Infostealers Weekly Report: 2025-03-03 – 2025-03-10
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 592
- #2 Spain 381
- #3 Indonesia 287
- #4 Vietnam 263
- #5 France 256
- #6 Brazil 255
- #7 Pakistan 205
- #8 Philippines 204
- #9 Italy 191
- #10 Argentina 186
- #11 Thailand 184
- #12 Turkey 175
- #13 Bangladesh 163
- #14 Egypt 158
- #15 Germany 117
- #16 Mexico 117
- #17 United States of America 97
- #18 Colombia 85
- #19 Peru 74
- #20 Algeria 60
- #21 Chile 58
- #22 South Africa 53
- #23 South Korea 47
- #24 Morocco 47
- #25 Sri Lanka 41
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,050 users
-
#2
facebook.com 4,222 users
-
#3
live.com 3,977 users
-
#4
instagram.com 2,530 users
-
#5
discord.com 2,294 users
-
#6
com.facebook.katana 2,293 users
-
#7
netflix.com 2,247 users
-
#8
amazon.com 2,142 users
-
#9
paypal.com 1,782 users
-
#10
roblox.com 1,727 users
-
#11
com.instagram.android 1,701 users
-
#12
steampowered.com 1,692 users
-
#13
com.netflix.mediaclient 1,675 users
-
#14
twitter.com 1,600 users
-
#15
twitch.tv 1,475 users
-
#16
apple.com 1,382 users
-
#17
epicgames.com 1,346 users
-
#18
riotgames.com 1,223 users
-
#19
steamcommunity.com 1,189 users
-
#20
linkedin.com 1,122 users
-
#21
com.discord 1,103 users
-
#22
microsoftonline.com 1,092 users
-
#23
com.roblox.client 1,075 users
-
#24
192.168.1.1 1,044 users
-
#25
com.pinterest 994 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 30 employees
-
#2
hostinger.com 28 employees
-
#3
firstmail.ltd 23 employees
-
#4
aruba.it 21 employees
-
#5
tim.it 20 employees
-
#6
buenosaires.gob.ar 20 employees
-
#7
icai.org 16 employees
-
#8
bobibanking.com 15 employees
-
#9
watchit.com 15 employees
-
#10
rediff.com 14 employees
-
#11
sempreser.com.br 13 employees
-
#12
concentrix.com 13 employees
-
#13
pec.it 12 employees
-
#14
secop.gov.co 11 employees
-
#15
deped.gov.ph 10 employees
-
#16
mail.tm 10 employees
-
#17
inacap.cl 10 employees
-
#18
telkomsa.net 10 employees
-
#19
unionbankonline.co.in 9 employees
-
#20
aiou.edu.pk 9 employees
-
#21
netpnb.com 9 employees
-
#22
secureserver.net 9 employees
-
#23
bcb.gov.br 8 employees
-
#24
confused.com 8 employees
-
#25
banquemisr.com 8 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 4 employees
-
#2
jpmorganchase.com 2 employees
-
#3
cognizant.com 2 employees
-
#4
netflix.com 1 employees
-
#5
cbre.com 1 employees
-
#6
cablevision.com 1 employees
-
#7
salesforce.com 1 employees
-
#8
ncr.com 1 employees
-
#9
csc.com 1 employees
-
#10
aa.com 1 employees
-
#11
fnf.com 1 employees
-
#12
ingredion.com 1 employees
Compromised users
-
#1
google.com 5,050 users
-
#2
facebook.com 4,222 users
-
#3
netflix.com 2,247 users
-
#4
amazon.com 2,142 users
-
#5
paypal.com 1,782 users
-
#6
apple.com 1,382 users
-
#7
ebay.com 272 users
-
#8
nike.com 250 users
-
#9
hp.com 234 users
-
#10
oracle.com 223 users
-
#11
microsoft.com 169 users
-
#12
ups.com 128 users
-
#13
cisco.com 101 users
-
#14
walmart.com 81 users
-
#15
fedex.com 59 users
-
#16
intel.com 52 users
-
#17
ibm.com 50 users
-
#18
adp.com 40 users
-
#19
bestbuy.com 33 users
-
#20
americanexpress.com 32 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
2,293 users
1,701 users
Netflix
1,675 users
Discord
1,103 users
Roblox
1,075 users
994 users
Twitch
915 users
Spotify
837 users
Snapchat
715 users
706 users
Wish
603 users
PayPal
533 users
Disney
469 users
Mega
359 users
Zoom
356 users
335 users
Xiaomi
267 users
Waze
236 users
Mercadolibre
231 users
Alibaba
230 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 273,091 users
-
#2
hotmail.com 29,428 users
-
#3
yahoo.com 10,731 users
-
#4
outlook.com 6,859 users
-
#5
hotmail.fr 2,946 users
-
#6
icloud.com 1,908 users
-
#7
hotmail.it 1,714 users
-
#8
web.de 1,503 users
-
#9
yahoo.it 1,324 users
-
#10
msn.com 1,198 users
-
#11
hotmail.es 1,164 users
-
#12
live.com 1,163 users
-
#13
live.fr 1,110 users
-
#14
orange.fr 1,086 users
-
#15
yahoo.fr 787 users
-
#16
laposte.net 773 users
-
#17
yahoo.co.id 717 users
-
#18
hotmail.co.uk 667 users
-
#19
gmx.de 667 users
-
#20
libero.it 596 users
-
#21
gmx.net 574 users
-
#22
sfr.fr 503 users
-
#23
yahoo.com.ar 475 users
-
#24
mail.com 452 users
-
#25
yahoo.de 448 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 4,572machines
- #2 Generic Stealer 2,497machines
- #3 StealC 99machines
Anti-virus Coverage
- #1 Windows Defender 3,605machines
- #2 Windows Defender [ON] 488machines
- #3 None 207machines
- #4 Reason Cybersecurity 146machines
- #5 Reason Cybersecurity [OFF] 23machines
- #6 Quick Heal Total Security 11machines
- #7 ESET Security 11machines
- #8 Malwarebytes [OFF] 10machines
- #9 Avast Antivirus 7machines
- #10 Norton Security [OFF] 7machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 27,117hits
- #2 sso 6,975hits
- #3 zoom 1,827hits
- #4 github 1,354hits
- #5 webmail 813hits
- #6 sap 595hits
- #7 adfs 461hits
- #8 oracle 449hits
- #9 zendesk 375hits
- #10 vpn 342hits
- #11 cpanel 226hits
- #12 owa 222hits
- #13 ping 192hits
- #14 extranet 178hits
- #15 sts 145hits
- #16 imap 141hits
- #17 st 135hits
- #18 webex 121hits
- #19 okta 113hits
- #20 roundcube 108hits
- #21 ftp 100hits
- #22 kaspersky 98hits
- #23 salesforce 83hits
- #24 twilio 65hits
- #25 citrix 42hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.