Skip to content
Weekly intelligence Mar 4 – Mar 11, 2024 13 min read

Infostealers Weekly Report: 2024-03-04 – 2024-03-11

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 65,349 Compromised Machines
#2 13,820 Compromised Employees
#3 13,420 Compromised Users
#4 38,109 Compromised Androids
#5 319,258 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 182
Infections by country

Top 25 countries

  1. #1 Pakistan 2,118
  2. #2 Brazil 1,834
  3. #3 Egypt 1,369
  4. #4 Turkey 1,366
  5. #5 Peru 1,317
  6. #6 India 1,278
  7. #7 Colombia 1,261
  8. #8 Philippines 1,250
  9. #9 Argentina 1,093
  10. #10 Mexico 947
  11. #11 Indonesia 905
  12. #12 Bangladesh 886
  13. #13 Vietnam 856
  14. #14 Algeria 836
  15. #15 Thailand 797
  16. #16 Chile 713
  17. #17 United States of America 705
  18. #18 Ecuador 607
  19. #19 Morocco 587
  20. #20 Malaysia 514
  21. #21 Venezuela 511
  22. #22 Germany 497
  23. #23 Spain 480
  24. #24 Saudi Arabia 471
  25. #25 Bolivia 435

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 44,792 users
  2. #2 facebook.com 40,885 users
  3. #3 live.com 37,581 users
  4. #4 com.facebook.katana 21,787 users
  5. #5 instagram.com 20,666 users
  6. #6 netflix.com 18,307 users
  7. #7 discord.com 17,996 users
  8. #8 amazon.com 15,389 users
  9. #9 roblox.com 15,227 users
  10. #10 com.netflix.mediaclient 14,358 users
  11. #11 twitter.com 14,355 users
  12. #12 com.instagram.android 14,174 users
  13. #13 steampowered.com 13,486 users
  14. #14 paypal.com 11,863 users
  15. #15 microsoftonline.com 11,578 users
  16. #16 mega.nz 11,171 users
  17. #17 linkedin.com 10,120 users
  18. #18 apple.com 9,869 users
  19. #19 twitch.tv 9,753 users
  20. #20 192.168.1.1 9,318 users
  21. #21 com.roblox.client 9,180 users
  22. #22 spotify.com 9,163 users
  23. #23 epicgames.com 8,939 users
  24. #24 com.discord 8,684 users
  25. #25 riotgames.com 8,628 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 hostinger.com 182 employees
  2. #2 secop.gov.co 157 employees
  3. #3 rediff.com 133 employees
  4. #4 icicibank.com 121 employees
  5. #5 watchit.com 112 employees
  6. #6 utp.edu.pe 104 employees
  7. #7 inacap.cl 103 employees
  8. #8 wp.pl 97 employees
  9. #9 buenosaires.gob.ar 95 employees
  10. #10 163.com 93 employees
  11. #11 laureate.net 85 employees
  12. #12 atlassian.com 82 employees
  13. #13 qq.com 75 employees
  14. #14 bluehost.com 73 employees
  15. #15 aruba.it 72 employees
  16. #16 bncr.fi.cr 71 employees
  17. #17 tigo.com.co 70 employees
  18. #18 secureserver.net 69 employees
  19. #19 abv.bg 68 employees
  20. #20 pronabec.edu.pe 67 employees
  21. #21 deped.gov.ph 66 employees
  22. #22 mail.tm 66 employees
  23. #23 sts.net.pk 65 employees
  24. #24 yandex.com.tr 65 employees
  25. #25 tim.it 63 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 rockwellautomation.com 56 employees
  2. #2 microsoft.com 43 employees
  3. #3 intel.com 20 employees
  4. #4 netflix.com 12 employees
  5. #5 ibm.com 9 employees
  6. #6 hp.com 6 employees
  7. #7 ups.com 6 employees
  8. #8 ppg.com 5 employees
  9. #9 twc.com 5 employees
  10. #10 homedepot.com 4 employees
  11. #11 paypal.com 4 employees
  12. #12 att.com 4 employees
  13. #13 manpowergroup.com 3 employees
  14. #14 salesforce.com 3 employees
  15. #15 publix.com 3 employees
  16. #16 amazon.com 3 employees
  17. #17 centurylink.com 3 employees
  18. #18 marriott.com 3 employees
  19. #19 oracle.com 2 employees
  20. #20 frontier.com 2 employees

Compromised users

  1. #1 google.com 44,792 users
  2. #2 facebook.com 40,885 users
  3. #3 netflix.com 18,307 users
  4. #4 amazon.com 15,389 users
  5. #5 paypal.com 11,863 users
  6. #6 apple.com 9,869 users
  7. #7 ebay.com 1,901 users
  8. #8 microsoft.com 1,713 users
  9. #9 oracle.com 1,609 users
  10. #10 hp.com 1,529 users
  11. #11 cisco.com 1,415 users
  12. #12 nike.com 1,035 users
  13. #13 ibm.com 604 users
  14. #14 walmart.com 544 users
  15. #15 westernunion.com 422 users
  16. #16 ups.com 376 users
  17. #17 intel.com 317 users
  18. #18 fedex.com 252 users
  19. #19 bestbuy.com 199 users
  20. #20 att.com 195 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

21,787 users

#2

Netflix

netflix.com · com.netflix.mediaclient

14,358 users

#3

Instagram

instagram.com · com.instagram.android

14,174 users

#4

Roblox

roblox.com · com.roblox.client

9,180 users

#5

Discord

discord.com · com.discord

8,684 users

#6

Spotify

spotify.com · com.spotify.music

8,255 users

#7

Twitch

app.com · tv.twitch.android.app

7,266 users

#8

Snapchat

snapchat.com · com.snapchat.android

6,357 users

#9

Twitter

twitter.com · com.twitter.android

6,209 users

#10

Pinterest

pinterest.com · com.pinterest

5,777 users

#11

Wish

contextlogic.com · com.contextlogic.wish

4,145 users

#12

Disney

disney.com · com.disney.disneyplus

3,742 users

#13

PayPal

paypal.com · com.paypal.android.p2pmobile

3,731 users

#14

Zoom

videomeetings.com · us.zoom.videomeetings

3,550 users

#15

Mercadolibre

mercadolibre.com · com.mercadolibre

3,222 users

#16

Mega

app.com · mega.privacy.android.app

3,207 users

#17

LinkedIn

linkedin.com · com.linkedin.android

3,070 users

#18

Xiaomi

xiaomi.com · com.xiaomi.account

2,419 users

#19

Waze

waze.com · com.waze

2,160 users

#20

Alibaba

alibaba.com · com.alibaba.aliexpresshd

2,099 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 1,810,825 users
  2. #2 hotmail.com 241,643 users
  3. #3 yahoo.com 79,919 users
  4. #4 outlook.com 50,755 users
  5. #5 icloud.com 10,452 users
  6. #6 live.com 6,756 users
  7. #7 yahoo.fr 5,306 users
  8. #8 mail.ru 5,163 users
  9. #9 hotmail.fr 4,935 users
  10. #10 hotmail.es 4,375 users
  11. #11 web.de 4,159 users
  12. #12 msn.com 4,065 users
  13. #13 gmx.de 3,253 users
  14. #14 hotmail.it 2,697 users
  15. #15 yahoo.com.br 2,665 users
  16. #16 libero.it 2,601 users
  17. #17 aol.com 2,509 users
  18. #18 ymail.com 2,338 users
  19. #19 yahoo.com.ar 2,094 users
  20. #20 live.fr 1,928 users
  21. #21 yahoo.it 1,849 users
  22. #22 mail.com 1,757 users
  23. #23 googlemail.com 1,677 users
  24. #24 yahoo.co.uk 1,520 users
  25. #25 yandex.com 1,406 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 40,885 accounts
  2. #2 twitter.com 14,358 accounts
  3. #3 instagram.com 20,666 accounts
  4. #4 linkedin.com 10,123 accounts
  5. #5 pinterest.com 3,469 accounts
  6. #6 tiktok.com 3,695 accounts
  7. #7 snapchat.com 3,710 accounts
  8. #8 reddit.com 1,323 accounts
  9. #9 youtube.com 291 accounts
  10. #10 weibo.com 165 accounts
  11. #11 vk.com 2,274 accounts
  12. #12 telegram.org 308 accounts
  13. #13 tumblr.com 1,000 accounts
  14. #14 discord.com 17,996 accounts
  15. #15 flickr.com 491 accounts
  16. #16 myspace.com 71 accounts
  17. #17 badoo.com 439 accounts
  18. #18 meetup.com 39 accounts
  19. #19 quora.com 249 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 RedLine 34,602machines
  2. #2 Lumma 19,532machines
  3. #3 Generic Stealer 11,212machines
  4. #4 StealC 2machines
  5. #5 racoon 1machines

Anti-virus Coverage

  1. #1 Windows Defender 32,710machines
  2. #2 Reason Cybersecurity 2,009machines
  3. #3 360 Total Security 1,177machines
  4. #4 Avast Antivirus 918machines
  5. #5 McAfee Firewall 569machines
  6. #6 McAfee 459machines
  7. #7 McAfee VirusScan 441machines
  8. #8 ESET Security 358machines
  9. #9 Kaspersky Internet Security 233machines
  10. #10 AVG Antivirus 225machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 172,519hits
  2. #2 sso 40,047hits
  3. #3 zoom 17,426hits
  4. #4 github 9,080hits
  5. #5 webmail 5,565hits
  6. #6 adfs 4,726hits
  7. #7 oracle 3,410hits
  8. #8 sap 2,997hits
  9. #9 zendesk 2,618hits
  10. #10 owa 2,117hits
  11. #11 ping 2,039hits
  12. #12 vpn 1,881hits
  13. #13 cpanel 1,686hits
  14. #14 sts 1,497hits
  15. #15 imap 1,325hits
  16. #16 salesforce 1,325hits
  17. #17 extranet 1,215hits
  18. #18 kaspersky 1,211hits
  19. #19 webex 1,001hits
  20. #20 ftp 934hits
  21. #21 st 837hits
  22. #22 roundcube 732hits
  23. #23 okta 707hits
  24. #24 twilio 447hits
  25. #25 gitlab 359hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure