Infostealers Weekly Report: 2024-02-05 – 2024-02-12
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 1,571
- #2 Pakistan 1,298
- #3 Turkey 1,157
- #4 Egypt 1,105
- #5 Mexico 960
- #6 Argentina 934
- #7 Philippines 885
- #8 Colombia 832
- #9 Peru 829
- #10 Vietnam 668
- #11 Bangladesh 659
- #12 Thailand 647
- #13 India 591
- #14 Algeria 555
- #15 Indonesia 533
- #16 Chile 423
- #17 Ecuador 419
- #18 Spain 419
- #19 Morocco 358
- #20 Venezuela 356
- #21 Malaysia 341
- #22 Sri Lanka 339
- #23 Saudi Arabia 313
- #24 Iraq 311
- #25 South Africa 228
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 40,496 users
-
#2
facebook.com 37,417 users
-
#3
live.com 35,166 users
-
#4
com.facebook.katana 19,743 users
-
#5
instagram.com 18,943 users
-
#6
discord.com 17,705 users
-
#7
netflix.com 17,427 users
-
#8
roblox.com 15,442 users
-
#9
amazon.com 13,768 users
-
#10
steampowered.com 13,598 users
-
#11
twitter.com 13,155 users
-
#12
com.instagram.android 12,945 users
-
#13
com.netflix.mediaclient 12,919 users
-
#14
mega.nz 10,928 users
-
#15
paypal.com 10,847 users
-
#16
microsoftonline.com 10,199 users
-
#17
twitch.tv 9,573 users
-
#18
com.roblox.client 9,198 users
-
#19
apple.com 9,123 users
-
#20
spotify.com 9,048 users
-
#21
riotgames.com 8,986 users
-
#22
linkedin.com 8,823 users
-
#23
epicgames.com 8,802 users
-
#24
com.discord 8,598 users
-
#25
com.spotify.music 7,607 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
secop.gov.co 166 employees
-
#2
hostinger.com 148 employees
-
#3
wp.pl 132 employees
-
#4
163.com 106 employees
-
#5
watchit.com 95 employees
-
#6
buenosaires.gob.ar 93 employees
-
#7
rockwellautomation.com 84 employees
-
#8
laureate.net 81 employees
-
#9
inacap.cl 79 employees
-
#10
icicibank.com 74 employees
-
#11
freemail.hu 72 employees
-
#12
yandex.com.tr 70 employees
-
#13
naver.com 70 employees
-
#14
britanico.edu.pe 68 employees
-
#15
utpl.edu.ec 64 employees
-
#16
abv.bg 63 employees
-
#17
cibertec.edu.pe 62 employees
-
#18
tim.it 61 employees
-
#19
rediff.com 60 employees
-
#20
sts.net.pk 60 employees
-
#21
upc.edu.pe 59 employees
-
#22
firstmail.ltd 57 employees
-
#23
banquemisr.com 56 employees
-
#24
jwpub.org 56 employees
-
#25
unc.edu.ar 55 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 84 employees
-
#2
microsoft.com 49 employees
-
#3
netflix.com 22 employees
-
#4
jpmorganchase.com 10 employees
-
#5
amazon.com 9 employees
-
#6
lear.com 8 employees
-
#7
ups.com 8 employees
-
#8
ibm.com 7 employees
-
#9
ford.com 7 employees
-
#10
hp.com 6 employees
-
#11
oracle.com 4 employees
-
#12
insight.com 4 employees
-
#13
csc.com 4 employees
-
#14
nike.com 3 employees
-
#15
ncr.com 3 employees
-
#16
cbrands.com 3 employees
-
#17
xerox.com 2 employees
-
#18
sanmina.com 2 employees
-
#19
disney.com 2 employees
-
#20
publix.com 1 employees
Compromised users
-
#1
google.com 40,496 users
-
#2
facebook.com 37,417 users
-
#3
netflix.com 17,427 users
-
#4
amazon.com 13,768 users
-
#5
paypal.com 10,847 users
-
#6
apple.com 9,123 users
-
#7
ebay.com 1,922 users
-
#8
microsoft.com 1,455 users
-
#9
oracle.com 1,391 users
-
#10
hp.com 1,218 users
-
#11
cisco.com 1,164 users
-
#12
nike.com 1,109 users
-
#13
ibm.com 441 users
-
#14
westernunion.com 355 users
-
#15
ups.com 355 users
-
#16
walmart.com 345 users
-
#17
intel.com 306 users
-
#18
fedex.com 202 users
-
#19
adp.com 142 users
-
#20
salesforce.com 137 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
19,743 users
12,945 users
Netflix
12,919 users
Roblox
9,198 users
Discord
8,598 users
Spotify
7,607 users
Twitch
7,343 users
5,685 users
Snapchat
5,215 users
4,462 users
Wish
3,889 users
PayPal
3,613 users
Disney
3,607 users
Mercadolibre
3,283 users
Mega
3,170 users
Zoom
3,114 users
2,499 users
Waze
2,054 users
Xiaomi
2,035 users
Alibaba
1,938 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,554,437 users
-
#2
hotmail.com 239,267 users
-
#3
yahoo.com 66,520 users
-
#4
outlook.com 43,930 users
-
#5
icloud.com 9,397 users
-
#6
mail.ru 6,462 users
-
#7
live.com 6,351 users
-
#8
hotmail.es 6,316 users
-
#9
msn.com 4,140 users
-
#10
yahoo.fr 3,876 users
-
#11
hotmail.fr 3,847 users
-
#12
yahoo.com.br 3,255 users
-
#13
ymail.com 2,712 users
-
#14
yahoo.com.ar 2,203 users
-
#15
hotmail.com.ar 2,007 users
-
#16
web.de 1,700 users
-
#17
mail.com 1,594 users
-
#18
hotmail.it 1,536 users
-
#19
libero.it 1,443 users
-
#20
yahoo.co.uk 1,311 users
-
#21
gmx.de 1,253 users
-
#22
yandex.com 1,172 users
-
#23
free.fr 1,092 users
-
#24
aol.com 1,066 users
-
#25
yahoo.co.id 1,021 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 38,705machines
- #2 Lumma 17,247machines
- #3 Generic Stealer 3,166machines
Anti-virus Coverage
- #1 Windows Defender 36,205machines
- #2 360 Total Security 1,319machines
- #3 Avast Antivirus 1,122machines
- #4 Reason Cybersecurity 1,008machines
- #5 McAfee Firewall 532machines
- #6 ESET Security 513machines
- #7 McAfee VirusScan 403machines
- #8 McAfee 381machines
- #9 Kaspersky Internet Security 313machines
- #10 AVG Antivirus 248machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 152,168hits
- #2 sso 39,711hits
- #3 zoom 16,973hits
- #4 github 7,304hits
- #5 webmail 5,579hits
- #6 adfs 4,389hits
- #7 oracle 3,195hits
- #8 sap 2,843hits
- #9 zendesk 2,182hits
- #10 vpn 1,844hits
- #11 owa 1,710hits
- #12 ping 1,641hits
- #13 cpanel 1,448hits
- #14 sts 1,374hits
- #15 kaspersky 1,214hits
- #16 extranet 1,209hits
- #17 webex 1,129hits
- #18 st 1,092hits
- #19 imap 1,038hits
- #20 roundcube 867hits
- #21 ftp 863hits
- #22 okta 668hits
- #23 salesforce 368hits
- #24 gitlab 361hits
- #25 twilio 262hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.