At a Glance
| Actor or group | A vendor using the alias “Kontraktnik”; no real identity published |
| Activity type | Malware-as-a-service sales of a credential stealer and remote access tool |
| Targets | Windows users, with developers and cloud administrators most at risk |
| Scale | No victim count or revenue figure published; 329 advertised features |
| Law-enforcement status | No arrests, charges, or takedowns reported |
| Source | Varonis Threat Labs |
TL;DR
Varonis Threat Labs bought its way into the Dolphin X stealer panel and studied it in an isolated lab. The tool advertises more than 300 credential targets and an AI Profiler that ranks infected machines by value. Nobody has been arrested or charged.
What Happened
Researchers spotted the listing on a cybercrime forum, where the seller pitched Dolphin X as an all-in-one product. Analysts then obtained the operator panel and pulled it apart.
The panel turns out to be a thin client. Operators pick a C2 address, an install path, persistence, and evasion settings, but nothing compiles locally. Instead, the configuration goes to the vendor’s build server, which returns a finished binary.
Mutation Sold as an Upgrade
That routing gives the seller a chokepoint. An opt-in mutation engine offers three advertised tiers, with the deeper two gated behind a PRO plan. The top tier claims to rewrite control flow and re-encrypt strings. Notably, the engine ships off by default, so unmodified builds share one hash.

Who Is Behind It
Attribution stops at a handle. Varonis names only the alias “Kontraktnik,” and links the seller to no country, group, or real identity. Treat every capability claim as vendor marketing until independently verified.
Impact and Scale
The collection scope is the real story. One archive can hold data from nine browsers, over 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools.
Developer machines make that dangerous. Varonis warns that “a single infection could expose access to an entire production environment.” The surveillance tab then adds an AI Profiler, which the seller markets as an “AI behavioral profiler with app usage tracking, risk score, and daily summary.” Operators use those rankings to triage thousands of victims quickly.
How to Stay Protected
- Keep long-lived credentials off disk, especially in project folders and local stores.
- Treat anything cached locally as already exposed after an infection.
- Hunt behaviour rather than hashes, since server-side mutation defeats static signatures.
- Watch for explorer.exe running under a non-default desktop, a strong HVNC indicator.
- Rotate cloud tokens and SSH keys on any suspect endpoint.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.