Security experts at Varonis Threat Labs have identified a new Windows-based malware called Dolphin X, which employs an AI-driven profiling system to assist cybercriminals in pinpointing their most lucrative targets. Advertised on underground cybercrime forums, this malware is designed to infiltrate over 300 different applications, capturing sensitive data such as cryptocurrency wallets, SSH keys, cloud tokens, and DevOps credentials.

The standout feature of Dolphin X is its sophisticated AI Profiler. This component automatically evaluates and ranks infected users by analyzing their application usage, browsing habits, and installed software. By assigning scores to victims, the malware enables attackers to efficiently identify and exploit high-value targets from potentially thousands of infected machines. This automated ranking system is pivotal because it allows cybercriminals to focus their efforts on the most promising victims, something that would be impossible to do manually on such a scale.

Varonis researchers, after analyzing the malware in a controlled lab setting, discovered that attackers receive daily ranking summaries. These summaries help them to quickly identify users who could provide valuable access or data. The malware's operator panel lists 329 features in ten categories, underscoring the broad scope of data collection. The credential-looter category alone targets over 300 applications, compiling the collected information into a single archive for easy access by attackers.

To counteract this threat, Varonis emphasizes that security teams should focus on specific defensive measures to mitigate the impact of Dolphin X's capabilities.