Infostealers Weekly Report: 2026-01-12 – 2026-01-19
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 786
- #2 India 404
- #3 Brazil 173
- #4 Indonesia 129
- #5 China 122
- #6 Bangladesh 102
- #7 Philippines 102
- #8 Vietnam 99
- #9 Germany 95
- #10 Unknown Region 90
- #11 United Kingdom 81
- #12 France 76
- #13 Pakistan 69
- #14 Turkey 59
- #15 South Korea 58
- #16 Japan 55
- #17 South Africa 51
- #18 Egypt 49
- #19 Italy 47
- #20 Canada 46
- #21 Netherlands 43
- #22 Mexico 42
- #23 Poland 40
- #24 Spain 39
- #25 Thailand 38
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,191 users
-
#2
facebook.com 2,542 users
-
#3
live.com 2,309 users
-
#4
discord.com 1,763 users
-
#5
roblox.com 1,672 users
-
#6
instagram.com 1,604 users
-
#7
com.facebook.katana 1,434 users
-
#8
steampowered.com 1,369 users
-
#9
netflix.com 1,326 users
-
#10
twitch.tv 1,099 users
-
#11
amazon.com 1,095 users
-
#12
com.instagram.android 1,064 users
-
#13
apple.com 999 users
-
#14
com.roblox.client 984 users
-
#15
paypal.com 954 users
-
#16
epicgames.com 911 users
-
#17
microsoftonline.com 904 users
-
#18
spotify.com 892 users
-
#19
riotgames.com 887 users
-
#20
com.netflix.mediaclient 865 users
-
#21
steamcommunity.com 863 users
-
#22
twitter.com 816 users
-
#23
com.discord 783 users
-
#24
com.spotify.music 689 users
-
#25
mega.nz 665 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
firstmail.ltd 29 employees
-
#2
hostinger.com 18 employees
-
#3
wp.pl 13 employees
-
#4
icicibank.com 12 employees
-
#5
aruba.it 10 employees
-
#6
rediff.com 9 employees
-
#7
interia.pl 7 employees
-
#8
seznam.cz 7 employees
-
#9
o2.pl 7 employees
-
#10
pec.it 6 employees
-
#11
unionbankonline.co.in 6 employees
-
#12
concentrix.com 6 employees
-
#13
zsthost.com 5 employees
-
#14
gygmail4.com 5 employees
-
#15
confused.com 5 employees
-
#16
bobibanking.com 5 employees
-
#17
abv.bg 5 employees
-
#18
onet.pl 5 employees
-
#19
bcb.gov.br 5 employees
-
#20
santander.com.br 5 employees
-
#21
tim.it 5 employees
-
#22
netpnb.com 5 employees
-
#23
secureserver.net 5 employees
-
#24
pnbibanking.in 5 employees
-
#25
inbox.lv 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
ups.com 2 employees
-
#2
microsoft.com 2 employees
-
#3
apple.com 2 employees
-
#4
publix.com 2 employees
-
#5
cognizant.com 1 employees
-
#6
netflix.com 1 employees
-
#7
disney.com 1 employees
-
#8
att.com 1 employees
-
#9
rockwellautomation.com 1 employees
-
#10
frontier.com 1 employees
-
#11
google.com 1 employees
-
#12
amazon.com 1 employees
Compromised users
-
#1
google.com 3,191 users
-
#2
facebook.com 2,542 users
-
#3
netflix.com 1,326 users
-
#4
amazon.com 1,095 users
-
#5
apple.com 999 users
-
#6
paypal.com 954 users
-
#7
ebay.com 137 users
-
#8
hp.com 121 users
-
#9
nike.com 114 users
-
#10
oracle.com 96 users
-
#11
walmart.com 78 users
-
#12
microsoft.com 77 users
-
#13
cisco.com 58 users
-
#14
ups.com 41 users
-
#15
bestbuy.com 40 users
-
#16
disney.com 38 users
-
#17
adp.com 34 users
-
#18
ibm.com 34 users
-
#19
fedex.com 34 users
-
#20
intel.com 34 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,434 users
1,064 users
Roblox
984 users
Netflix
865 users
Discord
783 users
Spotify
689 users
Twitch
589 users
551 users
Snapchat
491 users
404 users
PayPal
323 users
Wish
251 users
Disney
230 users
Mega
227 users
Xiaomi
196 users
Zoom
177 users
129 users
Mercadolibre
116 users
Alibaba
104 users
Waze
95 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 144,002 users
-
#2
hotmail.com 12,434 users
-
#3
yahoo.com 6,088 users
-
#4
outlook.com 2,772 users
-
#5
icloud.com 1,431 users
-
#6
libero.it 729 users
-
#7
pobox.com 414 users
-
#8
live.com 403 users
-
#9
web.de 395 users
-
#10
yahoo.com.br 383 users
-
#11
msn.com 337 users
-
#12
alice.it 267 users
-
#13
live.it 260 users
-
#14
hotmail.fr 245 users
-
#15
hotmail.co.uk 211 users
-
#16
laposte.net 183 users
-
#17
aol.com 180 users
-
#18
hotmail.it 163 users
-
#19
ymail.com 162 users
-
#20
hotmail.de 153 users
-
#21
online.de 150 users
-
#22
mail.ru 148 users
-
#23
live.fr 144 users
-
#24
gmx.de 144 users
-
#25
yahoo.co.id 126 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 2,698machines
- #2 Generic Stealer 1,572machines
- #3 Acreed 429machines
- #4 RedLine 34machines
- #5 Vidar 18machines
Anti-virus Coverage
- #1 Windows Defender 1,156machines
- #2 No anti-virus installed 7machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 16,793hits
- #2 sso 3,981hits
- #3 zoom 875hits
- #4 github 837hits
- #5 adfs 440hits
- #6 webmail 413hits
- #7 sap 221hits
- #8 zendesk 217hits
- #9 oracle 193hits
- #10 vpn 153hits
- #11 ping 138hits
- #12 sts 132hits
- #13 cpanel 104hits
- #14 kaspersky 88hits
- #15 st 78hits
- #16 owa 76hits
- #17 okta 76hits
- #18 ftp 51hits
- #19 webex 47hits
- #20 roundcube 43hits
- #21 extranet 39hits
- #22 gitlab 34hits
- #23 twilio 30hits
- #24 salesforce 27hits
- #25 git 22hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.