Infostealers Weekly Report: 2024-03-25 – 2024-04-01
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 1,643
- #2 Turkey 1,094
- #3 Philippines 1,055
- #4 Egypt 876
- #5 India 857
- #6 Pakistan 808
- #7 Thailand 669
- #8 Argentina 627
- #9 Indonesia 565
- #10 Algeria 471
- #11 Colombia 465
- #12 Mexico 455
- #13 Spain 454
- #14 Bangladesh 427
- #15 Peru 415
- #16 Vietnam 343
- #17 Poland 299
- #18 Morocco 277
- #19 Chile 265
- #20 United States of America 255
- #21 Ecuador 246
- #22 Venezuela 245
- #23 Saudi Arabia 230
- #24 Malaysia 219
- #25 Italy 214
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 25,432 users
-
#2
facebook.com 22,831 users
-
#3
live.com 21,422 users
-
#4
instagram.com 11,703 users
-
#5
com.facebook.katana 11,674 users
-
#6
discord.com 11,125 users
-
#7
netflix.com 10,283 users
-
#8
roblox.com 9,746 users
-
#9
steampowered.com 8,823 users
-
#10
amazon.com 8,034 users
-
#11
twitter.com 7,907 users
-
#12
com.netflix.mediaclient 7,606 users
-
#13
com.instagram.android 7,515 users
-
#14
microsoftonline.com 6,794 users
-
#15
paypal.com 6,402 users
-
#16
twitch.tv 6,291 users
-
#17
mega.nz 5,984 users
-
#18
com.roblox.client 5,716 users
-
#19
riotgames.com 5,700 users
-
#20
epicgames.com 5,698 users
-
#21
spotify.com 5,583 users
-
#22
192.168.1.1 5,395 users
-
#23
linkedin.com 5,383 users
-
#24
apple.com 5,380 users
-
#25
com.discord 5,052 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 126 employees
-
#2
hostinger.com 91 employees
-
#3
rediff.com 74 employees
-
#4
watchit.com 64 employees
-
#5
banquemisr.com 56 employees
-
#6
seznam.cz 55 employees
-
#7
firstmail.ltd 54 employees
-
#8
icicibank.com 54 employees
-
#9
utp.edu.pe 52 employees
-
#10
buenosaires.gob.ar 52 employees
-
#11
163.com 51 employees
-
#12
interia.pl 50 employees
-
#13
freemail.hu 50 employees
-
#14
yandex.com.tr 46 employees
-
#15
laureate.net 46 employees
-
#16
onet.pl 45 employees
-
#17
aruba.it 41 employees
-
#18
telecom.pt 40 employees
-
#19
one.com 40 employees
-
#20
sapo.pt 37 employees
-
#21
secop.gov.co 35 employees
-
#22
qq.com 35 employees
-
#23
bcb.gov.br 32 employees
-
#24
bni.co.id 31 employees
-
#25
microsoft.com 31 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 31 employees
-
#2
rockwellautomation.com 15 employees
-
#3
chs.net 4 employees
-
#4
centurylink.com 4 employees
-
#5
cognizant.com 4 employees
-
#6
aes.com 4 employees
-
#7
abbott.com 3 employees
-
#8
google.com 3 employees
-
#9
lear.com 3 employees
-
#10
hp.com 3 employees
-
#11
netflix.com 3 employees
-
#12
merck.com 3 employees
-
#13
jacobs.com 3 employees
-
#14
nscorp.com 3 employees
-
#15
ibm.com 3 employees
-
#16
parker.com 3 employees
-
#17
conocophillips.com 2 employees
-
#18
generalmills.com 2 employees
-
#19
amazon.com 2 employees
-
#20
express-scripts.com 2 employees
Compromised users
-
#1
google.com 25,432 users
-
#2
facebook.com 22,831 users
-
#3
netflix.com 10,283 users
-
#4
amazon.com 8,034 users
-
#5
paypal.com 6,402 users
-
#6
apple.com 5,380 users
-
#7
ebay.com 1,140 users
-
#8
hp.com 860 users
-
#9
microsoft.com 850 users
-
#10
oracle.com 768 users
-
#11
nike.com 686 users
-
#12
cisco.com 671 users
-
#13
ups.com 248 users
-
#14
ibm.com 241 users
-
#15
walmart.com 241 users
-
#16
westernunion.com 207 users
-
#17
intel.com 167 users
-
#18
fedex.com 131 users
-
#19
adp.com 102 users
-
#20
bestbuy.com 82 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
11,674 users
Netflix
7,606 users
7,515 users
Roblox
5,716 users
Discord
5,052 users
Spotify
4,512 users
Twitch
4,327 users
Snapchat
3,435 users
3,186 users
2,796 users
Disney
2,092 users
Wish
2,053 users
PayPal
2,012 users
Mega
1,818 users
Zoom
1,813 users
Mercadolibre
1,501 users
1,382 users
Xiaomi
1,168 users
Waze
1,145 users
Alibaba
994 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 938,097 users
-
#2
hotmail.com 129,545 users
-
#3
yahoo.com 39,753 users
-
#4
outlook.com 26,934 users
-
#5
icloud.com 5,539 users
-
#6
live.com 5,319 users
-
#7
hotmail.fr 2,615 users
-
#8
yahoo.fr 2,455 users
-
#9
yahoo.com.br 2,407 users
-
#10
hotmail.es 1,878 users
-
#11
mail.ru 1,878 users
-
#12
web.de 1,835 users
-
#13
msn.com 1,627 users
-
#14
yandex.com 1,285 users
-
#15
yahoo.com.ar 1,269 users
-
#16
yahoo.co.uk 1,180 users
-
#17
ymail.com 1,172 users
-
#18
libero.it 855 users
-
#19
protonmail.com 848 users
-
#20
yahoo.co.id 824 users
-
#21
yahoo.co.jp 767 users
-
#22
googlemail.com 761 users
-
#23
rocketmail.com 753 users
-
#24
outlook.com.br 748 users
-
#25
mail.com 730 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 22,369machines
- #2 Generic Stealer 9,409machines
- #3 Lumma 5,879machines
Anti-virus Coverage
- #1 Windows Defender 21,614machines
- #2 Reason Cybersecurity 1,209machines
- #3 Avast Antivirus 935machines
- #4 360 Total Security 931machines
- #5 McAfee Firewall 376machines
- #6 McAfee VirusScan 344machines
- #7 McAfee 297machines
- #8 AVG Antivirus 280machines
- #9 ESET Security 193machines
- #10 Norton Security Ultra 132machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 93,728hits
- #2 sso 22,847hits
- #3 zoom 8,102hits
- #4 github 4,717hits
- #5 webmail 2,843hits
- #6 adfs 2,671hits
- #7 oracle 1,752hits
- #8 zendesk 1,559hits
- #9 sap 1,539hits
- #10 ping 1,275hits
- #11 owa 1,179hits
- #12 vpn 1,053hits
- #13 sts 915hits
- #14 imap 703hits
- #15 kaspersky 670hits
- #16 cpanel 664hits
- #17 webex 603hits
- #18 extranet 528hits
- #19 st 515hits
- #20 roundcube 366hits
- #21 ftp 356hits
- #22 okta 286hits
- #23 gitlab 207hits
- #24 twilio 206hits
- #25 salesforce 170hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.