Threat Advisory

Dolphin X Malware Targets Over 300 Applications with Credential Collection

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Dolphin X is an advanced information-stealing malware designed to compromise Windows systems and harvest sensitive user data. Marketed as a malware-as-a-service (MaaS) offering, it enables cybercriminals with limited technical expertise to conduct credential theft and financial fraud. The malware targets a wide range of applications, including web browsers, cryptocurrency wallets, messaging platforms, VPN clients, FTP software, and password managers. In addition to stealing stored credentials, cookies, browsing history, and autofill information, Dolphin X collects system details to profile infected devices. The malware is distributed through common infection vectors such as phishing emails, malicious downloads, fake software installers, and cracked applications. Its modular architecture allows operators to continuously add new capabilities and expand the list of supported applications. By focusing on credential theft and session hijacking, Dolphin X provides attackers with access to online accounts and corporate environments, making it a significant threat to both individuals and organizations. Its commercial distribution model also contributes to its widespread adoption among cybercriminal groups.

Dolphin X follows a structured infection process that begins with execution on the victim's system, followed by environment checks and information gathering. The malware enumerates installed software and collects operating system details before extracting credentials, browser cookies, saved passwords, autofill data, browsing history, cryptocurrency wallet files, messaging application data, VPN credentials, and FTP client information. It also captures authentication tokens that can enable session hijacking without requiring user passwords. To evade detection, Dolphin X incorporates obfuscation techniques and anti-analysis checks that help it bypass security tools and sandbox environments. The malware organizes stolen information into categorized archives before compressing and transmitting the data to a remote command-and-control server. Its modular design enables operators to update supported targets and introduce additional stealing capabilities without modifying the overall framework. These features allow Dolphin X to efficiently harvest large volumes of sensitive information while maintaining flexibility for future enhancements.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Dolphin X is an advanced information-stealing malware designed to compromise Windows systems and harvest sensitive user data. Marketed as a malware-as-a-service (MaaS) offering, it enables cybercriminals with limited technical expertise to conduct credential theft and financial fraud. The malware targets a wide range of applications, including web browsers, cryptocurrency wallets, messaging platforms, VPN clients, FTP software, and password managers. In addition to stealing stored credentials, cookies, browsing history, and autofill information, Dolphin X collects system details to profile infected devices. The malware is distributed through common infection vectors such as phishing emails, malicious downloads, fake software installers, and cracked applications. Its modular architecture allows operators to continuously add new capabilities and expand the list of supported applications. By focusing on credential theft and session hijacking, Dolphin X provides attackers with access to online accounts and corporate environments, making it a significant threat to both individuals and organizations. Its commercial distribution model also contributes to its widespread adoption among cybercriminal groups.

Dolphin X follows a structured infection process that begins with execution on the victim's system, followed by environment checks and information gathering. The malware enumerates installed software and collects operating system details before extracting credentials, browser cookies, saved passwords, autofill data, browsing history, cryptocurrency wallet files, messaging application data, VPN credentials, and FTP client information. It also captures authentication tokens that can enable session hijacking without requiring user passwords. To evade detection, Dolphin X incorporates obfuscation techniques and anti-analysis checks that help it bypass security tools and sandbox environments. The malware organizes stolen information into categorized archives before compressing and transmitting the data to a remote command-and-control server. Its modular design enables operators to update supported targets and introduce additional stealing capabilities without modifying the overall framework. These features allow Dolphin X to efficiently harvest large volumes of sensitive information while maintaining flexibility for future enhancements.[emaillocker id="1283"]

Dolphin X demonstrates the continued evolution of information-stealing malware through its modular architecture, broad application support, and malware-as-a-service business model. Its ability to collect credentials, authentication tokens, cryptocurrency wallet data, browser information, and enterprise application credentials enables attackers to conduct account takeovers, financial theft, and follow-on intrusions into corporate networks. The malware's use of obfuscation and anti-analysis techniques further complicates detection and incident response, increasing its effectiveness against traditional security solutions. Organizations can reduce the risk posed by Dolphin X by enforcing multi-factor authentication, disabling password storage in browsers where possible, monitoring for unusual credential usage, deploying endpoint detection solutions, and educating users about phishing and malicious software downloads. Regular software updates, strong endpoint protection, and continuous monitoring of authentication events are also essential for limiting the impact of credential-stealing malware. As information stealers continue to evolve, Dolphin X highlights the growing sophistication and accessibility of credential theft tools within the cybercriminal ecosystem.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1106 Native API -
Persistence T1053.005 Scheduled Task/Job Scheduled Task
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027 Obfuscated Files or Information -
Defence Evasion T1055 Process Injection -
Defence Evasion T1548.002 Abuse Elevation Control Mechanism Bypass User Account Control
Defence Evasion T1562.001 Impair Defenses Disable or Modify Tools
Credential access T1552.001 Unsecured Credentials Credentials In Files
Credential access T1555 Credentials from Password Stores -
Collection T1005 Data from Local System -
Collection T1560 Archive Collected Data -
Command and control T1071.001 Application Layer Protocol Web Protocols

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Discovery E1083 File and Directory Discovery
Defense Evasion B0029 Polymorphic Code
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Persistence F0012 Registry Run Keys / Startup Folder
Anti-Static Analysis E1027 Obfuscated Files or Information
Execution E1204 User Execution
Discovery E1082 System Information Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu