Infostealers Weekly Report: 2024-06-10 – 2024-06-17
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,221
- #2 Indonesia 1,556
- #3 Pakistan 997
- #4 Egypt 927
- #5 Thailand 874
- #6 Turkey 742
- #7 Philippines 600
- #8 Brazil 586
- #9 Mexico 522
- #10 Vietnam 511
- #11 Argentina 435
- #12 Colombia 425
- #13 Taiwan 396
- #14 Bangladesh 386
- #15 Peru 367
- #16 Spain 344
- #17 Chile 306
- #18 Venezuela 245
- #19 Algeria 236
- #20 Saudi Arabia 201
- #21 Morocco 200
- #22 Malaysia 199
- #23 Sri Lanka 184
- #24 South Korea 180
- #25 Poland 175
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 17,289 users
-
#2
facebook.com 14,350 users
-
#3
live.com 13,235 users
-
#4
instagram.com 7,390 users
-
#5
com.facebook.katana 6,618 users
-
#6
netflix.com 6,032 users
-
#7
discord.com 5,926 users
-
#8
amazon.com 4,925 users
-
#9
twitter.com 4,758 users
-
#10
roblox.com 4,653 users
-
#11
steampowered.com 4,536 users
-
#12
com.instagram.android 4,415 users
-
#13
microsoftonline.com 4,259 users
-
#14
com.netflix.mediaclient 3,993 users
-
#15
paypal.com 3,853 users
-
#16
linkedin.com 3,831 users
-
#17
apple.com 3,730 users
-
#18
192.168.1.1 3,551 users
-
#19
mega.nz 3,506 users
-
#20
spotify.com 3,497 users
-
#21
riotgames.com 3,149 users
-
#22
twitch.tv 2,886 users
-
#23
epicgames.com 2,829 users
-
#24
yahoo.com 2,716 users
-
#25
com.discord 2,626 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 100 employees
-
#2
hostinger.com 83 employees
-
#3
rediff.com 75 employees
-
#4
wp.pl 56 employees
-
#5
watchit.com 41 employees
-
#6
netpnb.com 38 employees
-
#7
laureate.net 34 employees
-
#8
freemail.hu 33 employees
-
#9
inacap.cl 30 employees
-
#10
bobibanking.com 29 employees
-
#11
atlassian.com 27 employees
-
#12
163.com 27 employees
-
#13
buenosaires.gob.ar 26 employees
-
#14
icai.org 26 employees
-
#15
alxswe.com 26 employees
-
#16
banquemisr.com 26 employees
-
#17
secureserver.net 25 employees
-
#18
utp.edu.pe 25 employees
-
#19
naver.com 24 employees
-
#20
sts.net.pk 23 employees
-
#21
deped.gov.ph 23 employees
-
#22
o2.pl 23 employees
-
#23
rockwellautomation.com 23 employees
-
#24
aiou.edu.pk 23 employees
-
#25
aruba.it 23 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 23 employees
-
#2
microsoft.com 20 employees
-
#3
ibm.com 10 employees
-
#4
netflix.com 4 employees
-
#5
cisco.com 3 employees
-
#6
intel.com 2 employees
-
#7
ingrammicro.com 2 employees
-
#8
ups.com 1 employees
-
#9
ge.com 1 employees
-
#10
allstate.com 1 employees
-
#11
csc.com 1 employees
-
#12
emc.com 1 employees
-
#13
facebook.com 1 employees
-
#14
pepsico.com 1 employees
-
#15
viacom.com 1 employees
-
#16
amazon.com 1 employees
-
#17
hp.com 1 employees
-
#18
apple.com 1 employees
-
#19
fisglobal.com 1 employees
-
#20
disney.com 1 employees
Compromised users
-
#1
google.com 17,289 users
-
#2
facebook.com 14,350 users
-
#3
netflix.com 6,032 users
-
#4
amazon.com 4,925 users
-
#5
paypal.com 3,853 users
-
#6
apple.com 3,730 users
-
#7
ebay.com 800 users
-
#8
microsoft.com 600 users
-
#9
hp.com 594 users
-
#10
oracle.com 569 users
-
#11
cisco.com 506 users
-
#12
nike.com 362 users
-
#13
ibm.com 207 users
-
#14
ups.com 160 users
-
#15
walmart.com 144 users
-
#16
westernunion.com 133 users
-
#17
intel.com 114 users
-
#18
fedex.com 82 users
-
#19
salesforce.com 62 users
-
#20
americanexpress.com 61 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
6,618 users
4,415 users
Netflix
3,993 users
Discord
2,626 users
Roblox
2,544 users
Spotify
2,098 users
1,886 users
Snapchat
1,819 users
Twitch
1,784 users
Zoom
1,081 users
PayPal
1,078 users
Mega
944 users
Disney
930 users
895 users
Wish
814 users
721 users
Xiaomi
699 users
Mercadolibre
669 users
Waze
668 users
Alibaba
590 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 592,691 users
-
#2
hotmail.com 74,924 users
-
#3
yahoo.com 22,712 users
-
#4
outlook.com 18,024 users
-
#5
icloud.com 4,081 users
-
#6
live.com 1,847 users
-
#7
yahoo.co.uk 1,822 users
-
#8
mail.ru 1,691 users
-
#9
yahoo.co.id 1,321 users
-
#10
hotmail.es 1,321 users
-
#11
yahoo.fr 1,294 users
-
#12
gmx.net 1,239 users
-
#13
msn.com 1,233 users
-
#14
web.de 827 users
-
#15
mail.com 810 users
-
#16
protonmail.com 802 users
-
#17
libero.it 798 users
-
#18
yahoo.com.br 733 users
-
#19
ymail.com 718 users
-
#20
hotmail.fr 628 users
-
#21
t-online.de 560 users
-
#22
gmx.de 542 users
-
#23
free.fr 540 users
-
#24
proton.me 535 users
-
#25
yahoo.com.ar 512 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 12,519machines
- #2 Generic Stealer 11,762machines
- #3 StealC 2,902machines
- #4 Lumma 113machines
Anti-virus Coverage
- #1 Windows Defender 11,855machines
- #2 Avast Antivirus 457machines
- #3 360 Total Security 415machines
- #4 Reason Cybersecurity 372machines
- #5 McAfee 237machines
- #6 McAfee Firewall 188machines
- #7 McAfee VirusScan 153machines
- #8 AVG Antivirus 96machines
- #9 Kaspersky 80machines
- #10 Kaspersky Internet Security 74machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 66,050hits
- #2 sso 17,335hits
- #3 zoom 5,769hits
- #4 github 3,267hits
- #5 webmail 2,531hits
- #6 adfs 1,588hits
- #7 oracle 1,149hits
- #8 sts 1,136hits
- #9 sap 980hits
- #10 zendesk 871hits
- #11 owa 829hits
- #12 ping 739hits
- #13 cpanel 712hits
- #14 vpn 670hits
- #15 roundcube 477hits
- #16 webex 473hits
- #17 kaspersky 466hits
- #18 st 393hits
- #19 ftp 385hits
- #20 extranet 317hits
- #21 okta 277hits
- #22 salesforce 197hits
- #23 imap 175hits
- #24 gitlab 149hits
- #25 dana-na 116hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.