Infostealers Weekly Report: 2024-04-08 – 2024-04-15
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 3,339
- #2 Brazil 2,754
- #3 Turkey 2,030
- #4 Egypt 2,018
- #5 Mexico 1,520
- #6 Pakistan 1,443
- #7 India 1,443
- #8 Philippines 1,417
- #9 Argentina 1,402
- #10 Peru 1,213
- #11 Thailand 1,168
- #12 Colombia 1,120
- #13 Canada 1,100
- #14 Vietnam 1,001
- #15 Spain 964
- #16 Indonesia 914
- #17 Algeria 850
- #18 Bangladesh 734
- #19 Chile 709
- #20 Germany 692
- #21 France 645
- #22 United Kingdom 606
- #23 Poland 591
- #24 Morocco 581
- #25 Venezuela 536
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 58,327 users
-
#2
facebook.com 52,109 users
-
#3
live.com 50,783 users
-
#4
discord.com 29,267 users
-
#5
instagram.com 28,553 users
-
#6
com.facebook.katana 26,200 users
-
#7
roblox.com 25,792 users
-
#8
netflix.com 24,997 users
-
#9
steampowered.com 22,598 users
-
#10
amazon.com 21,803 users
-
#11
twitter.com 19,824 users
-
#12
twitch.tv 17,713 users
-
#13
com.instagram.android 17,609 users
-
#14
com.netflix.mediaclient 17,433 users
-
#15
paypal.com 17,409 users
-
#16
microsoftonline.com 16,792 users
-
#17
spotify.com 16,124 users
-
#18
epicgames.com 15,872 users
-
#19
riotgames.com 14,872 users
-
#20
apple.com 14,661 users
-
#21
mega.nz 14,501 users
-
#22
com.roblox.client 13,886 users
-
#23
steamcommunity.com 13,319 users
-
#24
com.discord 12,695 users
-
#25
linkedin.com 12,668 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
firstmail.ltd 245 employees
-
#2
watchit.com 238 employees
-
#3
hostinger.com 220 employees
-
#4
wp.pl 210 employees
-
#5
163.com 172 employees
-
#6
secop.gov.co 169 employees
-
#7
rediff.com 164 employees
-
#8
buenosaires.gob.ar 136 employees
-
#9
laureate.net 128 employees
-
#10
icicibank.com 125 employees
-
#11
qq.com 124 employees
-
#12
utp.edu.pe 119 employees
-
#13
banquemisr.com 114 employees
-
#14
seznam.cz 97 employees
-
#15
aruba.it 90 employees
-
#16
yandex.com.tr 84 employees
-
#17
jwpub.org 84 employees
-
#18
abv.bg 80 employees
-
#19
sat.gob.mx 78 employees
-
#20
deped.gov.ph 78 employees
-
#21
secureserver.net 77 employees
-
#22
tim.it 76 employees
-
#23
atlassian.com 75 employees
-
#24
interia.pl 75 employees
-
#25
sempreser.com.br 74 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 64 employees
-
#2
rockwellautomation.com 54 employees
-
#3
publix.com 39 employees
-
#4
apple.com 22 employees
-
#5
cognizant.com 12 employees
-
#6
hp.com 11 employees
-
#7
ibm.com 10 employees
-
#8
netflix.com 9 employees
-
#9
ups.com 8 employees
-
#10
marriott.com 6 employees
-
#11
facebook.com 6 employees
-
#12
ford.com 5 employees
-
#13
fedex.com 4 employees
-
#14
twc.com 4 employees
-
#15
amazon.com 4 employees
-
#16
cablevision.com 4 employees
-
#17
frontier.com 3 employees
-
#18
cbre.com 3 employees
-
#19
pg.com 3 employees
-
#20
att.com 3 employees
Compromised users
-
#1
google.com 58,327 users
-
#2
facebook.com 52,109 users
-
#3
netflix.com 24,997 users
-
#4
amazon.com 21,803 users
-
#5
paypal.com 17,409 users
-
#6
apple.com 14,661 users
-
#7
ebay.com 3,315 users
-
#8
hp.com 2,222 users
-
#9
microsoft.com 2,150 users
-
#10
oracle.com 2,017 users
-
#11
nike.com 1,923 users
-
#12
cisco.com 1,643 users
-
#13
walmart.com 1,366 users
-
#14
ups.com 911 users
-
#15
ibm.com 695 users
-
#16
target.com 686 users
-
#17
adp.com 653 users
-
#18
fedex.com 645 users
-
#19
bestbuy.com 636 users
-
#20
capitalone.com 589 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
26,200 users
17,609 users
Netflix
17,433 users
Roblox
13,886 users
Discord
12,695 users
Spotify
11,087 users
Twitch
10,708 users
Snapchat
7,781 users
7,547 users
7,331 users
Wish
5,570 users
Disney
5,331 users
PayPal
4,710 users
Mega
4,213 users
Mercadolibre
3,954 users
Zoom
3,918 users
3,334 users
Xiaomi
2,878 users
Waze
2,746 users
Alibaba
2,621 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 2,431,951 users
-
#2
hotmail.com 354,986 users
-
#3
yahoo.com 103,296 users
-
#4
outlook.com 73,432 users
-
#5
icloud.com 20,418 users
-
#6
live.com 11,663 users
-
#7
hotmail.es 9,237 users
-
#8
yahoo.fr 8,259 users
-
#9
mail.ru 8,193 users
-
#10
msn.com 6,602 users
-
#11
aol.com 6,264 users
-
#12
hotmail.fr 5,576 users
-
#13
yahoo.com.br 5,482 users
-
#14
gmx.de 5,018 users
-
#15
comcast.net 4,403 users
-
#16
yahoo.com.ar 3,841 users
-
#17
libero.it 3,732 users
-
#18
web.de 3,645 users
-
#19
mail.com 3,083 users
-
#20
ymail.com 3,011 users
-
#21
yandex.ru 2,944 users
-
#22
yahoo.co.uk 2,796 users
-
#23
hotmail.co.uk 2,614 users
-
#24
hotmail.it 2,391 users
-
#25
proton.me 2,079 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 39,459machines
- #2 Generic Stealer 35,436machines
- #3 Lumma 9,478machines
- #4 DarkCrystal 1,142machines
- #5 StealC 636machines
- #6 racoon 627machines
Anti-virus Coverage
- #1 Windows Defender 41,993machines
- #2 360 Total Security 1,616machines
- #3 Reason Cybersecurity 1,595machines
- #4 Avast Antivirus 1,447machines
- #5 McAfee Firewall 738machines
- #6 McAfee VirusScan 708machines
- #7 McAfee 708machines
- #8 AVG Antivirus 519machines
- #9 ESET Security 335machines
- #10 Kaspersky 317machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 260,274hits
- #2 sso 71,576hits
- #3 zoom 20,042hits
- #4 github 12,914hits
- #5 adfs 9,390hits
- #6 webmail 9,098hits
- #7 sap 4,267hits
- #8 oracle 4,165hits
- #9 zendesk 3,981hits
- #10 owa 3,469hits
- #11 ping 3,113hits
- #12 vpn 2,775hits
- #13 extranet 2,626hits
- #14 sts 2,483hits
- #15 cpanel 2,363hits
- #16 ftp 1,701hits
- #17 webex 1,579hits
- #18 kaspersky 1,520hits
- #19 imap 1,432hits
- #20 st 1,381hits
- #21 okta 1,369hits
- #22 roundcube 1,118hits
- #23 salesforce 830hits
- #24 twilio 504hits
- #25 gitlab 494hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.