Skip to content
Weekly intelligence Jan 20 – Jan 27, 2025 11 min read

Infostealers Weekly Report: 2025-01-20 – 2025-01-27

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 3,800 Compromised Machines
#2 682 Compromised Employees
#3 1,141 Compromised Users
#4 1,977 Compromised Androids
#5 51,771 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 136
Infections by country

Top 25 countries

  1. #1 India 261
  2. #2 Brazil 187
  3. #3 Vietnam 165
  4. #4 Indonesia 161
  5. #5 Pakistan 110
  6. #6 Turkey 104
  7. #7 Philippines 103
  8. #8 Egypt 70
  9. #9 United States of America 65
  10. #10 Argentina 64
  11. #11 Bangladesh 57
  12. #12 Germany 43
  13. #13 Thailand 40
  14. #14 South Africa 39
  15. #15 Portugal 37
  16. #16 France 37
  17. #17 Serbia 33
  18. #18 South Korea 32
  19. #19 Romania 32
  20. #20 Morocco 31
  21. #21 Poland 28
  22. #22 Italy 28
  23. #23 Mexico 27
  24. #24 United Kingdom 26
  25. #25 Malaysia 26

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 2,521 users
  2. #2 facebook.com 2,041 users
  3. #3 live.com 1,781 users
  4. #4 discord.com 1,175 users
  5. #5 instagram.com 1,140 users
  6. #6 roblox.com 1,088 users
  7. #7 com.facebook.katana 1,044 users
  8. #8 netflix.com 983 users
  9. #9 steampowered.com 746 users
  10. #10 com.instagram.android 732 users
  11. #11 amazon.com 703 users
  12. #12 com.netflix.mediaclient 694 users
  13. #13 spotify.com 648 users
  14. #14 paypal.com 624 users
  15. #15 twitter.com 621 users
  16. #16 epicgames.com 610 users
  17. #17 twitch.tv 574 users
  18. #18 apple.com 568 users
  19. #19 riotgames.com 551 users
  20. #20 com.roblox.client 542 users
  21. #21 microsoftonline.com 533 users
  22. #22 steamcommunity.com 496 users
  23. #23 com.pinterest 485 users
  24. #24 192.168.1.1 485 users
  25. #25 mega.nz 479 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 icicibank.com 17 employees
  2. #2 hostinger.com 16 employees
  3. #3 firstmail.ltd 16 employees
  4. #4 buenosaires.gob.ar 9 employees
  5. #5 bobibanking.com 9 employees
  6. #6 rediff.com 9 employees
  7. #7 163.com 9 employees
  8. #8 icai.org 8 employees
  9. #9 concentrix.com 8 employees
  10. #10 sts.net.pk 7 employees
  11. #11 qq.com 7 employees
  12. #12 isacombank.com.vn 6 employees
  13. #13 bestmergeltd.co.ke 5 employees
  14. #14 testversalis.net 5 employees
  15. #15 pakizaknit.com 5 employees
  16. #16 mail.tm 5 employees
  17. #17 netpnb.com 5 employees
  18. #18 zukufiber.com 5 employees
  19. #19 kpu.go.id 5 employees
  20. #20 secureserver.net 5 employees
  21. #21 zsthost.com 5 employees
  22. #22 52you.in 5 employees
  23. #23 aruba.it 5 employees
  24. #24 cepa.co.ke 5 employees
  25. #25 deped.gov.ph 5 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 spglobal.com 2 employees
  2. #2 emerson.com 2 employees
  3. #3 cisco.com 2 employees
  4. #4 facebook.com 1 employees
  5. #5 gm.com 1 employees
  6. #6 harman.com 1 employees
  7. #7 rockwellautomation.com 1 employees
  8. #8 lear.com 1 employees

Compromised users

  1. #1 google.com 2,521 users
  2. #2 facebook.com 2,041 users
  3. #3 netflix.com 983 users
  4. #4 amazon.com 703 users
  5. #5 paypal.com 624 users
  6. #6 apple.com 568 users
  7. #7 ebay.com 97 users
  8. #8 nike.com 74 users
  9. #9 microsoft.com 72 users
  10. #10 hp.com 68 users
  11. #11 oracle.com 61 users
  12. #12 cisco.com 40 users
  13. #13 ibm.com 31 users
  14. #14 westernunion.com 24 users
  15. #15 walmart.com 20 users
  16. #16 intel.com 19 users
  17. #17 americanexpress.com 17 users
  18. #18 salesforce.com 16 users
  19. #19 broadcom.com 12 users
  20. #20 ups.com 11 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

1,044 users

#2

Instagram

instagram.com · com.instagram.android

732 users

#3

Netflix

netflix.com · com.netflix.mediaclient

694 users

#4

Roblox

roblox.com · com.roblox.client

542 users

#5

Pinterest

pinterest.com · com.pinterest

485 users

#6

Discord

discord.com · com.discord

456 users

#7

Spotify

spotify.com · com.spotify.music

444 users

#8

Twitch

app.com · tv.twitch.android.app

331 users

#9

Twitter

twitter.com · com.twitter.android

308 users

#10

Snapchat

snapchat.com · com.snapchat.android

300 users

#11

Wish

contextlogic.com · com.contextlogic.wish

198 users

#12

PayPal

paypal.com · com.paypal.android.p2pmobile

158 users

#13

Mega

app.com · mega.privacy.android.app

156 users

#14

Zoom

videomeetings.com · us.zoom.videomeetings

149 users

#15

Disney

disney.com · com.disney.disneyplus

125 users

#16

LinkedIn

linkedin.com · com.linkedin.android

115 users

#17

Xiaomi

xiaomi.com · com.xiaomi.account

114 users

#18

Mercadolibre

mercadolibre.com · com.mercadolibre

98 users

#19

Waze

waze.com · com.waze

90 users

#20

Alibaba

alibaba.com · com.alibaba.aliexpresshd

85 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 104,667 users
  2. #2 hotmail.com 8,366 users
  3. #3 yahoo.com 4,647 users
  4. #4 outlook.com 2,695 users
  5. #5 live.com 1,148 users
  6. #6 icloud.com 759 users
  7. #7 ymail.com 364 users
  8. #8 hotmail.fr 314 users
  9. #9 email.com 198 users
  10. #10 gmx.de 169 users
  11. #11 yahoo.fr 169 users
  12. #12 msn.com 160 users
  13. #13 yahoo.co.id 142 users
  14. #14 yahoo.com.br 118 users
  15. #15 web.de 106 users
  16. #16 mail.com 73 users
  17. #17 yahoo.com.ar 49 users
  18. #18 yahoo.com.sg 48 users
  19. #19 hanmail.net 40 users
  20. #20 yahoo.de 39 users
  21. #21 proton.me 37 users
  22. #22 facebook.com 36 users
  23. #23 libero.it 36 users
  24. #24 hotmail.com.ar 36 users
  25. #25 aol.com 33 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 2,041 accounts
  2. #2 twitter.com 621 accounts
  3. #3 instagram.com 1,140 accounts
  4. #4 linkedin.com 468 accounts
  5. #5 pinterest.com 179 accounts
  6. #6 tiktok.com 238 accounts
  7. #7 snapchat.com 206 accounts
  8. #8 reddit.com 91 accounts
  9. #9 youtube.com 16 accounts
  10. #10 weibo.com 7 accounts
  11. #11 vk.com 114 accounts
  12. #12 telegram.org 10 accounts
  13. #13 tumblr.com 42 accounts
  14. #14 discord.com 1,175 accounts
  15. #15 flickr.com 27 accounts
  16. #16 myspace.com 1 accounts
  17. #17 badoo.com 11 accounts
  18. #18 meetup.com 2 accounts
  19. #19 quora.com 17 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Lumma 3,195machines
  2. #2 Generic Stealer 603machines
  3. #3 DarkCrystal 2machines

Anti-virus Coverage

  1. #1 Windows Defender 1,872machines
  2. #2 Windows Defender [ON] 372machines
  3. #3 None 163machines
  4. #4 Reason Cybersecurity 92machines
  5. #5 Avast Antivirus 11machines
  6. #6 Reason Cybersecurity [OFF] 10machines
  7. #7 Malwarebytes [OFF] 8machines
  8. #8 360 Total Security 8machines
  9. #9 Kaspersky Anti‑Virus [OFF] 7machines
  10. #10 ESET Security 7machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 10,335hits
  2. #2 sso 2,362hits
  3. #3 zoom 758hits
  4. #4 github 595hits
  5. #5 webmail 324hits
  6. #6 adfs 205hits
  7. #7 zendesk 144hits
  8. #8 sap 128hits
  9. #9 oracle 118hits
  10. #10 vpn 106hits
  11. #11 owa 100hits
  12. #12 sts 96hits
  13. #13 extranet 96hits
  14. #14 imap 71hits
  15. #15 cpanel 65hits
  16. #16 roundcube 63hits
  17. #17 ping 61hits
  18. #18 kaspersky 52hits
  19. #19 ftp 42hits
  20. #20 okta 41hits
  21. #21 st 35hits
  22. #22 webex 33hits
  23. #23 salesforce 28hits
  24. #24 dana-na 23hits
  25. #25 citrix 14hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure