Dolphin X turns a steal-everything infostealer into a triage tool. The operator does not have to sift through every infected box by hand; the malware scores them and pushes a ranked list of the ones most likely to hold cloud, SSH, wallet, or DevOps access.
Varonis says the Windows infostealer and RAT targets more than 300 apps, including browser logins, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps credentials. Its operator panel includes an "AI Profiler" that uses application usage, browsing activity, and installed software to produce daily victim rankings, and Varonis analyzed that panel in an isolated lab.
That makes mass infection more efficient. Once credentials are on disk or in browsers, the attacker can quickly surface the highest-value endpoints first, which raises the payoff of any workstation that stores long-lived access.