Security researchers have uncovered Dolphin X, a newly emerging Windows-based remote access trojan (RAT) and information stealer that incorporates artificial intelligence to help attackers identify the most valuable compromised systems. Unlike conventional stealers that simply collect and transmit stolen information, Dolphin X analyzes the harvested data to rank victims based on their potential value. This capability enables cybercriminals to focus their efforts on high-priority targets, making attacks more efficient and potentially increasing the success of follow-on activities such as ransomware deployment, business email compromise, and data theft. The malware is designed to gather a broad range of sensitive information from infected devices, including browser credentials, authentication tokens, cryptocurrency wallet data, SSH keys, cloud credentials, and configuration files that may contain secrets. After collecting this information, Dolphin X uses its built-in profiling mechanism to evaluate characteristics such as user privileges, installed software, and system activity. By automatically generating a priority score for each infected endpoint, the malware reduces the manual effort required by threat actors to review stolen data and helps them quickly identify organizations or individuals with elevated access or valuable digital assets. The emergence of AI-assisted malware highlights a growing shift in cybercrime, where automation is increasingly used to improve attack efficiency rather than relying solely on manual analysis. Organizations can reduce their exposure by implementing endpoint detection and response (EDR) solutions, enforcing multi-factor authentication, limiting privileged account access, and continuously monitoring systems for unusual authentication attempts or unauthorized data access. Regular software updates, strong credential management practices, and employee awareness training also remain essential to defending against modern information-stealing malware.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...