Infostealers Weekly Report: 2025-08-25 – 2025-09-01
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 458
- #2 Bangladesh 170
- #3 France 117
- #4 Philippines 106
- #5 Indonesia 99
- #6 Pakistan 83
- #7 United States of America 79
- #8 Brazil 59
- #9 Egypt 58
- #10 Japan 52
- #11 Mexico 37
- #12 Turkey 34
- #13 Germany 34
- #14 Argentina 30
- #15 Vietnam 24
- #16 South Africa 24
- #17 Algeria 21
- #18 Nigeria 19
- #19 Nepal 17
- #20 Malaysia 15
- #21 Kenya 15
- #22 Morocco 14
- #23 China 14
- #24 Peru 14
- #25 Sri Lanka 13
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,611 users
-
#2
facebook.com 2,263 users
-
#3
live.com 1,502 users
-
#4
com.facebook.katana 1,369 users
-
#5
instagram.com 1,027 users
-
#6
apple.com 937 users
-
#7
netflix.com 918 users
-
#8
com.instagram.android 820 users
-
#9
amazon.com 809 users
-
#10
192.168.1.1 736 users
-
#11
unlocktool.net 731 users
-
#12
mega.nz 712 users
-
#13
com.netflix.mediaclient 679 users
-
#14
paypal.com 676 users
-
#15
twitter.com 651 users
-
#16
discord.com 642 users
-
#17
linkedin.com 614 users
-
#18
192.168.0.1 557 users
-
#19
xiaomi.com 540 users
-
#20
microsoftonline.com 530 users
-
#21
github.com 471 users
-
#22
com.pinterest 458 users
-
#23
yahoo.com 445 users
-
#24
samsung.com 435 users
-
#25
steampowered.com 423 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 34 employees
-
#2
hostinger.com 29 employees
-
#3
rediff.com 17 employees
-
#4
netpnb.com 14 employees
-
#5
mail.tm 14 employees
-
#6
unionbankonline.co.in 14 employees
-
#7
firstmail.ltd 10 employees
-
#8
bobibanking.com 9 employees
-
#9
mts.rs 8 employees
-
#10
artmed.com.br 7 employees
-
#11
mail.gov.in 7 employees
-
#12
yahoosmallbusiness.com 7 employees
-
#13
sempreser.com.br 7 employees
-
#14
dskbangladesh.org 6 employees
-
#15
ionos.com 6 employees
-
#16
pnbibanking.in 6 employees
-
#17
starceramicsbd.com 6 employees
-
#18
amityonline.com 6 employees
-
#19
turbify.com 6 employees
-
#20
buenosaires.gob.ar 6 employees
-
#21
gre.ac.uk 6 employees
-
#22
verizonsmallbusinessessentials.com 6 employees
-
#23
idbibank.co.in 5 employees
-
#24
thangtien.vn 5 employees
-
#25
bluehost.com 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
oracle.com 5 employees
-
#2
facebook.com 3 employees
-
#3
apple.com 2 employees
-
#4
salesforce.com 2 employees
-
#5
ally.com 2 employees
-
#6
microsoft.com 2 employees
-
#7
rockwellautomation.com 2 employees
-
#8
ibm.com 1 employees
-
#9
quintiles.com 1 employees
-
#10
dupont.com 1 employees
-
#11
att.com 1 employees
Compromised users
-
#1
google.com 2,611 users
-
#2
facebook.com 2,263 users
-
#3
apple.com 937 users
-
#4
netflix.com 918 users
-
#5
amazon.com 809 users
-
#6
paypal.com 676 users
-
#7
ebay.com 103 users
-
#8
hp.com 101 users
-
#9
oracle.com 94 users
-
#10
microsoft.com 84 users
-
#11
cisco.com 64 users
-
#12
salesforce.com 51 users
-
#13
ibm.com 34 users
-
#14
walmart.com 33 users
-
#15
nike.com 31 users
-
#16
ups.com 29 users
-
#17
westernunion.com 25 users
-
#18
broadcom.com 24 users
-
#19
intel.com 20 users
-
#20
adp.com 19 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,369 users
820 users
Netflix
679 users
458 users
Snapchat
420 users
353 users
Roblox
335 users
Spotify
334 users
Discord
334 users
Mega
245 users
Xiaomi
234 users
PayPal
224 users
Wish
216 users
Twitch
201 users
Zoom
150 users
138 users
Alibaba
108 users
Disney
92 users
Mercadolibre
80 users
Waze
73 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 127,163 users
-
#2
hotmail.com 9,057 users
-
#3
yahoo.com 6,032 users
-
#4
outlook.com 2,829 users
-
#5
icloud.com 814 users
-
#6
yahoo.com.br 742 users
-
#7
live.com 250 users
-
#8
hotmail.fr 235 users
-
#9
terra.com.br 217 users
-
#10
yahoo.fr 188 users
-
#11
msn.com 176 users
-
#12
mail.ru 154 users
-
#13
yahoo.co.id 140 users
-
#14
hotmail.com.ar 124 users
-
#15
rocketmail.com 112 users
-
#16
aol.com 109 users
-
#17
mail.com 107 users
-
#18
yahoo.com.ar 97 users
-
#19
yahoo.co.uk 90 users
-
#20
ymail.com 85 users
-
#21
proton.me 46 users
-
#22
email.com 42 users
-
#23
yahoo.com.ph 42 users
-
#24
googlemail.com 39 users
-
#25
yandex.com 36 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 2,157machines
- #2 Generic Stealer 1,931machines
- #3 Acreed 109machines
Anti-virus Coverage
- #1 Windows Defender 1,668machines
- #2 None 593machines
- #3 Windows Defender [ON] 259machines
- #4 Reason Cybersecurity 76machines
- #5 30machines
- #6 Avast Antivirus 10machines
- #7 Norton Security Ultra 7machines
- #8 Quick Heal AntiVirus Pro 6machines
- #9 Kaspersky 5machines
- #10 Bkav Pro Internet Security 4machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 12,615hits
- #2 sso 2,542hits
- #3 zoom 807hits
- #4 github 777hits
- #5 vpn 329hits
- #6 adfs 267hits
- #7 webmail 254hits
- #8 oracle 216hits
- #9 cpanel 150hits
- #10 zendesk 145hits
- #11 owa 134hits
- #12 sap 125hits
- #13 ping 93hits
- #14 kaspersky 90hits
- #15 ftp 88hits
- #16 salesforce 80hits
- #17 twilio 69hits
- #18 jira 54hits
- #19 gitlab 51hits
- #20 st 49hits
- #21 sts 42hits
- #22 extranet 36hits
- #23 roundcube 35hits
- #24 okta 32hits
- #25 citrix 30hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.