🟠 High | Source: The Register — Security
A new Windows-based information stealer called Dophin X has been identified, capable of targeting over 300 applications including browsers, crypto wallets, and cloud credential stores. What makes it particularly dangerous is an integrated AI profiling module that analyses stolen data to identify high-value victims and maximise criminal returns. This represents a significant evolution in stealer malware, combining broad credential harvesting with automated victim prioritisation.
Security Architect’s Take: Audit your organisation’s Windows endpoint controls and ensure cloud service credentials, API keys, and session tokens are not persisted in browser storage or local files. Implement short-lived credentials with strict rotation policies, enforce MFA resistant to token theft, and deploy endpoint detection capable of identifying credential-scraping behaviour before exfiltration occurs.
Original advisory: Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits