Skip to content
Weekly intelligence Aug 4 – Aug 11, 2025 14 min read

Infostealers Weekly Report: 2025-08-04 – 2025-08-11

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 57,801 Compromised Machines
#2 14,821 Compromised Employees
#3 23,602 Compromised Users
#4 19,378 Compromised Androids
#5 323,681 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 187
Infections by country

Top 25 countries

  1. #1 India 3,275
  2. #2 United States of America 2,108
  3. #3 Brazil 1,245
  4. #4 France 819
  5. #5 Indonesia 748
  6. #6 Bangladesh 715
  7. #7 Japan 691
  8. #8 Spain 602
  9. #9 Poland 595
  10. #10 Mexico 575
  11. #11 Nigeria 530
  12. #12 Pakistan 527
  13. #13 Philippines 487
  14. #14 Germany 425
  15. #15 Italy 423
  16. #16 Vietnam 419
  17. #17 Turkey 356
  18. #18 Colombia 347
  19. #19 South Korea 314
  20. #20 Argentina 303
  21. #21 Egypt 295
  22. #22 United Kingdom 291
  23. #23 Peru 222
  24. #24 Thailand 221
  25. #25 Canada 195

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 30,373 users
  2. #2 facebook.com 22,626 users
  3. #3 live.com 17,222 users
  4. #4 instagram.com 13,282 users
  5. #5 netflix.com 11,713 users
  6. #6 discord.com 11,007 users
  7. #7 com.facebook.katana 10,327 users
  8. #8 microsoftonline.com 10,137 users
  9. #9 roblox.com 9,706 users
  10. #10 amazon.com 9,049 users
  11. #11 apple.com 8,275 users
  12. #12 paypal.com 7,655 users
  13. #13 linkedin.com 7,441 users
  14. #14 com.instagram.android 7,189 users
  15. #15 twitter.com 7,055 users
  16. #16 spotify.com 6,756 users
  17. #17 zoom.us 6,752 users
  18. #18 steampowered.com 6,450 users
  19. #19 com.netflix.mediaclient 6,164 users
  20. #20 twitch.tv 5,665 users
  21. #21 mega.nz 5,234 users
  22. #22 epicgames.com 5,164 users
  23. #23 github.com 5,126 users
  24. #24 openai.com 5,062 users
  25. #25 com.roblox.client 5,042 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 hostinger.com 319 employees
  2. #2 firstmail.ltd 229 employees
  3. #3 icicibank.com 218 employees
  4. #4 aruba.it 132 employees
  5. #5 wp.pl 102 employees
  6. #6 unionbankonline.co.in 84 employees
  7. #7 secureserver.net 79 employees
  8. #8 163.com 78 employees
  9. #9 onet.pl 77 employees
  10. #10 office365.com 77 employees
  11. #11 bobibanking.com 77 employees
  12. #12 digimail.in 75 employees
  13. #13 rediff.com 74 employees
  14. #14 pec.it 69 employees
  15. #15 bharatnet.internal 63 employees
  16. #16 atlassian.com 63 employees
  17. #17 qq.com 59 employees
  18. #18 zsthost.com 59 employees
  19. #19 naver.com 56 employees
  20. #20 o2.pl 52 employees
  21. #21 ovh.net 51 employees
  22. #22 company.local 49 employees
  23. #23 bluehost.com 46 employees
  24. #24 hostgator.com.br 46 employees
  25. #25 mail.tm 45 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 microsoft.com 37 employees
  2. #2 netflix.com 14 employees
  3. #3 fedex.com 10 employees
  4. #4 oracle.com 10 employees
  5. #5 rockwellautomation.com 9 employees
  6. #6 amazon.com 9 employees
  7. #7 ibm.com 8 employees
  8. #8 publix.com 7 employees
  9. #9 verizon.com 7 employees
  10. #10 pfizer.com 6 employees
  11. #11 hp.com 5 employees
  12. #12 abbott.com 4 employees
  13. #13 cognizant.com 4 employees
  14. #14 metlife.com 4 employees
  15. #15 frontier.com 4 employees
  16. #16 yum.com 3 employees
  17. #17 apple.com 3 employees
  18. #18 ford.com 3 employees
  19. #19 visteon.com 3 employees
  20. #20 marriott.com 3 employees

Compromised users

  1. #1 google.com 30,373 users
  2. #2 facebook.com 22,626 users
  3. #3 netflix.com 11,713 users
  4. #4 amazon.com 9,049 users
  5. #5 apple.com 8,275 users
  6. #6 paypal.com 7,655 users
  7. #7 ebay.com 1,362 users
  8. #8 hp.com 1,094 users
  9. #9 microsoft.com 945 users
  10. #10 oracle.com 897 users
  11. #11 salesforce.com 846 users
  12. #12 nike.com 840 users
  13. #13 walmart.com 653 users
  14. #14 ups.com 476 users
  15. #15 cisco.com 468 users
  16. #16 fedex.com 326 users
  17. #17 target.com 317 users
  18. #18 bankofamerica.com 313 users
  19. #19 ibm.com 312 users
  20. #20 bestbuy.com 307 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

10,327 users

#2

Instagram

instagram.com · com.instagram.android

7,189 users

#3

Netflix

netflix.com · com.netflix.mediaclient

6,164 users

#4

Roblox

roblox.com · com.roblox.client

5,042 users

#5

Discord

discord.com · com.discord

4,146 users

#6

Spotify

spotify.com · com.spotify.music

3,628 users

#7

Snapchat

snapchat.com · com.snapchat.android

3,345 users

#8

Twitter

twitter.com · com.twitter.android

3,016 users

#9

Twitch

app.com · tv.twitch.android.app

2,849 users

#10

Pinterest

pinterest.com · com.pinterest

2,799 users

#11

PayPal

paypal.com · com.paypal.android.p2pmobile

1,822 users

#12

Mega

app.com · mega.privacy.android.app

1,547 users

#13

Zoom

videomeetings.com · us.zoom.videomeetings

1,539 users

#14

LinkedIn

linkedin.com · com.linkedin.android

1,512 users

#15

Wish

contextlogic.com · com.contextlogic.wish

1,466 users

#16

Disney

disney.com · com.disney.disneyplus

1,442 users

#17

Xiaomi

xiaomi.com · com.xiaomi.account

1,301 users

#18

Mercadolibre

mercadolibre.com · com.mercadolibre

916 users

#19

Waze

waze.com · com.waze

851 users

#20

Alibaba

alibaba.com · com.alibaba.aliexpresshd

813 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 1,290,320 users
  2. #2 hotmail.com 92,436 users
  3. #3 yahoo.com 52,903 users
  4. #4 outlook.com 32,094 users
  5. #5 icloud.com 14,273 users
  6. #6 mail.ru 4,348 users
  7. #7 yahoo.com.ar 4,136 users
  8. #8 live.com 3,938 users
  9. #9 hotmail.fr 3,426 users
  10. #10 me.com 3,369 users
  11. #11 aol.com 3,099 users
  12. #12 gmx.de 3,099 users
  13. #13 ymail.com 2,843 users
  14. #14 mail.com 2,493 users
  15. #15 web.de 2,151 users
  16. #16 yahoo.com.br 1,868 users
  17. #17 googlemail.com 1,695 users
  18. #18 yahoo.fr 1,655 users
  19. #19 hotmail.es 1,648 users
  20. #20 comcast.net 1,625 users
  21. #21 libero.it 1,611 users
  22. #22 gmx.com 1,596 users
  23. #23 hotmail.it 1,346 users
  24. #24 yahoo.it 1,244 users
  25. #25 orange.fr 1,205 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 22,626 accounts
  2. #2 twitter.com 7,055 accounts
  3. #3 instagram.com 13,282 accounts
  4. #4 linkedin.com 7,445 accounts
  5. #5 pinterest.com 2,309 accounts
  6. #6 tiktok.com 3,409 accounts
  7. #7 snapchat.com 2,763 accounts
  8. #8 reddit.com 1,137 accounts
  9. #9 youtube.com 139 accounts
  10. #10 weibo.com 68 accounts
  11. #11 vk.com 981 accounts
  12. #12 telegram.org 205 accounts
  13. #13 tumblr.com 589 accounts
  14. #14 discord.com 11,007 accounts
  15. #15 flickr.com 501 accounts
  16. #16 myspace.com 120 accounts
  17. #17 badoo.com 162 accounts
  18. #18 meetup.com 53 accounts
  19. #19 quora.com 332 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Generic Stealer 33,555machines
  2. #2 Lumma 24,244machines
  3. #3 RedLine 2machines

Anti-virus Coverage

  1. #1 Windows Defender 18,860machines
  2. #2 None 1,985machines
  3. #3 Windows Defender [ON] 1,492machines
  4. #4 Reason Cybersecurity 508machines
  5. #5 Windows Defender. 167machines
  6. #6 McAfee, Windows Defender 91machines
  7. #7 Windows Defender, McAfee 84machines
  8. #8 McAfee 53machines
  9. #9 Windows Defender, Reason Cybersecurity 52machines
  10. #10 Avast Antivirus, Windows Defender 52machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 146,451hits
  2. #2 sso 35,543hits
  3. #3 zoom 12,216hits
  4. #4 github 8,489hits
  5. #5 vpn 6,501hits
  6. #6 webmail 5,968hits
  7. #7 adfs 3,261hits
  8. #8 oracle 2,127hits
  9. #9 zendesk 2,051hits
  10. #10 cpanel 1,636hits
  11. #11 jira 1,528hits
  12. #12 ping 1,523hits
  13. #13 salesforce 1,312hits
  14. #14 sap 1,267hits
  15. #15 owa 1,142hits
  16. #16 sts 988hits
  17. #17 roundcube 894hits
  18. #18 ftp 836hits
  19. #19 gitlab 817hits
  20. #20 extranet 803hits
  21. #21 okta 769hits
  22. #22 kaspersky 708hits
  23. #23 git 568hits
  24. #24 twilio 523hits
  25. #25 imap 452hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure