Infostealers Weekly Report: 2024-09-23 – 2024-09-30
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 641
- #2 Pakistan 561
- #3 Egypt 500
- #4 India 474
- #5 Turkey 428
- #6 Vietnam 351
- #7 Argentina 335
- #8 Thailand 319
- #9 Mexico 285
- #10 Indonesia 281
- #11 Philippines 263
- #12 Colombia 255
- #13 Bangladesh 233
- #14 Peru 211
- #15 Chile 164
- #16 Morocco 161
- #17 Algeria 160
- #18 Iraq 157
- #19 Ecuador 147
- #20 Spain 146
- #21 South Korea 143
- #22 Venezuela 124
- #23 South Africa 118
- #24 Nigeria 110
- #25 Dominican Republic 103
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 11,992 users
-
#2
facebook.com 10,345 users
-
#3
live.com 9,477 users
-
#4
instagram.com 5,485 users
-
#5
com.facebook.katana 5,123 users
-
#6
discord.com 4,864 users
-
#7
netflix.com 4,745 users
-
#8
steampowered.com 3,930 users
-
#9
roblox.com 3,851 users
-
#10
amazon.com 3,690 users
-
#11
com.instagram.android 3,533 users
-
#12
twitter.com 3,400 users
-
#13
com.netflix.mediaclient 3,399 users
-
#14
microsoftonline.com 3,001 users
-
#15
mega.nz 2,972 users
-
#16
paypal.com 2,892 users
-
#17
apple.com 2,833 users
-
#18
192.168.1.1 2,729 users
-
#19
twitch.tv 2,683 users
-
#20
riotgames.com 2,623 users
-
#21
spotify.com 2,594 users
-
#22
epicgames.com 2,506 users
-
#23
linkedin.com 2,338 users
-
#24
com.discord 2,326 users
-
#25
com.roblox.client 2,288 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 57 employees
-
#2
163.com 52 employees
-
#3
icicibank.com 37 employees
-
#4
firstmail.ltd 34 employees
-
#5
qq.com 33 employees
-
#6
wp.pl 32 employees
-
#7
buenosaires.gob.ar 31 employees
-
#8
rediff.com 30 employees
-
#9
abv.bg 29 employees
-
#10
naver.com 28 employees
-
#11
banquemisr.com 26 employees
-
#12
aruba.it 26 employees
-
#13
watchit.com 24 employees
-
#14
secop.gov.co 23 employees
-
#15
bobibanking.com 23 employees
-
#16
bluehost.com 21 employees
-
#17
kakao.com 21 employees
-
#18
utp.edu.pe 20 employees
-
#19
laureate.net 20 employees
-
#20
utpl.edu.ec 18 employees
-
#21
yandex.com.tr 18 employees
-
#22
sat.gob.mx 17 employees
-
#23
alxswe.com 17 employees
-
#24
rockwellautomation.com 16 employees
-
#25
mail.tm 16 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 16 employees
-
#2
microsoft.com 13 employees
-
#3
hp.com 4 employees
-
#4
ibm.com 4 employees
-
#5
pepsico.com 3 employees
-
#6
amazon.com 3 employees
-
#7
cummins.com 3 employees
-
#8
ge.com 2 employees
-
#9
halliburton.com 2 employees
-
#10
nov.com 2 employees
-
#11
cognizant.com 2 employees
-
#12
jpmorganchase.com 1 employees
-
#13
airproducts.com 1 employees
-
#14
ebay.com 1 employees
-
#15
windstream.com 1 employees
-
#16
cbre.com 1 employees
-
#17
salesforce.com 1 employees
-
#18
amark.com 1 employees
-
#19
mckesson.com 1 employees
-
#20
google.com 1 employees
Compromised users
-
#1
google.com 11,992 users
-
#2
facebook.com 10,345 users
-
#3
netflix.com 4,745 users
-
#4
amazon.com 3,690 users
-
#5
paypal.com 2,892 users
-
#6
apple.com 2,833 users
-
#7
ebay.com 452 users
-
#8
hp.com 442 users
-
#9
microsoft.com 408 users
-
#10
oracle.com 390 users
-
#11
cisco.com 324 users
-
#12
nike.com 290 users
-
#13
ibm.com 129 users
-
#14
walmart.com 104 users
-
#15
intel.com 100 users
-
#16
ups.com 86 users
-
#17
westernunion.com 60 users
-
#18
salesforce.com 43 users
-
#19
fedex.com 40 users
-
#20
broadcom.com 39 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
5,123 users
3,533 users
Netflix
3,399 users
Discord
2,326 users
Roblox
2,288 users
Spotify
2,107 users
Twitch
1,947 users
1,755 users
1,537 users
Snapchat
1,419 users
Wish
995 users
Disney
950 users
PayPal
877 users
Mega
850 users
Zoom
786 users
Mercadolibre
669 users
663 users
Xiaomi
601 users
Alibaba
504 users
Waze
473 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 463,649 users
-
#2
hotmail.com 61,717 users
-
#3
yahoo.com 19,712 users
-
#4
outlook.com 12,499 users
-
#5
icloud.com 2,971 users
-
#6
live.com 1,447 users
-
#7
yahoo.fr 1,219 users
-
#8
hotmail.es 1,209 users
-
#9
libero.it 1,002 users
-
#10
yahoo.com.ar 922 users
-
#11
yahoo.com.br 874 users
-
#12
msn.com 815 users
-
#13
free.fr 647 users
-
#14
mail.ru 640 users
-
#15
hotmail.fr 585 users
-
#16
mail.com 577 users
-
#17
ymail.com 493 users
-
#18
outlook.com.br 414 users
-
#19
hanmail.net 403 users
-
#20
proton.me 398 users
-
#21
yahoo.co.id 377 users
-
#22
aol.com 368 users
-
#23
yahoo.de 294 users
-
#24
yandex.com 282 users
-
#25
yahoo.co.jp 274 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 StealC 6,115machines
- #2 Lumma 4,760machines
- #3 Generic Stealer 4,453machines
- #4 RedLine 1,986machines
- #5 Vidar 854machines
Anti-virus Coverage
- #1 Windows Defender 5,227machines
- #2 Reason Cybersecurity 711machines
- #3 Windows Defender [ON] 474machines
- #4 None 350machines
- #5 Avast Antivirus 139machines
- #6 360 Total Security 117machines
- #7 Unknown 55machines
- #8 알약 42machines
- #9 McAfee 37machines
- #10 AVG Antivirus 30machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 50,131hits
- #2 sso 12,238hits
- #3 zoom 4,548hits
- #4 github 2,719hits
- #5 webmail 2,254hits
- #6 adfs 1,006hits
- #7 oracle 830hits
- #8 zendesk 723hits
- #9 owa 527hits
- #10 ping 502hits
- #11 vpn 485hits
- #12 sap 475hits
- #13 cpanel 422hits
- #14 sts 394hits
- #15 kaspersky 336hits
- #16 webex 296hits
- #17 st 288hits
- #18 roundcube 275hits
- #19 extranet 227hits
- #20 ftp 192hits
- #21 imap 166hits
- #22 gitlab 159hits
- #23 okta 128hits
- #24 salesforce 106hits
- #25 twilio 93hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.