Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors kontraktnik

Also known as: tracked as, Open Source Intelligence, Fancy Bear, Sednit, Forest Blizzard, BlueDelta

Description

Kontraktnik is publicly known as an online fraudster who advertises the Dolphin X credential stealer on cybercrime forums under a seller handle. The delivery mechanism is a remote build service that compiles customized agents from the vendor’s servers, applying a multi‑tier mutation engine to re‑encrypt strings, change import tables, and alter file metadata – ensuring each binary has a unique indicator of compromise (IoC)., Once executed on a victim machine, Dolphin X first scans for credentials across more than 300 targets: Internet browsers (including Chromium‑based), popular crypto wallets (MetaMask, Exodus, etc.), password managers, SSH keys, .env files and cloud CLI tokens. A lightweight ‘AI Profiler’ runs locally to collect system usage data, application install lists, and network activity; results are transmitted to the operator panel, where machines that contain high‑value credentials receive higher priority scores for further exploitation., The RAT supplies full Remote Desktop Control via a hidden HVNC shell, enabling operators to view real‑time keyboard strokes, screenshots and clipboard contents. Persistence is achieved through Registry Run Keys, Startup Folder entries, and Scheduled Tasks; AMSI/ETW patching and native API bypasses protect the implant from endpoint detection. Traffic to command‑and‑control servers is tunneled through a SOCKS5 proxy, frequently changed via custom proxy utilities, and often wrapped in TLS on non‑standard ports (e.g., 8443)., Analysts note that Dolphin X is frequently bundled with the classic remote access tool DWAgent on initial infection vectors such as phishing attachments or malicious GitHub repositories. The combination enables both long‑term covert access and rapid lateral movement using a portfolio of custom malware—Covenant, BeardShell, SlimAgent—to deploy payloads deeper into victim networks.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Healthcare
Government
Transportation
Maritime
Energy

Targeted Countries / Regions

RU
UA
US
TR
AE
PL
DE
IR

AI Analysis

Grounded in web research
· analyzed in 13 chunks · 5 days ago

Executive Summary

Kontraktnik is a malware‑as‑a‑service vendor that sells the Dolphin X Remote Access Trojan (RAT). The malware harvests credentials from over 300 Windows applications—including browsers, crypto wallets, and DevOps tools—and uses an AI profiler to rank targets by value. Operators bundle the RAT with a mutation engine, SOCKS5 proxying, and PowerShell abuse to evade detection and expand lateral movement.

Goals & Targeting

Kontraktnik’s primary objective is financial gain through credential theft. By collecting wide swaths of login data—including DevOps keys and cloud tokens—the actors can sell or use the information to infiltrate target infrastructure, compromise API gateways, and potentially pivot to ransomware or persistent espionage operations. The AI‑driven scoring mechanism reflects a business model that favors high‑value victims; therefore, organizations managing cloud services, web development environments, or cryptocurrencies are especially at risk.

Enhanced Description

Key Capabilities

  • Distribute malware via underground cybercrime forums
  • Offer remote-build service with polymorphic mutation engine (code obfuscation, string re‑encryption, import table changes)
  • Employ AI‑driven victim profiling and scoring to prioritize high‑value targets
  • Harvest credentials from over 300 Windows applications (browsers, crypto wallets, password managers, SSH keys, .env files, cloud CLI tokens)
  • Provide Remote Desktop access via hidden HVNC shell
  • Use SOCKS5 reverse proxy for traffic obfuscation and C2 routing
  • Execute malicious PowerShell commands for persistence and lateral movement
  • Inject code into browser and wallet processes for credential extraction
  • Bypass UAC and patch AMSI/ETW to evade detection
  • Persist via Registry Run Keys, Startup Folder entries, and Scheduled Tasks

MITRE ATT&CK Tactics

Credential Access
Collection
Execution
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Defense Evasion
Command and Control
Discovery
Exfiltration
Impact

ATT&CK Techniques

T1552.001
T1560
T1059.001
T1059.006
T1105
T1021
T1090
T1555
T1055
T1547.001
T1053.005
T1548.003
T1027
T1005
T1083
T1110
T1539
T1555.003
T1548.002
T1562.001
T1106
T1056.001
T1113
T1059.003
T1071.001
T1068

Software / Tooling

Dolphin X RAT
Dolphin X Stealer
Starland RAT
DWAgent
Custom Proxy Tool
BeardShell
Covenant
SlimAgent
Xagent

Campaigns & Victims

Kontraktnik’s operations exhibit a high‑frequency, low‑effort approach typical of cybercrime marketplaces. New malware builds are released weekly via forum postings, and C2 infrastructures cycle through new IP/port combinations on the same day as build requests to avoid detection. Victim profiles range from individual developers using GitHub repositories, to SMEs running web-application stacks that host crypto wallets or devops credentials. The group’s publicized mimicry of ransomware tactics (e.g., naming conventions) suggests a desire to conceal legitimate credential‑theft missions behind a more familiar threat narrative.

IOC Patterns

  • File hash and SHA–256 patterns
  • IP addresses from Russian state infrastructure
  • Domain names such as "thedolphinx.top"
  • Non‑standard HTTPS ports (e.g., 8443)
  • Social media references indicating APT activity
  • .env files, SSH keys, cloud tokens, cryptocurrency wallet data exfiltration targets
  • Large‑scale credential harvesting across 300+ applications
  • AI‑based victim scoring and prioritization indicators

Recommended Actions

  • Block known malicious file hashes and domains associated with Dolphin X
  • Deploy endpoint detection & response (EDR) rules that flag HVNC desktop sessions, keylogging or screenshot capture via unknown shells
  • Monitor for outbound traffic on non‑standard TLS ports, especially those routed through SOCKS5 proxies
  • Implement strict multi‑factor authentication for all DevOps and cloud service accounts; rotate privileged credentials regularly
  • Enforce least privilege on local machines to minimize stored long‑lived secrets (e.g., .env files, SSH keys)
  • Apply timely patches against known malware evasion vectors such as AMSI/ETW tampering
  • Segregate network segments that host high‑value applications (wallets, CI/CD pipelines) and limit lateral traffic
  • Restrict download privileges and screen phishing emails that spoof legitimate tools or meetings
  • Conduct security audits to identify unauthorized remote‑access tools like DWAgent inside the organization

Suggested Tags

Dolphin X
Kontraktnik
Remote Access Trojan
Stealer
Credential Theft
AI Profiling
Malware‑as‑a‑Service
Polymorphic Malware
SOCKS5 Proxy
PowerShell Abuse
.env Exfiltration
SSH Key Theft
Cloud Token Theft
Cryptocurrency Wallet Theft
Remote Build Service
Persistent Persistence

Confidence Assessment

The analysis relies on publicly reported threat‑lab articles, security blogs and cybercrime forum posts that collectively corroborate the existence of Kontraktnik and its Dolphin X offering. While the technical description and capabilities are well supported, there is limited independent attribution evidence linking the actor to a state sponsor; claims of Russian state affiliation derive mainly from IP geolocation patterns rather than definitive forensic data. Consequently, confidence in the technical profile is high, whereas attribution remains moderate pending further corroboration.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

13

Techniques

49

Tools

0

Campaigns

12

IOCs

0

Observed Data

9

Tactics

Tags

malware
credential-theft
Developer Tools
Cloud Infrastructure
High-Value Targeting
Dolphin X
Kontraktnik
Remote Access Trojan
Stealer
Credential Theft
AI Profiling
Malware‑as‑a‑Service
Polymorphic Malware
SOCKS5 Proxy
PowerShell Abuse
.env Exfiltration
SSH Key Theft
Cloud Token Theft
Cryptocurrency Wallet Theft
Remote Build Service
Persistent Persistence

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.