Infostealers Weekly Report: 2025-03-31 – 2025-04-07
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 442
- #2 Vietnam 422
- #3 Brazil 198
- #4 Pakistan 176
- #5 Philippines 172
- #6 Bangladesh 122
- #7 Argentina 122
- #8 Egypt 99
- #9 Indonesia 95
- #10 Turkey 86
- #11 Portugal 54
- #12 South Africa 51
- #13 Romania 50
- #14 Dominican Republic 49
- #15 Thailand 47
- #16 Serbia 46
- #17 Algeria 45
- #18 Mexico 43
- #19 Sri Lanka 43
- #20 Kenya 41
- #21 United States of America 41
- #22 Malaysia 41
- #23 United Arab Emirates 37
- #24 Nepal 36
- #25 Morocco 32
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,956 users
-
#2
facebook.com 3,388 users
-
#3
live.com 2,967 users
-
#4
instagram.com 1,873 users
-
#5
com.facebook.katana 1,678 users
-
#6
discord.com 1,668 users
-
#7
netflix.com 1,650 users
-
#8
amazon.com 1,390 users
-
#9
roblox.com 1,368 users
-
#10
steampowered.com 1,285 users
-
#11
twitter.com 1,212 users
-
#12
paypal.com 1,160 users
-
#13
com.instagram.android 1,144 users
-
#14
com.netflix.mediaclient 1,123 users
-
#15
apple.com 1,058 users
-
#16
microsoftonline.com 963 users
-
#17
spotify.com 916 users
-
#18
192.168.1.1 911 users
-
#19
riotgames.com 874 users
-
#20
mega.nz 866 users
-
#21
epicgames.com 850 users
-
#22
linkedin.com 837 users
-
#23
twitch.tv 806 users
-
#24
com.discord 783 users
-
#25
com.roblox.client 772 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 33 employees
-
#2
hostinger.com 25 employees
-
#3
rediff.com 23 employees
-
#4
qq.com 22 employees
-
#5
sapo.pt 20 employees
-
#6
telecom.pt 19 employees
-
#7
163.com 18 employees
-
#8
mail.tm 14 employees
-
#9
wp.pl 13 employees
-
#10
web-hosting.com 13 employees
-
#11
watchit.com 13 employees
-
#12
buenosaires.gob.ar 12 employees
-
#13
firstmail.ltd 11 employees
-
#14
sina.com.cn 11 employees
-
#15
microsoft.com 10 employees
-
#16
ewexltd.com 9 employees
-
#17
njoyn.com 9 employees
-
#18
rockwellautomation.com 9 employees
-
#19
abv.bg 9 employees
-
#20
secureserver.net 8 employees
-
#21
accenture.com 8 employees
-
#22
correo.com.uy 8 employees
-
#23
zsthost.com 7 employees
-
#24
tangerangkab.go.id 7 employees
-
#25
banquemisr.com 7 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 10 employees
-
#2
rockwellautomation.com 9 employees
-
#3
ibm.com 4 employees
-
#4
cbre.com 3 employees
-
#5
mastercard.com 2 employees
-
#6
ford.com 2 employees
-
#7
fisglobal.com 2 employees
-
#8
netflix.com 1 employees
-
#9
ups.com 1 employees
-
#10
csc.com 1 employees
Compromised users
-
#1
google.com 3,956 users
-
#2
facebook.com 3,388 users
-
#3
netflix.com 1,650 users
-
#4
amazon.com 1,390 users
-
#5
paypal.com 1,160 users
-
#6
apple.com 1,058 users
-
#7
ebay.com 255 users
-
#8
hp.com 148 users
-
#9
microsoft.com 136 users
-
#10
oracle.com 130 users
-
#11
nike.com 85 users
-
#12
cisco.com 81 users
-
#13
westernunion.com 58 users
-
#14
ibm.com 57 users
-
#15
walmart.com 44 users
-
#16
ups.com 43 users
-
#17
intel.com 34 users
-
#18
fedex.com 34 users
-
#19
adp.com 22 users
-
#20
broadcom.com 21 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,678 users
1,144 users
Netflix
1,123 users
Discord
783 users
Roblox
772 users
Spotify
753 users
673 users
Snapchat
506 users
Twitch
481 users
470 users
Wish
312 users
PayPal
303 users
Zoom
276 users
273 users
Mega
261 users
Disney
205 users
Xiaomi
187 users
Alibaba
168 users
Waze
149 users
Mercadolibre
146 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 189,191 users
-
#2
hotmail.com 15,853 users
-
#3
yahoo.com 9,005 users
-
#4
outlook.com 5,026 users
-
#5
aol.com 1,383 users
-
#6
live.com 981 users
-
#7
icloud.com 937 users
-
#8
prodigy.net.mx 724 users
-
#9
msn.com 651 users
-
#10
yahoo.com.br 367 users
-
#11
ymail.com 338 users
-
#12
yahoo.co.jp 310 users
-
#13
live.com.ar 270 users
-
#14
outlook.com.br 260 users
-
#15
live.fr 240 users
-
#16
protonmail.com 239 users
-
#17
gmx.com 217 users
-
#18
yahoo.co.in 214 users
-
#19
mail.com 203 users
-
#20
yahoo.com.ar 178 users
-
#21
rocketmail.com 155 users
-
#22
yahoo.fr 152 users
-
#23
hanmail.net 137 users
-
#24
email.com 126 users
-
#25
mail.ru 117 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 3,640machines
- #2 Generic Stealer 1,852machines
- #3 StealC 195machines
Anti-virus Coverage
- #1 Windows Defender 2,677machines
- #2 Windows Defender [ON] 319machines
- #3 None 153machines
- #4 Reason Cybersecurity 57machines
- #5 Bkav Pro Internet Security 16machines
- #6 ESET Security 12machines
- #7 Reason Cybersecurity [OFF] 11machines
- #8 Norton Security [OFF] 8machines
- #9 Malwarebytes [OFF] 6machines
- #10 Webroot SecureAnywhere 5machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 18,856hits
- #2 sso 4,785hits
- #3 zoom 1,434hits
- #4 github 1,097hits
- #5 webmail 538hits
- #6 adfs 530hits
- #7 sap 378hits
- #8 oracle 297hits
- #9 zendesk 280hits
- #10 vpn 268hits
- #11 ping 175hits
- #12 owa 171hits
- #13 cpanel 165hits
- #14 sts 137hits
- #15 extranet 135hits
- #16 ftp 130hits
- #17 roundcube 82hits
- #18 kaspersky 79hits
- #19 webex 78hits
- #20 okta 77hits
- #21 imap 73hits
- #22 st 67hits
- #23 twilio 44hits
- #24 jira 38hits
- #25 rlogin 36hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.