Skip to content
Weekly intelligence Jan 1 – Jan 8, 2024 12 min read

Infostealers Weekly Report: 2024-01-01 – 2024-01-08

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 71,139 Compromised Machines
#2 6,683 Compromised Employees
#3 45,597 Compromised Users
#4 18,859 Compromised Androids
#5 124,602 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 187
Infections by country

Top 25 countries

  1. #1 Brazil 2,181
  2. #2 India 1,543
  3. #3 Egypt 1,270
  4. #4 Turkey 1,157
  5. #5 Pakistan 1,112
  6. #6 Philippines 995
  7. #7 Argentina 759
  8. #8 Mexico 728
  9. #9 Algeria 671
  10. #10 Indonesia 657
  11. #11 Vietnam 565
  12. #12 Bangladesh 539
  13. #13 Thailand 529
  14. #14 Peru 497
  15. #15 Colombia 482
  16. #16 Morocco 473
  17. #17 Iraq 437
  18. #18 Spain 417
  19. #19 Sri Lanka 413
  20. #20 Chile 410
  21. #21 Malaysia 358
  22. #22 United States of America 340
  23. #23 Poland 337
  24. #24 Romania 317
  25. #25 Germany 307

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 23,835 users
  2. #2 facebook.com 21,988 users
  3. #3 live.com 20,402 users
  4. #4 instagram.com 10,141 users
  5. #5 com.facebook.katana 10,132 users
  6. #6 netflix.com 9,865 users
  7. #7 discord.com 9,849 users
  8. #8 roblox.com 8,455 users
  9. #9 steampowered.com 7,700 users
  10. #10 amazon.com 7,340 users
  11. #11 twitter.com 7,228 users
  12. #12 com.netflix.mediaclient 6,640 users
  13. #13 com.instagram.android 6,497 users
  14. #14 paypal.com 6,228 users
  15. #15 mega.nz 6,021 users
  16. #16 microsoftonline.com 5,661 users
  17. #17 twitch.tv 5,458 users
  18. #18 apple.com 5,300 users
  19. #19 spotify.com 5,198 users
  20. #20 riotgames.com 5,171 users
  21. #21 epicgames.com 5,112 users
  22. #22 linkedin.com 4,858 users
  23. #23 com.roblox.client 4,458 users
  24. #24 steamcommunity.com 4,318 users
  25. #25 com.discord 4,143 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 wp.pl 114 employees
  2. #2 hostinger.com 75 employees
  3. #3 abv.bg 71 employees
  4. #4 buenosaires.gob.ar 62 employees
  5. #5 banquemisr.com 61 employees
  6. #6 o2.pl 53 employees
  7. #7 jwpub.org 53 employees
  8. #8 login.sp.gov.br 51 employees
  9. #9 skole.hr 50 employees
  10. #10 freemail.hu 48 employees
  11. #11 yandex.com.tr 45 employees
  12. #12 laureate.net 43 employees
  13. #13 nauta.cu 43 employees
  14. #14 secop.gov.co 43 employees
  15. #15 firstmail.ltd 42 employees
  16. #16 sempreser.com.br 40 employees
  17. #17 bcb.gov.br 39 employees
  18. #18 mail.tm 38 employees
  19. #19 utpl.edu.ec 37 employees
  20. #20 seznam.cz 37 employees
  21. #21 ovh.net 32 employees
  22. #22 mail.bg 32 employees
  23. #23 bluehost.com 32 employees
  24. #24 microsoft.com 32 employees
  25. #25 web-hosting.com 30 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 microsoft.com 32 employees
  2. #2 rockwellautomation.com 27 employees
  3. #3 publix.com 5 employees
  4. #4 ppg.com 5 employees
  5. #5 frontier.com 3 employees
  6. #6 hp.com 3 employees
  7. #7 amazon.com 3 employees
  8. #8 emc.com 2 employees
  9. #9 ibm.com 1 employees
  10. #10 cisco.com 1 employees

Compromised users

  1. #1 google.com 23,835 users
  2. #2 facebook.com 21,988 users
  3. #3 netflix.com 9,865 users
  4. #4 amazon.com 7,340 users
  5. #5 paypal.com 6,228 users
  6. #6 apple.com 5,300 users
  7. #7 ebay.com 1,253 users
  8. #8 microsoft.com 878 users
  9. #9 hp.com 740 users
  10. #10 oracle.com 653 users
  11. #11 cisco.com 632 users
  12. #12 nike.com 519 users
  13. #13 walmart.com 238 users
  14. #14 ibm.com 206 users
  15. #15 westernunion.com 185 users
  16. #16 ups.com 180 users
  17. #17 intel.com 178 users
  18. #18 adp.com 112 users
  19. #19 fedex.com 89 users
  20. #20 bestbuy.com 82 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

10,132 users

#2

Netflix

netflix.com · com.netflix.mediaclient

6,640 users

#3

Instagram

instagram.com · com.instagram.android

6,497 users

#4

Roblox

roblox.com · com.roblox.client

4,458 users

#5

Discord

discord.com · com.discord

4,143 users

#6

Twitch

app.com · tv.twitch.android.app

3,987 users

#7

Spotify

spotify.com · com.spotify.music

3,736 users

#8

Twitter

twitter.com · com.twitter.android

2,791 users

#9

Snapchat

snapchat.com · com.snapchat.android

2,634 users

#10

Disney

disney.com · com.disney.disneyplus

1,954 users

#11

PayPal

paypal.com · com.paypal.android.p2pmobile

1,823 users

#12

Mercadolibre

mercadolibre.com · com.mercadolibre

1,790 users

#13

Mega

app.com · mega.privacy.android.app

1,629 users

#14

Wish

contextlogic.com · com.contextlogic.wish

1,599 users

#15

Zoom

videomeetings.com · us.zoom.videomeetings

1,367 users

#16

LinkedIn

linkedin.com · com.linkedin.android

1,295 users

#17

Waze

waze.com · com.waze

1,149 users

#18

Alibaba

alibaba.com · com.alibaba.aliexpresshd

1,136 users

#19

Xiaomi

xiaomi.com · com.xiaomi.account

1,038 users

#20

Pinterest

pinterest.com · com.pinterest

900 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 861,255 users
  2. #2 hotmail.com 133,715 users
  3. #3 yahoo.com 39,779 users
  4. #4 outlook.com 28,628 users
  5. #5 icloud.com 6,379 users
  6. #6 live.com 4,579 users
  7. #7 hotmail.es 4,514 users
  8. #8 msn.com 4,213 users
  9. #9 yahoo.com.br 4,136 users
  10. #10 yahoo.fr 4,117 users
  11. #11 hotmail.fr 2,946 users
  12. #12 mail.ru 2,929 users
  13. #13 free.fr 2,222 users
  14. #14 googlemail.com 1,630 users
  15. #15 aol.com 1,399 users
  16. #16 libero.it 1,356 users
  17. #17 yandex.com 1,351 users
  18. #18 hotmail.com.ar 1,317 users
  19. #19 live.fr 1,305 users
  20. #20 yahoo.com.ar 1,220 users
  21. #21 mail.com 1,005 users
  22. #22 protonmail.com 995 users
  23. #23 live.co.uk 797 users
  24. #24 web.de 752 users
  25. #25 ymail.com 732 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 21,988 accounts
  2. #2 twitter.com 7,228 accounts
  3. #3 instagram.com 10,141 accounts
  4. #4 linkedin.com 4,863 accounts
  5. #5 pinterest.com 1,720 accounts
  6. #6 tiktok.com 1,622 accounts
  7. #7 snapchat.com 1,776 accounts
  8. #8 reddit.com 807 accounts
  9. #9 youtube.com 94 accounts
  10. #10 weibo.com 34 accounts
  11. #11 vk.com 1,400 accounts
  12. #12 telegram.org 164 accounts
  13. #13 tumblr.com 610 accounts
  14. #14 discord.com 9,849 accounts
  15. #15 flickr.com 250 accounts
  16. #16 myspace.com 27 accounts
  17. #17 badoo.com 329 accounts
  18. #18 meetup.com 29 accounts
  19. #19 quora.com 99 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 RedLine 57,958machines
  2. #2 Lumma 12,770machines
  3. #3 Generic Stealer 411machines

Anti-virus Coverage

  1. #1 Windows Defender 53,282machines
  2. #2 Reason Cybersecurity 2,085machines
  3. #3 Avast Antivirus 1,623machines
  4. #4 360 Total Security 1,540machines
  5. #5 McAfee Firewall 784machines
  6. #6 ESET Security 571machines
  7. #7 McAfee VirusScan 546machines
  8. #8 Kaspersky Internet Security 373machines
  9. #9 McAfee 362machines
  10. #10 Kaspersky 352machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 112,300hits
  2. #2 sso 23,329hits
  3. #3 zoom 9,788hits
  4. #4 github 3,563hits
  5. #5 webmail 3,114hits
  6. #6 adfs 2,270hits
  7. #7 zendesk 1,742hits
  8. #8 sap 1,337hits
  9. #9 extranet 1,282hits
  10. #10 oracle 1,280hits
  11. #11 owa 1,178hits
  12. #12 sts 865hits
  13. #13 vpn 847hits
  14. #14 ping 816hits
  15. #15 kaspersky 792hits
  16. #16 cpanel 755hits
  17. #17 roundcube 582hits
  18. #18 st 525hits
  19. #19 webex 509hits
  20. #20 ftp 492hits
  21. #21 okta 289hits
  22. #22 twilio 177hits
  23. #23 gitlab 167hits
  24. #24 zimbra 153hits
  25. #25 imap 149hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure