This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target

This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target

(Image credit: wk1003mike / Shutterstock) Varonis Threat Labs uncovered Dolphin X, a powerful RAT with 329 features across 10 categoriesIts standout “AI Profiler” ranks victims by usage and sends summaries to attackers dailyMalware is sold on the dark web via subscription tiers, starting at $80 per monthWhat if malware could talk to its operator and tell it which of the infected victims is worth paying attention to, and which not? A few years ago, this might have been science fiction but today, thanks to breakthroughs in Artificial Intelligence (AI), not only is it possible, it’s also already available on the black market.Security researchers Varonis Threat Labs recently disclosed finding a rather revolutionary remote access trojan (RAT) called Dolphin X.Even without advanced AI capabilities, the RAT is quite potent, acting as an infostealer, a Hidden Virtual Network Computing (HVNC), a DDoS botnet, or a loader. Just its infostealer capabilities are nothing short of impressive - it can target more than 300 applications to steal browser passwords, enterprise credentials, cryptocurrency wallet data, DevOps secrets, and different sensitive files, and it comes with 329 features split into 10 categories.AI ProfilerHowever, the AI capability is the one that stunned the researchers. Called “AI Profiler”, the feature ranks victims by app usage, browsing history, and more, sending a daily summary to the attackers.The malware is now being offered on the dark web, where other criminals can subscribe to one of three tiers. The basic tier costs $80 per month, while the top tier is around $230 per month. Lifetime subscription costs $1,140 for basic access, and goes up to $3,420 for the top tier."Dolphin X’s collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials," Varonis said in its write-up. "On the wrong machine, a single infection could expose access to an entire production environment.""Its use of AI is also interesting because it shows us how AI is being integrated into more cybercrime tooling."Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Original Source

Read the full article at Techradar →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.