Threat Brief — 2026-07-26 — Patient malware, resilient scams
Executive summary
A newly described Windows infostealer called Dolphin X takes a patient, reconnaissance-first approach—profiling 300+ applications, 9 browsers, and hundreds of crypto wallets before deciding whether a target is worth robbing. Separately, satellite imagery confirms that scam-compound infrastructure rebuilds within months of law-enforcement raids, underscoring how resilient the cybercrime real-estate pipeline remains. On the defensive side, AI safety filters in ChatGPT and Claude are reportedly blocking legitimate vulnerability research, adding friction to offensive security workflows.
Top items
- Dolphin X: patient Windows stealer profiles before striking. Rather than immediately exfiltrating data, this malware conducts deep system reconnaissance—cataloguing installed applications, browser profiles, and crypto-wallet extensions—then archives everything in a single bundle and evaluates whether the victim is a high-value target. This "study first, rob later" model reduces noise and helps operators prioritise lucrative victims, making detection harder for traditional heuristics that flag mass exfiltration behaviour. (src: securitylab.ru)
- Satellite imagery shows scam compounds rebuilding within months of raids. Comparative satellite analysis reveals that industrial-scale scam operations reconstruct facilities on cleared sites shortly after law-enforcement demolitions, demonstrating that the physical infrastructure behind pig-butchering and similar fraud is effectively self-healing. The speed of reconstruction suggests continued investment and demand, and indicates that takedowns alone are insufficient without sustained pressure. (src: securitylab.ru)
- ChatGPT and Claude filters block vulnerability research. Security researchers report that AI-model safety guardrails in both ChatGPT and Claude are preventing legitimate exploit-development and vulnerability-testing queries, requiring users to prove benign intent before the models will assist. While the filters aim to curb malicious use, they are creating friction for defenders who increasingly rely on LLMs for offensive-research assistance. (src: securitylab.ru)
Themes
Selective and patient malware. Dolphin X joins a recent trend of threat actors favouring reconnaissance-driven targeting over indiscriminate mass theft—similar in spirit to the BlueNoroff wallet-profiling phishing kit reported earlier this week (first reported 2026-07-24, The Hacker News). Operators are increasingly filtering victims before committing payloads, which lowers detection rates and improves ROI.
AI as double-edged sword for security work. The same AI guardrails that curb malicious exploitation are now impeding legitimate researchers—a tension that parallels the "AI pentest agents found NodeBB flaws" story from 2026-07-24 (The Hacker News). The community is simultaneously leveraging AI for defence and bumping against its safety rails.
