Infostealers Weekly Report: 2023-10-02 – 2023-10-09
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 15,966
- #2 Unknown Region 13,565
- #3 Pakistan 9,915
- #4 Turkey 9,723
- #5 Indonesia 8,482
- #6 Egypt 8,275
- #7 India 8,210
- #8 Philippines 7,336
- #9 Thailand 6,280
- #10 Bangladesh 5,304
- #11 United States of America 4,298
- #12 Mexico 4,250
- #13 Vietnam 4,189
- #14 Peru 3,771
- #15 Algeria 3,291
- #16 Morocco 3,216
- #17 Colombia 3,041
- #18 Iraq 2,616
- #19 Unknown 2,606
- #20 Sri Lanka 2,393
- #21 Germany 2,388
- #22 Malaysia 2,092
- #23 Spain 2,067
- #24 Italy 1,945
- #25 Nigeria 1,941
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 82,061 users
-
#2
facebook.com 73,401 users
-
#3
live.com 68,684 users
-
#4
instagram.com 36,865 users
-
#5
discord.com 34,003 users
-
#6
com.facebook.katana 33,788 users
-
#7
netflix.com 32,303 users
-
#8
amazon.com 27,825 users
-
#9
roblox.com 27,000 users
-
#10
twitter.com 26,378 users
-
#11
steampowered.com 25,504 users
-
#12
com.instagram.android 23,390 users
-
#13
paypal.com 22,998 users
-
#14
com.netflix.mediaclient 21,691 users
-
#15
microsoftonline.com 21,109 users
-
#16
linkedin.com 20,177 users
-
#17
apple.com 19,149 users
-
#18
mega.nz 18,540 users
-
#19
riotgames.com 18,220 users
-
#20
twitch.tv 18,192 users
-
#21
spotify.com 17,942 users
-
#22
epicgames.com 16,381 users
-
#23
com.discord 14,988 users
-
#24
zoom.us 14,759 users
-
#25
steamcommunity.com 14,527 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 349 employees
-
#2
icicibank.com 316 employees
-
#3
wp.pl 280 employees
-
#4
aruba.it 265 employees
-
#5
rediff.com 199 employees
-
#6
163.com 194 employees
-
#7
laureate.net 159 employees
-
#8
banquemisr.com 154 employees
-
#9
sempreser.com.br 150 employees
-
#10
alxswe.com 148 employees
-
#11
freemail.hu 146 employees
-
#12
pec.it 143 employees
-
#13
secureserver.net 133 employees
-
#14
tim.it 130 employees
-
#15
o2.pl 127 employees
-
#16
rockwellautomation.com 125 employees
-
#17
abv.bg 125 employees
-
#18
aiou.edu.pk 120 employees
-
#19
qq.com 119 employees
-
#20
secop.gov.co 115 employees
-
#21
jwpub.org 112 employees
-
#22
bcb.gov.br 110 employees
-
#23
sts.net.pk 110 employees
-
#24
netpnb.com 108 employees
-
#25
bluehost.com 107 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 125 employees
-
#2
microsoft.com 72 employees
-
#3
ibm.com 38 employees
-
#4
publix.com 18 employees
-
#5
cognizant.com 13 employees
-
#6
att.com 10 employees
-
#7
netflix.com 9 employees
-
#8
paypal.com 8 employees
-
#9
cablevision.com 6 employees
-
#10
hp.com 6 employees
-
#11
twc.com 5 employees
-
#12
apple.com 5 employees
-
#13
jpmorganchase.com 4 employees
-
#14
genesishcc.com 4 employees
-
#15
oracle.com 3 employees
-
#16
cisco.com 3 employees
-
#17
ups.com 3 employees
-
#18
henryschein.com 3 employees
-
#19
morganstanley.com 3 employees
-
#20
pg.com 3 employees
Compromised users
-
#1
google.com 82,061 users
-
#2
facebook.com 73,401 users
-
#3
netflix.com 32,303 users
-
#4
amazon.com 27,825 users
-
#5
paypal.com 22,998 users
-
#6
apple.com 19,149 users
-
#7
ebay.com 4,653 users
-
#8
oracle.com 3,461 users
-
#9
microsoft.com 3,303 users
-
#10
cisco.com 2,817 users
-
#11
hp.com 2,661 users
-
#12
nike.com 2,135 users
-
#13
ibm.com 1,107 users
-
#14
walmart.com 1,095 users
-
#15
ups.com 900 users
-
#16
westernunion.com 819 users
-
#17
fedex.com 513 users
-
#18
intel.com 505 users
-
#19
bestbuy.com 463 users
-
#20
adp.com 445 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
33,788 users
23,390 users
Netflix
21,691 users
Discord
14,988 users
Roblox
13,671 users
Spotify
12,403 users
Twitch
11,419 users
10,212 users
Snapchat
9,793 users
PayPal
6,247 users
Zoom
5,348 users
5,210 users
Mega
5,168 users
Wish
4,811 users
Disney
4,587 users
Mercadolibre
4,238 users
Alibaba
4,140 users
Waze
4,111 users
Xiaomi
3,759 users
2,525 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 3,241,851 users
-
#2
hotmail.com 408,072 users
-
#3
yahoo.com 163,422 users
-
#4
outlook.com 91,097 users
-
#5
icloud.com 25,164 users
-
#6
live.com 17,534 users
-
#7
hotmail.fr 13,412 users
-
#8
mail.ru 10,200 users
-
#9
yahoo.fr 9,801 users
-
#10
yahoo.com.br 9,743 users
-
#11
libero.it 8,593 users
-
#12
msn.com 7,419 users
-
#13
ymail.com 7,054 users
-
#14
orange.fr 7,028 users
-
#15
gmx.de 5,736 users
-
#16
aol.com 5,561 users
-
#17
hotmail.it 5,274 users
-
#18
yahoo.co.id 5,101 users
-
#19
googlemail.com 4,684 users
-
#20
free.fr 4,508 users
-
#21
hotmail.es 4,464 users
-
#22
web.de 3,981 users
-
#23
yahoo.it 3,828 users
-
#24
mail.com 3,823 users
-
#25
live.fr 3,326 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 117,972machines
- #2 Lumma 69,219machines
- #3 Mystic 2,203machines
- #4 Generic Stealer 1,363machines
- #5 StealC 17machines
Anti-virus Coverage
- #1 Windows Defender 106,372machines
- #2 Avast Antivirus 3,822machines
- #3 360 Total Security 3,767machines
- #4 Reason Cybersecurity 3,306machines
- #5 McAfee Firewall 2,255machines
- #6 McAfee VirusScan 1,807machines
- #7 AVG Antivirus 1,045machines
- #8 ESET Security 858machines
- #9 Kaspersky Internet Security 682machines
- #10 Norton Security Ultra 653machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 336,847hits
- #2 sso 87,012hits
- #3 zoom 33,000hits
- #4 github 18,162hits
- #5 webmail 14,174hits
- #6 adfs 9,601hits
- #7 oracle 7,214hits
- #8 sap 6,049hits
- #9 zendesk 5,243hits
- #10 owa 5,007hits
- #11 cpanel 4,400hits
- #12 ping 4,132hits
- #13 vpn 4,023hits
- #14 sts 3,288hits
- #15 webex 2,713hits
- #16 kaspersky 2,468hits
- #17 ftp 2,105hits
- #18 st 1,887hits
- #19 roundcube 1,788hits
- #20 extranet 1,722hits
- #21 imap 1,664hits
- #22 okta 1,253hits
- #23 twilio 1,038hits
- #24 salesforce 1,032hits
- #25 gitlab 952hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-15 – 2026-06-22
- 16K machines
- 3K users
- 216K domains
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.