Kontraktnik is the alias of a cybercrime vendor associated with Dolphin X, a malware-as-a-service offering that combines credential theft and remote access functionality. The actor is known for selling tooling aimed at Windows systems and for operating a server-side build model in which customers submit configuration to a central build service that returns a compiled payload. This architecture gives the vendor centralized control over malware generation and supports optional mutation features intended to hinder static detection. Dolphin X is positioned as an all-in-one criminal platform with broad collection coverage across browsers, cryptocurrency wallets, password managers, and cloud command-line tooling. The malware is especially dangerous to developers and cloud administrators because compromise can expose credentials and artifacts that enable access to broader production environments. The offering also includes an "AI Profiler" feature that ranks infected machines by value using behavioral and application-usage data, allowing operators to prioritize high-value victims efficiently. Observed capabilities associated with Kontraktnik’s offering include credential theft, persistence configuration, defense evasion through optional mutation and code transformation, and post-exploitation access via remote administration features. No high-confidence attribution to a specific country, organization, or state sponsor is currently available, and no confirmed real-world identity or group affiliation has been established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.