Infostealers Weekly Report: 2024-08-19 – 2024-08-26
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 957
- #2 Pakistan 837
- #3 Turkey 718
- #4 India 569
- #5 Philippines 562
- #6 Vietnam 530
- #7 Bangladesh 512
- #8 Mexico 506
- #9 Argentina 458
- #10 Peru 411
- #11 Colombia 404
- #12 Egypt 395
- #13 Thailand 359
- #14 Algeria 306
- #15 Indonesia 263
- #16 Taiwan 242
- #17 United States of America 205
- #18 Nigeria 203
- #19 Romania 151
- #20 Iraq 148
- #21 Venezuela 125
- #22 Morocco 124
- #23 Kenya 117
- #24 Chile 102
- #25 Spain 87
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 10,239 users
-
#2
facebook.com 9,297 users
-
#3
live.com 8,275 users
-
#4
instagram.com 4,696 users
-
#5
com.facebook.katana 4,590 users
-
#6
discord.com 4,323 users
-
#7
netflix.com 4,154 users
-
#8
roblox.com 3,397 users
-
#9
amazon.com 3,225 users
-
#10
steampowered.com 3,173 users
-
#11
com.instagram.android 3,009 users
-
#12
twitter.com 2,889 users
-
#13
com.netflix.mediaclient 2,843 users
-
#14
microsoftonline.com 2,479 users
-
#15
mega.nz 2,403 users
-
#16
paypal.com 2,386 users
-
#17
apple.com 2,383 users
-
#18
spotify.com 2,292 users
-
#19
linkedin.com 2,221 users
-
#20
192.168.1.1 2,106 users
-
#21
com.roblox.client 2,014 users
-
#22
twitch.tv 1,960 users
-
#23
yahoo.com 1,954 users
-
#24
riotgames.com 1,926 users
-
#25
epicgames.com 1,915 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 43 employees
-
#2
icicibank.com 40 employees
-
#3
163.com 34 employees
-
#4
rediff.com 32 employees
-
#5
jwpub.org 26 employees
-
#6
firstmail.ltd 25 employees
-
#7
alxswe.com 24 employees
-
#8
utp.edu.pe 23 employees
-
#9
laureate.net 22 employees
-
#10
buenosaires.gob.ar 22 employees
-
#11
upc.edu.pe 21 employees
-
#12
secop.gov.co 21 employees
-
#13
watchit.com 20 employees
-
#14
qq.com 20 employees
-
#15
mail.tm 19 employees
-
#16
hinet.net 19 employees
-
#17
skole.hr 18 employees
-
#18
deped.gov.ph 17 employees
-
#19
sts.net.pk 16 employees
-
#20
yandex.com.tr 16 employees
-
#21
netpnb.com 15 employees
-
#22
abv.bg 15 employees
-
#23
banquemisr.com 14 employees
-
#24
sempreser.com.br 14 employees
-
#25
wp.pl 13 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 9 employees
-
#2
rockwellautomation.com 8 employees
-
#3
att.com 4 employees
-
#4
publix.com 2 employees
-
#5
xerox.com 2 employees
-
#6
cognizant.com 2 employees
-
#7
ebay.com 1 employees
-
#8
jacobs.com 1 employees
-
#9
honeywell.com 1 employees
-
#10
bestbuy.com 1 employees
-
#11
walmart.com 1 employees
-
#12
visa.com 1 employees
-
#13
ups.com 1 employees
-
#14
citigroup.com 1 employees
-
#15
ryder.com 1 employees
-
#16
oxy.com 1 employees
-
#17
netflix.com 1 employees
-
#18
fanniemae.com 1 employees
-
#19
charter.com 1 employees
-
#20
paypal.com 1 employees
Compromised users
-
#1
google.com 10,239 users
-
#2
facebook.com 9,297 users
-
#3
netflix.com 4,154 users
-
#4
amazon.com 3,225 users
-
#5
paypal.com 2,386 users
-
#6
apple.com 2,383 users
-
#7
ebay.com 431 users
-
#8
hp.com 371 users
-
#9
microsoft.com 355 users
-
#10
oracle.com 322 users
-
#11
cisco.com 273 users
-
#12
nike.com 233 users
-
#13
walmart.com 109 users
-
#14
ibm.com 107 users
-
#15
ups.com 67 users
-
#16
intel.com 61 users
-
#17
fedex.com 60 users
-
#18
target.com 53 users
-
#19
bestbuy.com 47 users
-
#20
adp.com 46 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
4,590 users
3,009 users
Netflix
2,843 users
Roblox
2,014 users
Discord
1,894 users
Twitch
1,384 users
Spotify
1,355 users
1,341 users
Snapchat
1,250 users
Disney
730 users
Zoom
727 users
PayPal
700 users
Mercadolibre
661 users
Mega
651 users
522 users
Xiaomi
481 users
Wish
476 users
Alibaba
413 users
Waze
383 users
359 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 380,900 users
-
#2
hotmail.com 50,964 users
-
#3
yahoo.com 20,643 users
-
#4
outlook.com 10,914 users
-
#5
icloud.com 2,647 users
-
#6
live.com 1,743 users
-
#7
yahoo.fr 1,227 users
-
#8
mail.com 1,091 users
-
#9
mail.ru 785 users
-
#10
hotmail.fr 684 users
-
#11
yahoo.com.br 672 users
-
#12
hotmail.es 591 users
-
#13
hotmail.co.uk 565 users
-
#14
rocketmail.com 551 users
-
#15
aol.com 534 users
-
#16
msn.com 465 users
-
#17
yahoo.com.ar 414 users
-
#18
orange.fr 408 users
-
#19
live.com.mx 348 users
-
#20
googlemail.com 315 users
-
#21
yandex.com 310 users
-
#22
t-online.de 309 users
-
#23
yahoo.co.id 283 users
-
#24
ymail.com 271 users
-
#25
proton.me 216 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 11,841machines
- #2 StealC 4,287machines
- #3 Lumma 187machines
- #4 Generic Stealer 107machines
Anti-virus Coverage
- #1 Windows Defender 11,207machines
- #2 Reason Cybersecurity 797machines
- #3 360 Total Security 612machines
- #4 Avast Antivirus 570machines
- #5 McAfee 221machines
- #6 McAfee Firewall 147machines
- #7 McAfee VirusScan 131machines
- #8 AVG Antivirus 110machines
- #9 Kaspersky 86machines
- #10 Kaspersky Internet Security 84machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 39,678hits
- #2 sso 11,164hits
- #3 zoom 4,060hits
- #4 github 2,137hits
- #5 webmail 1,166hits
- #6 adfs 1,073hits
- #7 sap 624hits
- #8 oracle 621hits
- #9 zendesk 499hits
- #10 owa 467hits
- #11 ping 449hits
- #12 vpn 443hits
- #13 cpanel 416hits
- #14 sts 366hits
- #15 kaspersky 317hits
- #16 roundcube 282hits
- #17 st 238hits
- #18 webex 188hits
- #19 extranet 182hits
- #20 ftp 176hits
- #21 okta 141hits
- #22 imap 109hits
- #23 salesforce 108hits
- #24 twilio 80hits
- #25 gitlab 69hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.