Infostealers Weekly Report: 2024-09-16 – 2024-09-23
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 689
- #2 Pakistan 515
- #3 Turkey 438
- #4 Thailand 427
- #5 Egypt 411
- #6 Mexico 362
- #7 Peru 346
- #8 India 344
- #9 Argentina 325
- #10 Colombia 321
- #11 Philippines 311
- #12 Vietnam 244
- #13 Spain 227
- #14 Indonesia 212
- #15 Bangladesh 210
- #16 Chile 192
- #17 Ecuador 153
- #18 Algeria 150
- #19 Morocco 136
- #20 Poland 128
- #21 Venezuela 124
- #22 Iraq 120
- #23 South Korea 112
- #24 United States of America 105
- #25 Iran 105
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 10,537 users
-
#2
facebook.com 9,004 users
-
#3
live.com 8,407 users
-
#4
instagram.com 4,495 users
-
#5
com.facebook.katana 4,335 users
-
#6
discord.com 4,318 users
-
#7
netflix.com 4,077 users
-
#8
roblox.com 3,501 users
-
#9
steampowered.com 3,236 users
-
#10
amazon.com 3,082 users
-
#11
com.instagram.android 2,835 users
-
#12
twitter.com 2,783 users
-
#13
com.netflix.mediaclient 2,631 users
-
#14
microsoftonline.com 2,522 users
-
#15
mega.nz 2,471 users
-
#16
paypal.com 2,385 users
-
#17
spotify.com 2,377 users
-
#18
apple.com 2,365 users
-
#19
192.168.1.1 2,274 users
-
#20
twitch.tv 2,270 users
-
#21
riotgames.com 2,135 users
-
#22
epicgames.com 2,127 users
-
#23
linkedin.com 2,028 users
-
#24
com.roblox.client 1,852 users
-
#25
com.discord 1,838 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 42 employees
-
#2
icicibank.com 38 employees
-
#3
laureate.net 37 employees
-
#4
abv.bg 34 employees
-
#5
rediff.com 33 employees
-
#6
wp.pl 31 employees
-
#7
buenosaires.gob.ar 30 employees
-
#8
aruba.it 30 employees
-
#9
secureserver.net 30 employees
-
#10
secop.gov.co 26 employees
-
#11
qq.com 26 employees
-
#12
sts.net.pk 25 employees
-
#13
tim.it 24 employees
-
#14
naver.com 24 employees
-
#15
lws.fr 22 employees
-
#16
yandex.com.tr 21 employees
-
#17
yshamforkids.com 19 employees
-
#18
cibertec.edu.pe 19 employees
-
#19
163.com 19 employees
-
#20
utp.edu.pe 19 employees
-
#21
hoteldomedore.com 19 employees
-
#22
firstmail.ltd 17 employees
-
#23
santander.com.br 16 employees
-
#24
alxswe.com 16 employees
-
#25
inacap.cl 16 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 14 employees
-
#2
microsoft.com 6 employees
-
#3
cbre.com 5 employees
-
#4
jacobs.com 4 employees
-
#5
abbott.com 4 employees
-
#6
amazon.com 3 employees
-
#7
autoliv.com 2 employees
-
#8
cablevision.com 2 employees
-
#9
ibm.com 2 employees
-
#10
ingredion.com 2 employees
-
#11
synnex.com 1 employees
-
#12
xerox.com 1 employees
-
#13
oracle.com 1 employees
-
#14
apple.com 1 employees
-
#15
adp.com 1 employees
Compromised users
-
#1
google.com 10,537 users
-
#2
facebook.com 9,004 users
-
#3
netflix.com 4,077 users
-
#4
amazon.com 3,082 users
-
#5
paypal.com 2,385 users
-
#6
apple.com 2,365 users
-
#7
ebay.com 413 users
-
#8
hp.com 359 users
-
#9
microsoft.com 325 users
-
#10
oracle.com 280 users
-
#11
nike.com 255 users
-
#12
cisco.com 251 users
-
#13
ibm.com 127 users
-
#14
walmart.com 79 users
-
#15
westernunion.com 72 users
-
#16
intel.com 66 users
-
#17
ups.com 61 users
-
#18
americanexpress.com 54 users
-
#19
fedex.com 49 users
-
#20
broadcom.com 43 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
4,335 users
2,835 users
Netflix
2,631 users
Roblox
1,852 users
Discord
1,838 users
Twitch
1,529 users
Spotify
1,476 users
Snapchat
1,211 users
1,167 users
Disney
787 users
PayPal
674 users
Mega
656 users
Zoom
638 users
Mercadolibre
580 users
Wish
545 users
Xiaomi
515 users
483 users
Alibaba
390 users
Waze
376 users
314 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 366,829 users
-
#2
hotmail.com 54,011 users
-
#3
yahoo.com 16,877 users
-
#4
outlook.com 10,565 users
-
#5
icloud.com 2,540 users
-
#6
mail.ru 2,197 users
-
#7
yahoo.com.br 1,162 users
-
#8
hotmail.es 1,127 users
-
#9
ymail.com 924 users
-
#10
laposte.net 865 users
-
#11
yahoo.fr 837 users
-
#12
live.com 778 users
-
#13
yahoo.com.ar 758 users
-
#14
mail.com 555 users
-
#15
aol.com 548 users
-
#16
libero.it 489 users
-
#17
hanmail.net 460 users
-
#18
hotmail.co.uk 454 users
-
#19
msn.com 392 users
-
#20
att.net 335 users
-
#21
hotmail.fr 331 users
-
#22
sfr.fr 325 users
-
#23
yahoo.co.uk 313 users
-
#24
web.de 308 users
-
#25
yahoo.com.mx 302 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 8,600machines
- #2 StealC 4,667machines
- #3 Vidar 2,258machines
- #4 Generic Stealer 486machines
- #5 Lumma 9machines
Anti-virus Coverage
- #1 Windows Defender 10,133machines
- #2 Reason Cybersecurity 931machines
- #3 360 Total Security 381machines
- #4 Avast Antivirus 370machines
- #5 McAfee 198machines
- #6 Unknown 148machines
- #7 AVG Antivirus 122machines
- #8 McAfee Firewall 113machines
- #9 McAfee VirusScan 85machines
- #10 Kaspersky 74machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 43,562hits
- #2 sso 10,142hits
- #3 zoom 3,684hits
- #4 github 2,021hits
- #5 webmail 1,489hits
- #6 adfs 959hits
- #7 oracle 532hits
- #8 zendesk 515hits
- #9 webex 496hits
- #10 sap 424hits
- #11 roundcube 423hits
- #12 vpn 412hits
- #13 owa 382hits
- #14 ping 380hits
- #15 sts 342hits
- #16 kaspersky 328hits
- #17 cpanel 280hits
- #18 ftp 259hits
- #19 extranet 234hits
- #20 st 180hits
- #21 okta 168hits
- #22 imap 167hits
- #23 salesforce 119hits
- #24 twilio 83hits
- #25 gitlab 71hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.