Also known as: tracked as, Open Source Intelligence, Fancy Bear, Sednit, Forest Blizzard, BlueDelta
Kontraktnik is publicly known as an online fraudster who advertises the Dolphin X credential stealer on cybercrime forums under a seller handle. The delivery mechanism is a remote build service that compiles customized agents from the vendor’s servers, applying a multi‑tier mutation engine to re‑encrypt strings, change import tables, and alter file metadata – ensuring each binary has a unique indicator of compromise (IoC)., Once executed on a victim machine, Dolphin X first scans for credentials across more than 300 targets: Internet browsers (including Chromium‑based), popular crypto wallets (MetaMask, Exodus, etc.), password managers, SSH keys, .env files and cloud CLI tokens. A lightweight ‘AI Profiler’ runs locally to collect system usage data, application install lists, and network activity; results are transmitted to the operator panel, where machines that contain high‑value credentials receive higher priority scores for further exploitation., The RAT supplies full Remote Desktop Control via a hidden HVNC shell, enabling operators to view real‑time keyboard strokes, screenshots and clipboard contents. Persistence is achieved through Registry Run Keys, Startup Folder entries, and Scheduled Tasks; AMSI/ETW patching and native API bypasses protect the implant from endpoint detection. Traffic to command‑and‑control servers is tunneled through a SOCKS5 proxy, frequently changed via custom proxy utilities, and often wrapped in TLS on non‑standard ports (e.g., 8443)., Analysts note that Dolphin X is frequently bundled with the classic remote access tool DWAgent on initial infection vectors such as phishing attachments or malicious GitHub repositories. The combination enables both long‑term covert access and rapid lateral movement using a portfolio of custom malware—Covenant, BeardShell, SlimAgent—to deploy payloads deeper into victim networks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Kontraktnik is a malware‑as‑a‑service vendor that sells the Dolphin X Remote Access Trojan (RAT). The malware harvests credentials from over 300 Windows applications—including browsers, crypto wallets, and DevOps tools—and uses an AI profiler to rank targets by value. Operators bundle the RAT with a mutation engine, SOCKS5 proxying, and PowerShell abuse to evade detection and expand lateral movement.
Goals & Targeting
Kontraktnik’s primary objective is financial gain through credential theft. By collecting wide swaths of login data—including DevOps keys and cloud tokens—the actors can sell or use the information to infiltrate target infrastructure, compromise API gateways, and potentially pivot to ransomware or persistent espionage operations. The AI‑driven scoring mechanism reflects a business model that favors high‑value victims; therefore, organizations managing cloud services, web development environments, or cryptocurrencies are especially at risk.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Kontraktnik’s operations exhibit a high‑frequency, low‑effort approach typical of cybercrime marketplaces. New malware builds are released weekly via forum postings, and C2 infrastructures cycle through new IP/port combinations on the same day as build requests to avoid detection. Victim profiles range from individual developers using GitHub repositories, to SMEs running web-application stacks that host crypto wallets or devops credentials. The group’s publicized mimicry of ransomware tactics (e.g., naming conventions) suggests a desire to conceal legitimate credential‑theft missions behind a more familiar threat narrative.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis relies on publicly reported threat‑lab articles, security blogs and cybercrime forum posts that collectively corroborate the existence of Kontraktnik and its Dolphin X offering. While the technical description and capabilities are well supported, there is limited independent attribution evidence linking the actor to a state sponsor; claims of Russian state affiliation derive mainly from IP geolocation patterns rather than definitive forensic data. Consequently, confidence in the technical profile is high, whereas attribution remains moderate pending further corroboration.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
49
Tools
0
Campaigns
12
IOCs
0
Observed Data
9
Tactics