolphinx[.]top:8443, where the payload is built remotely.

This delivery model enables the seller to mutate payloads before returning them to operators.
Advertised mutation tiers can alter control flow, instructions, string encryption, import tables, PE timestamps, Rich headers, and section padding changes intended to undermine hash-based blocklists and brittle signature rules.
Dolphin X also advertises HVNC capabilities, which can provide an attacker with a hidden desktop session, and SOCKS5 reverse-proxy functionality that may let operators route traffic through compromised devices.
Its listed features also include process injection, AMSI and ETW patching, direct syscalls, UAC bypasses, Registry Run Key persistence, and scheduled-task persistence.
Security teams should prioritize behavior-based detection, investigate explorer.exe running under a non-default desktop, unusual archive creation from browser and developer credential locations, suspicious access to wallet or password-manager data, and unexpected proxy behavior.
Varonis notes that the analysis examined the operator panel and network traffic; many agent functions remain vendor-advertised claims rather than independently confirmed in a live infection.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.