Dolphin X: A New RAT That Claims to Use AI to Rank Victims by Value
What Happened
BleepingComputer reports on a newly identified remote access trojan (RAT) called Dolphin X. According to the report, the malware includes a profiling feature that its operators claim uses AI to score and rank infected users, intended to help attackers prioritize which victims to target or exploit first.
Details remain limited at this stage — this is a single-source report and the specifics of the "AI-powered" scoring mechanism, how it collects data on victims, or how widely Dolphin X has been deployed have not been independently corroborated or fully disclosed.
Why It Matters for Defenders
Whether or not the AI component turns out to be a marketing claim rather than a technical breakthrough, the underlying idea reflects a broader trend: attackers automating victim triage after initial compromise. A RAT that can automatically flag high-value hosts (e.g., machines with privileged access, financial data, or sensitive credentials) could let threat actors scale operations and focus manual effort on the most lucrative targets, potentially shortening the time between initial infection and follow-on activity like data theft or ransomware deployment.
Any organization susceptible to common RAT delivery vectors (phishing, malicious downloads, drive-by compromise) should consider this a reminder that infections are increasingly followed by rapid, automated post-compromise decision-making.
What Defenders Should Watch For
- General RAT indicators: unexpected outbound connections to unfamiliar C2 infrastructure, persistence mechanisms (scheduled tasks, registry run keys, service creation), and unusual process injection or living-off-the-land binary usage.
- Signs of automated host/data profiling shortly after initial compromise — e.g., rapid enumeration of installed software, user privileges, network shares, or stored credentials, which may indicate a scoring/triage phase.
- Endpoint telemetry correlating a new unsigned or unrecognized process with immediate system reconnaissance commands (whoami, net user, systeminfo, credential store access).
- Threat intel feeds for IOCs (hashes, domains, IPs) associated with Dolphin X as they become available from vendors and researchers.
Developing Story
This is a net-new report and technical analysis is still emerging; claims about Dolphin X's AI capabilities should be treated as unverified pending deeper malware analysis from the security research community. We will continue to monitor for follow-up reporting, IOCs, and any formal detection guidance. Read the original report from BleepingComputer: New Dolphin X malware uses AI to rank high-value targets.