Infostealers Weekly Report: 2026-05-18 – 2026-05-25
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Philippines 1,325
- #2 Mexico 776
- #3 India 728
- #4 Peru 687
- #5 Pakistan 345
- #6 Nigeria 301
- #7 Nepal 291
- #8 Indonesia 200
- #9 Vietnam 135
- #10 Netherlands 132
- #11 Madagascar 127
- #12 Brazil 119
- #13 Malaysia 112
- #14 France 102
- #15 United States of America 91
- #16 Myanmar (Burma) 90
- #17 Mongolia 81
- #18 Bangladesh 77
- #19 Mozambique 70
- #20 Malawi 62
- #21 Italy 60
- #22 South Africa 57
- #23 Nicaragua 53
- #24 Panama 49
- #25 Egypt 44
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 9,447 users
-
#2
facebook.com 7,164 users
-
#3
live.com 5,962 users
-
#4
instagram.com 4,183 users
-
#5
discord.com 3,675 users
-
#6
roblox.com 3,471 users
-
#7
netflix.com 3,412 users
-
#8
com.facebook.katana 3,352 users
-
#9
amazon.com 2,736 users
-
#10
steampowered.com 2,584 users
-
#11
com.instagram.android 2,496 users
-
#12
microsoftonline.com 2,401 users
-
#13
apple.com 2,384 users
-
#14
paypal.com 2,307 users
-
#15
com.netflix.mediaclient 2,166 users
-
#16
spotify.com 1,954 users
-
#17
twitter.com 1,809 users
-
#18
twitch.tv 1,770 users
-
#19
com.roblox.client 1,682 users
-
#20
riotgames.com 1,622 users
-
#21
192.168.1.1 1,612 users
-
#22
openai.com 1,598 users
-
#23
linkedin.com 1,566 users
-
#24
epicgames.com 1,545 users
-
#25
mega.nz 1,496 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 83 employees
-
#2
firstmail.ltd 44 employees
-
#3
icicibank.com 41 employees
-
#4
android 39 employees
-
#5
laureate.net 33 employees
-
#6
rediff.com 26 employees
-
#7
concentrix.com 24 employees
-
#8
deped.gov.ph 24 employees
-
#9
mail.tm 19 employees
-
#10
netpnb.com 19 employees
-
#11
indusind.com 18 employees
-
#12
aruba.it 18 employees
-
#13
zsthost.com 16 employees
-
#14
unionbankonline.co.in 16 employees
-
#15
secureserver.net 15 employees
-
#16
bobibanking.com 15 employees
-
#17
pnbibanking.in 14 employees
-
#18
pnp.gov.ph 14 employees
-
#19
santander.com.br 13 employees
-
#20
tim.it 13 employees
-
#21
pec.it 13 employees
-
#22
payoneer.com 13 employees
-
#23
icai.org 13 employees
-
#24
one.com 13 employees
-
#25
atlassian.com 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 6 employees
-
#2
ford.com 5 employees
-
#3
oracle.com 4 employees
-
#4
salesforce.com 3 employees
-
#5
ibm.com 2 employees
-
#6
xerox.com 2 employees
-
#7
att.com 2 employees
-
#8
rockwellautomation.com 2 employees
-
#9
paypal.com 2 employees
-
#10
cognizant.com 2 employees
-
#11
apple.com 2 employees
-
#12
disney.com 1 employees
-
#13
hp.com 1 employees
-
#14
pg.com 1 employees
-
#15
twc.com 1 employees
-
#16
henryschein.com 1 employees
-
#17
netflix.com 1 employees
-
#18
broadcom.com 1 employees
-
#19
facebook.com 1 employees
-
#20
intel.com 1 employees
Compromised users
-
#1
google.com 9,447 users
-
#2
facebook.com 7,164 users
-
#3
netflix.com 3,412 users
-
#4
amazon.com 2,736 users
-
#5
apple.com 2,384 users
-
#6
paypal.com 2,307 users
-
#7
oracle.com 392 users
-
#8
hp.com 382 users
-
#9
ebay.com 356 users
-
#10
nike.com 280 users
-
#11
microsoft.com 277 users
-
#12
cisco.com 192 users
-
#13
walmart.com 180 users
-
#14
ibm.com 148 users
-
#15
ups.com 147 users
-
#16
broadcom.com 97 users
-
#17
intel.com 91 users
-
#18
westernunion.com 81 users
-
#19
fedex.com 75 users
-
#20
adp.com 70 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
3,352 users
2,496 users
Netflix
2,166 users
Roblox
1,682 users
Discord
1,419 users
Spotify
1,331 users
Snapchat
1,136 users
1,033 users
868 users
Twitch
802 users
PayPal
617 users
Wish
545 users
Zoom
534 users
Xiaomi
427 users
Mega
394 users
Disney
391 users
363 users
Waze
267 users
Mercadolibre
245 users
Alibaba
205 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 384,817 users
-
#2
hotmail.com 32,723 users
-
#3
yahoo.com 12,767 users
-
#4
outlook.com 7,437 users
-
#5
hotmail.fr 3,988 users
-
#6
icloud.com 3,153 users
-
#7
yahoo.fr 1,446 users
-
#8
ymail.com 850 users
-
#9
aol.com 782 users
-
#10
live.com 704 users
-
#11
sfr.fr 673 users
-
#12
orange.fr 641 users
-
#13
laposte.net 566 users
-
#14
live.co.uk 552 users
-
#15
hotmail.es 535 users
-
#16
msn.com 530 users
-
#17
live.fr 505 users
-
#18
gmx.de 494 users
-
#19
libero.it 486 users
-
#20
mail.ru 484 users
-
#21
yahoo.com.br 394 users
-
#22
web.de 389 users
-
#23
hotmail.it 379 users
-
#24
yahoo.co.id 369 users
-
#25
mail.com 367 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 13,617machines
- #2 Acreed 188machines
- #3 Lumma 15machines
Anti-virus Coverage
- #1 No anti-virus installed 1,517machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 46,983hits
- #2 sso 12,241hits
- #3 zoom 2,780hits
- #4 github 2,462hits
- #5 adfs 1,171hits
- #6 webmail 1,134hits
- #7 oracle 779hits
- #8 zendesk 553hits
- #9 sap 514hits
- #10 vpn 467hits
- #11 ping 451hits
- #12 cpanel 433hits
- #13 sts 430hits
- #14 salesforce 403hits
- #15 owa 379hits
- #16 extranet 259hits
- #17 okta 247hits
- #18 st 209hits
- #19 kaspersky 209hits
- #20 webex 206hits
- #21 ftp 206hits
- #22 roundcube 149hits
- #23 twilio 134hits
- #24 gitlab 72hits
- #25 imap 67hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.