Infostealers Weekly Report: 2026-06-01 – 2026-06-08
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 3,011
- #2 France 601
- #3 United States of America 430
- #4 Italy 342
- #5 Indonesia 338
- #6 Brazil 233
- #7 United Kingdom 219
- #8 Pakistan 207
- #9 Spain 202
- #10 Philippines 162
- #11 Germany 135
- #12 Bangladesh 134
- #13 Vietnam 125
- #14 South Africa 113
- #15 Unknown Region 111
- #16 Egypt 99
- #17 China 96
- #18 Canada 89
- #19 Algeria 88
- #20 Japan 74
- #21 Colombia 69
- #22 Morocco 68
- #23 Sri Lanka 67
- #24 Mexico 64
- #25 Kenya 54
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 11,058 users
-
#2
facebook.com 8,282 users
-
#3
live.com 7,482 users
-
#4
instagram.com 6,330 users
-
#5
netflix.com 4,765 users
-
#6
amazon.com 4,744 users
-
#7
com.facebook.katana 4,702 users
-
#8
discord.com 4,444 users
-
#9
com.instagram.android 4,061 users
-
#10
paypal.com 3,775 users
-
#11
apple.com 3,731 users
-
#12
microsoftonline.com 3,604 users
-
#13
steampowered.com 3,485 users
-
#14
linkedin.com 3,483 users
-
#15
twitter.com 3,430 users
-
#16
roblox.com 3,364 users
-
#17
amazon.in 3,325 users
-
#18
openai.com 3,231 users
-
#19
spotify.com 3,120 users
-
#20
192.168.1.1 3,074 users
-
#21
github.com 2,959 users
-
#22
twitch.tv 2,863 users
-
#23
com.netflix.mediaclient 2,760 users
-
#24
mega.nz 2,725 users
-
#25
epicgames.com 2,724 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
android 549 employees
-
#2
icicibank.com 385 employees
-
#3
hostinger.com 378 employees
-
#4
wirelesslan.gr 318 employees
-
#5
indogames.id 266 employees
-
#6
rediff.com 221 employees
-
#7
aruba.it 217 employees
-
#8
bobibanking.com 164 employees
-
#9
icai.org 164 employees
-
#10
wp.pl 142 employees
-
#11
pec.it 140 employees
-
#12
pnp.gov.ph 136 employees
-
#13
tim.it 122 employees
-
#14
rmunify.com 121 employees
-
#15
skole.hr 114 employees
-
#16
unionbankonline.co.in 96 employees
-
#17
fnp.com 93 employees
-
#18
quest-global.com 88 employees
-
#19
campero.com 87 employees
-
#20
ingrails.com 86 employees
-
#21
jcyl.es 82 employees
-
#22
bankofbaroda.bank.in 82 employees
-
#23
egyptair.com 79 employees
-
#24
netpnb.com 78 employees
-
#25
endoweb.com.br 76 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
ibm.com 65 employees
-
#2
microsoft.com 59 employees
-
#3
cognizant.com 53 employees
-
#4
essendant.com 27 employees
-
#5
salesforce.com 16 employees
-
#6
fedex.com 15 employees
-
#7
twc.com 8 employees
-
#8
nike.com 8 employees
-
#9
jpmorganchase.com 7 employees
-
#10
qualcomm.com 7 employees
-
#11
netflix.com 6 employees
-
#12
oracle.com 6 employees
-
#13
rockwellautomation.com 6 employees
-
#14
abbott.com 5 employees
-
#15
xerox.com 5 employees
-
#16
jnj.com 4 employees
-
#17
publix.com 4 employees
-
#18
amazon.com 4 employees
-
#19
att.com 4 employees
-
#20
ge.com 3 employees
Compromised users
-
#1
google.com 11,058 users
-
#2
facebook.com 8,282 users
-
#3
netflix.com 4,765 users
-
#4
amazon.com 4,744 users
-
#5
paypal.com 3,775 users
-
#6
apple.com 3,731 users
-
#7
oracle.com 1,404 users
-
#8
hp.com 1,164 users
-
#9
ebay.com 1,078 users
-
#10
microsoft.com 939 users
-
#11
nike.com 775 users
-
#12
cisco.com 748 users
-
#13
ibm.com 689 users
-
#14
salesforce.com 479 users
-
#15
ups.com 468 users
-
#16
pg.com 367 users
-
#17
americanexpress.com 321 users
-
#18
broadcom.com 319 users
-
#19
walmart.com 278 users
-
#20
westernunion.com 247 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
4,702 users
4,061 users
Netflix
2,760 users
Snapchat
1,853 users
Spotify
1,825 users
Discord
1,701 users
Roblox
1,676 users
1,626 users
1,249 users
Twitch
1,032 users
PayPal
794 users
Zoom
793 users
Wish
764 users
719 users
Xiaomi
712 users
Mega
634 users
Disney
550 users
Alibaba
354 users
Mercadolibre
288 users
Waze
263 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,085,700 users
-
#2
hotmail.com 76,677 users
-
#3
yahoo.com 32,691 users
-
#4
outlook.com 26,772 users
-
#5
hotmail.fr 12,736 users
-
#6
icloud.com 7,763 users
-
#7
gmx.de 4,660 users
-
#8
orange.fr 4,070 users
-
#9
yahoo.fr 3,822 users
-
#10
web.de 3,748 users
-
#11
googlemail.com 3,657 users
-
#12
libero.it 3,510 users
-
#13
free.fr 3,453 users
-
#14
live.com 3,211 users
-
#15
live.fr 3,003 users
-
#16
hotmail.it 2,638 users
-
#17
gmx.net 2,532 users
-
#18
hotmail.co.uk 1,935 users
-
#19
yahoo.com.br 1,871 users
-
#20
msn.com 1,857 users
-
#21
sfr.fr 1,554 users
-
#22
virgilio.it 1,283 users
-
#23
laposte.net 1,234 users
-
#24
ymail.com 1,219 users
-
#25
yahoo.it 1,207 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 14,232machines
- #2 Acreed 1,628machines
- #3 Lumma 1machines
- #4 Raccoon 1machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 133,685hits
- #2 sso 40,870hits
- #3 zoom 9,154hits
- #4 github 7,280hits
- #5 sap 4,894hits
- #6 webmail 3,961hits
- #7 adfs 3,471hits
- #8 oracle 2,750hits
- #9 ping 1,414hits
- #10 sts 1,333hits
- #11 zendesk 1,242hits
- #12 salesforce 1,196hits
- #13 owa 1,115hits
- #14 vpn 1,113hits
- #15 cpanel 950hits
- #16 webex 654hits
- #17 extranet 635hits
- #18 okta 553hits
- #19 ftp 545hits
- #20 st 495hits
- #21 kaspersky 475hits
- #22 roundcube 420hits
- #23 gitlab 351hits
- #24 twilio 347hits
- #25 imap 313hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.