Infostealers Weekly Report: 2024-01-24 – 2024-01-31
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 1,320
- #2 Turkey 978
- #3 Argentina 925
- #4 Mexico 822
- #5 Philippines 715
- #6 Colombia 699
- #7 Pakistan 668
- #8 Vietnam 651
- #9 Peru 628
- #10 Indonesia 569
- #11 India 543
- #12 Egypt 526
- #13 Thailand 463
- #14 Chile 453
- #15 Spain 447
- #16 Bangladesh 444
- #17 United States of America 324
- #18 Ecuador 302
- #19 Malaysia 277
- #20 Algeria 273
- #21 Venezuela 269
- #22 Morocco 236
- #23 Poland 232
- #24 Sri Lanka 217
- #25 Romania 206
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 34,152 users
-
#2
facebook.com 31,319 users
-
#3
live.com 30,654 users
-
#4
discord.com 17,062 users
-
#5
com.facebook.katana 16,948 users
-
#6
instagram.com 16,484 users
-
#7
roblox.com 15,701 users
-
#8
netflix.com 14,916 users
-
#9
steampowered.com 13,400 users
-
#10
amazon.com 12,301 users
-
#11
com.instagram.android 11,435 users
-
#12
com.netflix.mediaclient 11,420 users
-
#13
twitter.com 11,386 users
-
#14
twitch.tv 9,790 users
-
#15
microsoftonline.com 9,632 users
-
#16
paypal.com 9,370 users
-
#17
mega.nz 9,173 users
-
#18
riotgames.com 9,081 users
-
#19
epicgames.com 9,043 users
-
#20
com.roblox.client 8,924 users
-
#21
spotify.com 8,651 users
-
#22
com.discord 8,053 users
-
#23
apple.com 7,524 users
-
#24
steamcommunity.com 7,396 users
-
#25
linkedin.com 7,347 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 126 employees
-
#2
buenosaires.gob.ar 122 employees
-
#3
hostinger.com 117 employees
-
#4
inacap.cl 115 employees
-
#5
laureate.net 89 employees
-
#6
freemail.hu 87 employees
-
#7
secop.gov.co 80 employees
-
#8
utp.edu.pe 77 employees
-
#9
aruba.it 77 employees
-
#10
aiou.edu.pk 65 employees
-
#11
abv.bg 64 employees
-
#12
icicibank.com 64 employees
-
#13
rediff.com 62 employees
-
#14
utpl.edu.ec 59 employees
-
#15
deped.gov.ph 59 employees
-
#16
yandex.com.tr 57 employees
-
#17
firstmail.ltd 55 employees
-
#18
sempreser.com.br 51 employees
-
#19
pec.it 49 employees
-
#20
ctonline.mx 49 employees
-
#21
aiep.cl 49 employees
-
#22
seznam.cz 47 employees
-
#23
sts.net.pk 47 employees
-
#24
banquemisr.com 46 employees
-
#25
skole.hr 46 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 36 employees
-
#2
microsoft.com 28 employees
-
#3
xerox.com 8 employees
-
#4
ibm.com 7 employees
-
#5
publix.com 5 employees
-
#6
paypal.com 5 employees
-
#7
johnsoncontrols.com 4 employees
-
#8
ford.com 4 employees
-
#9
ecolab.com 4 employees
-
#10
netflix.com 3 employees
-
#11
intel.com 3 employees
-
#12
ebay.com 3 employees
-
#13
baxter.com 3 employees
-
#14
cisco.com 3 employees
-
#15
gm.com 2 employees
-
#16
halliburton.com 2 employees
-
#17
utc.com 2 employees
-
#18
wrberkley.com 2 employees
-
#19
amazon.com 2 employees
-
#20
cognizant.com 1 employees
Compromised users
-
#1
google.com 34,152 users
-
#2
facebook.com 31,319 users
-
#3
netflix.com 14,916 users
-
#4
amazon.com 12,301 users
-
#5
paypal.com 9,370 users
-
#6
apple.com 7,524 users
-
#7
ebay.com 1,684 users
-
#8
microsoft.com 1,365 users
-
#9
nike.com 1,108 users
-
#10
oracle.com 1,103 users
-
#11
hp.com 1,069 users
-
#12
cisco.com 1,003 users
-
#13
walmart.com 373 users
-
#14
ibm.com 372 users
-
#15
ups.com 304 users
-
#16
intel.com 273 users
-
#17
westernunion.com 247 users
-
#18
fedex.com 161 users
-
#19
bestbuy.com 147 users
-
#20
target.com 125 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
16,948 users
11,435 users
Netflix
11,420 users
Roblox
8,924 users
Discord
8,053 users
Twitch
6,658 users
Spotify
6,608 users
4,779 users
Snapchat
4,652 users
Disney
3,365 users
PayPal
3,169 users
Mercadolibre
3,033 users
Wish
2,952 users
Mega
2,783 users
2,650 users
Zoom
2,606 users
Waze
2,005 users
1,949 users
Xiaomi
1,808 users
Alibaba
1,800 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,294,945 users
-
#2
hotmail.com 195,741 users
-
#3
yahoo.com 49,884 users
-
#4
outlook.com 39,544 users
-
#5
icloud.com 9,504 users
-
#6
live.com 8,046 users
-
#7
mail.ru 4,707 users
-
#8
hotmail.es 3,749 users
-
#9
yahoo.com.br 3,495 users
-
#10
msn.com 3,038 users
-
#11
hotmail.fr 2,917 users
-
#12
yahoo.com.ar 2,907 users
-
#13
gmx.de 2,742 users
-
#14
yahoo.fr 2,696 users
-
#15
libero.it 2,166 users
-
#16
yahoo.co.uk 2,139 users
-
#17
live.fr 1,802 users
-
#18
ymail.com 1,483 users
-
#19
hotmail.it 1,397 users
-
#20
web.de 1,217 users
-
#21
telenet.be 1,209 users
-
#22
yahoo.co.id 1,141 users
-
#23
outlook.com.br 1,115 users
-
#24
me.com 1,040 users
-
#25
rambler.ru 1,032 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 40,924machines
- #2 Lumma 9,608machines
- #3 Generic Stealer 420machines
Anti-virus Coverage
- #1 Windows Defender 38,320machines
- #2 360 Total Security 1,249machines
- #3 Reason Cybersecurity 1,182machines
- #4 Avast Antivirus 1,057machines
- #5 McAfee Firewall 661machines
- #6 McAfee VirusScan 479machines
- #7 McAfee 405machines
- #8 ESET Security 339machines
- #9 Kaspersky Internet Security 299machines
- #10 Kaspersky 272machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 131,055hits
- #2 sso 40,412hits
- #3 zoom 14,886hits
- #4 adfs 5,972hits
- #5 github 5,871hits
- #6 webmail 4,054hits
- #7 sap 3,195hits
- #8 oracle 2,099hits
- #9 zendesk 2,049hits
- #10 owa 1,713hits
- #11 ping 1,290hits
- #12 vpn 1,264hits
- #13 extranet 1,126hits
- #14 sts 1,017hits
- #15 cpanel 962hits
- #16 webex 941hits
- #17 kaspersky 917hits
- #18 roundcube 741hits
- #19 ftp 592hits
- #20 st 529hits
- #21 okta 398hits
- #22 salesforce 347hits
- #23 twilio 256hits
- #24 gitlab 226hits
- #25 imap 224hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.