New Dolphin X malware uses AI to rank high-value targets

2026-07-24T01:23:32Zdf7b72dfdb70c78328089e56680857cea5f390d18a7d16297a44495d4b6ca128
AI-profilingDolphin-XEverestExchange-OnlineLaundry-BearMicrosoft-365-outageNotepad++PIIRATRefluXFSSectopRATSmartConsoleVoid-BlizzardZimbrabrowser-c2data-breachmalvertisingmalwaremsaRATpersistenceprivilege-escalationransomwareremote-access-trojansupply-chainzero-day

What happened

Multiple high-impact security incidents reported: new malware families (Dolphin X RAT with AI-based victim scoring, msaRAT that tunnels C2 through Chrome/Edge, and SectopRAT distributed via a fake Claude app malvertising campaign) and supply-chain style abuse of Notepad++ plugins to persist malware. Active exploitation of flaws observed — a patched Zimbra zero-click bug used by Russian state-linked Laundry Bear (Void Blizzard) and an actively exploited Check Point SmartConsole zero-day — alongside disclosure of a serious Linux XFS local privilege-escalation race condition (RefluXFS, CVE-2026-6

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
df7b72dfdb70c78328089e56680857cea5f390d18a7d16297a44495d4b6ca128
Enrichment time
2026-07-24T01:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.