Infostealers Weekly Report: 2024-04-15 – 2024-04-22
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 1,870
- #2 Egypt 1,403
- #3 Vietnam 1,289
- #4 India 1,278
- #5 Pakistan 1,201
- #6 Brazil 1,116
- #7 Indonesia 1,068
- #8 Argentina 797
- #9 Thailand 648
- #10 Algeria 633
- #11 Philippines 620
- #12 Bangladesh 613
- #13 Mexico 606
- #14 United States of America 550
- #15 Colombia 518
- #16 Spain 488
- #17 Peru 483
- #18 Venezuela 342
- #19 Morocco 301
- #20 Chile 296
- #21 Germany 289
- #22 Italy 267
- #23 United Kingdom 247
- #24 Ecuador 239
- #25 Saudi Arabia 228
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 31,171 users
-
#2
facebook.com 28,496 users
-
#3
live.com 25,982 users
-
#4
instagram.com 14,679 users
-
#5
com.facebook.katana 14,212 users
-
#6
discord.com 12,864 users
-
#7
netflix.com 12,620 users
-
#8
amazon.com 10,215 users
-
#9
roblox.com 9,977 users
-
#10
twitter.com 9,907 users
-
#11
steampowered.com 9,635 users
-
#12
com.instagram.android 9,534 users
-
#13
com.netflix.mediaclient 9,011 users
-
#14
microsoftonline.com 8,212 users
-
#15
paypal.com 8,045 users
-
#16
192.168.1.1 7,366 users
-
#17
apple.com 7,150 users
-
#18
linkedin.com 7,083 users
-
#19
mega.nz 6,916 users
-
#20
spotify.com 6,794 users
-
#21
twitch.tv 6,749 users
-
#22
riotgames.com 6,381 users
-
#23
epicgames.com 6,219 users
-
#24
com.roblox.client 5,978 users
-
#25
com.discord 5,780 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 109 employees
-
#2
icicibank.com 97 employees
-
#3
wp.pl 96 employees
-
#4
watchit.com 89 employees
-
#5
aruba.it 84 employees
-
#6
tim.it 75 employees
-
#7
banquemisr.com 74 employees
-
#8
163.com 72 employees
-
#9
buenosaires.gob.ar 70 employees
-
#10
bluehost.com 67 employees
-
#11
secop.gov.co 63 employees
-
#12
pec.it 61 employees
-
#13
laureate.net 58 employees
-
#14
firstmail.ltd 56 employees
-
#15
sts.net.pk 56 employees
-
#16
qq.com 56 employees
-
#17
atlassian.com 49 employees
-
#18
yandex.com.tr 48 employees
-
#19
rediff.com 47 employees
-
#20
abv.bg 47 employees
-
#21
skole.hr 46 employees
-
#22
utp.edu.pe 46 employees
-
#23
unionbankonline.co.in 45 employees
-
#24
secureserver.net 45 employees
-
#25
ovh.net 44 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 36 employees
-
#2
microsoft.com 31 employees
-
#3
ibm.com 8 employees
-
#4
amazon.com 7 employees
-
#5
pg.com 7 employees
-
#6
apple.com 6 employees
-
#7
publix.com 5 employees
-
#8
netflix.com 5 employees
-
#9
bestbuy.com 4 employees
-
#10
twc.com 4 employees
-
#11
halliburton.com 4 employees
-
#12
hp.com 3 employees
-
#13
whirlpoolcorp.com 3 employees
-
#14
att.com 3 employees
-
#15
verizon.com 3 employees
-
#16
delta.com 3 employees
-
#17
cablevision.com 3 employees
-
#18
cbre.com 2 employees
-
#19
quantaservices.com 2 employees
-
#20
aa.com 2 employees
Compromised users
-
#1
google.com 31,171 users
-
#2
facebook.com 28,496 users
-
#3
netflix.com 12,620 users
-
#4
amazon.com 10,215 users
-
#5
paypal.com 8,045 users
-
#6
apple.com 7,150 users
-
#7
ebay.com 1,465 users
-
#8
hp.com 1,195 users
-
#9
microsoft.com 1,193 users
-
#10
oracle.com 1,039 users
-
#11
nike.com 855 users
-
#12
cisco.com 842 users
-
#13
walmart.com 458 users
-
#14
ibm.com 368 users
-
#15
ups.com 364 users
-
#16
westernunion.com 308 users
-
#17
fedex.com 219 users
-
#18
intel.com 195 users
-
#19
bestbuy.com 187 users
-
#20
adp.com 167 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
14,212 users
9,534 users
Netflix
9,011 users
Roblox
5,978 users
Discord
5,780 users
Spotify
5,448 users
Twitch
4,555 users
Snapchat
4,216 users
4,048 users
3,770 users
Wish
2,733 users
Disney
2,411 users
PayPal
2,345 users
Zoom
2,262 users
2,081 users
Mega
2,023 users
Mercadolibre
1,656 users
Xiaomi
1,514 users
Alibaba
1,348 users
Waze
1,248 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,240,563 users
-
#2
hotmail.com 165,500 users
-
#3
yahoo.com 56,293 users
-
#4
outlook.com 34,523 users
-
#5
icloud.com 8,722 users
-
#6
yahoo.fr 5,957 users
-
#7
live.com 5,338 users
-
#8
msn.com 4,740 users
-
#9
hotmail.es 3,386 users
-
#10
hotmail.fr 2,913 users
-
#11
libero.it 2,780 users
-
#12
mail.ru 2,563 users
-
#13
web.de 2,382 users
-
#14
live.fr 2,324 users
-
#15
aol.com 2,262 users
-
#16
googlemail.com 2,226 users
-
#17
yahoo.com.ar 2,068 users
-
#18
hotmail.it 1,912 users
-
#19
yahoo.com.br 1,897 users
-
#20
tiscali.it 1,772 users
-
#21
alice.it 1,503 users
-
#22
yandex.com 1,437 users
-
#23
yahoo.co.uk 1,389 users
-
#24
comcast.net 1,358 users
-
#25
mail.com 1,355 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 23,666machines
- #2 Generic Stealer 15,440machines
- #3 Lumma 6,762machines
- #4 DarkCrystal 1,125machines
- #5 Atomic 1machines
Anti-virus Coverage
- #1 Windows Defender 23,020machines
- #2 360 Total Security 802machines
- #3 Reason Cybersecurity 794machines
- #4 Avast Antivirus 789machines
- #5 McAfee Firewall 321machines
- #6 McAfee 307machines
- #7 McAfee VirusScan 277machines
- #8 AVG Antivirus 214machines
- #9 Kaspersky Internet Security 190machines
- #10 ESET Security 186machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 132,730hits
- #2 sso 34,759hits
- #3 zoom 11,285hits
- #4 github 6,345hits
- #5 webmail 4,539hits
- #6 adfs 3,277hits
- #7 oracle 2,323hits
- #8 sap 2,281hits
- #9 owa 1,987hits
- #10 zendesk 1,846hits
- #11 extranet 1,652hits
- #12 ping 1,626hits
- #13 cpanel 1,457hits
- #14 vpn 1,398hits
- #15 sts 1,305hits
- #16 kaspersky 894hits
- #17 webex 820hits
- #18 imap 778hits
- #19 st 718hits
- #20 ftp 681hits
- #21 roundcube 587hits
- #22 okta 576hits
- #23 salesforce 491hits
- #24 citrix 427hits
- #25 twilio 315hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.