Infostealers Weekly Report: 2023-09-18 – 2023-09-25
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Unknown 29,696
- #2 Brazil 14,050
- #3 India 8,494
- #4 Pakistan 7,721
- #5 Turkey 6,890
- #6 Indonesia 6,514
- #7 Philippines 4,944
- #8 Egypt 4,528
- #9 Thailand 4,086
- #10 Bangladesh 4,019
- #11 Algeria 3,221
- #12 Mexico 3,145
- #13 Peru 2,962
- #14 Vietnam 2,836
- #15 Morocco 2,645
- #16 Colombia 2,600
- #17 United States of America 2,514
- #18 Germany 2,449
- #19 Argentina 2,387
- #20 Sri Lanka 2,016
- #21 Spain 1,950
- #22 Italy 1,839
- #23 Iraq 1,677
- #24 Nigeria 1,660
- #25 France 1,637
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 75,329 users
-
#2
facebook.com 66,398 users
-
#3
live.com 61,448 users
-
#4
instagram.com 34,355 users
-
#5
com.facebook.katana 30,437 users
-
#6
discord.com 28,909 users
-
#7
netflix.com 28,636 users
-
#8
amazon.com 25,321 users
-
#9
twitter.com 24,063 users
-
#10
com.instagram.android 21,970 users
-
#11
steampowered.com 21,650 users
-
#12
roblox.com 21,483 users
-
#13
paypal.com 20,440 users
-
#14
com.netflix.mediaclient 19,932 users
-
#15
linkedin.com 18,313 users
-
#16
mega.nz 17,140 users
-
#17
apple.com 16,721 users
-
#18
microsoftonline.com 16,118 users
-
#19
spotify.com 15,598 users
-
#20
twitch.tv 15,380 users
-
#21
epicgames.com 14,205 users
-
#22
riotgames.com 13,849 users
-
#23
zoom.us 13,128 users
-
#24
com.discord 13,085 users
-
#25
yahoo.com 12,903 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 378 employees
-
#2
163.com 273 employees
-
#3
hostinger.com 263 employees
-
#4
qq.com 242 employees
-
#5
aruba.it 233 employees
-
#6
rediff.com 194 employees
-
#7
wp.pl 191 employees
-
#8
tim.it 164 employees
-
#9
alxswe.com 163 employees
-
#10
freemail.hu 162 employees
-
#11
pec.it 160 employees
-
#12
banquemisr.com 147 employees
-
#13
sempreser.com.br 147 employees
-
#14
laureate.net 116 employees
-
#15
secureserver.net 114 employees
-
#16
aiou.edu.pk 113 employees
-
#17
netpnb.com 110 employees
-
#18
login.sp.gov.br 107 employees
-
#19
bcb.gov.br 105 employees
-
#20
abv.bg 104 employees
-
#21
secop.gov.co 104 employees
-
#22
ukr.net 102 employees
-
#23
bobibanking.com 102 employees
-
#24
icai.org 101 employees
-
#25
unionbankonline.co.in 100 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 86 employees
-
#2
microsoft.com 72 employees
-
#3
netflix.com 14 employees
-
#4
ibm.com 14 employees
-
#5
twc.com 9 employees
-
#6
hp.com 8 employees
-
#7
honeywell.com 7 employees
-
#8
frontier.com 7 employees
-
#9
cognizant.com 6 employees
-
#10
amazon.com 6 employees
-
#11
publix.com 5 employees
-
#12
csc.com 5 employees
-
#13
cablevision.com 4 employees
-
#14
cbre.com 4 employees
-
#15
oracle.com 4 employees
-
#16
facebook.com 4 employees
-
#17
apple.com 4 employees
-
#18
salesforce.com 4 employees
-
#19
ups.com 3 employees
-
#20
quintiles.com 3 employees
Compromised users
-
#1
google.com 75,329 users
-
#2
facebook.com 66,398 users
-
#3
netflix.com 28,636 users
-
#4
amazon.com 25,321 users
-
#5
paypal.com 20,440 users
-
#6
apple.com 16,721 users
-
#7
ebay.com 3,982 users
-
#8
oracle.com 3,052 users
-
#9
microsoft.com 2,913 users
-
#10
hp.com 2,464 users
-
#11
cisco.com 2,428 users
-
#12
nike.com 1,863 users
-
#13
ibm.com 998 users
-
#14
ups.com 781 users
-
#15
walmart.com 668 users
-
#16
westernunion.com 656 users
-
#17
intel.com 563 users
-
#18
fedex.com 408 users
-
#19
salesforce.com 344 users
-
#20
adp.com 316 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
30,437 users
21,970 users
Netflix
19,932 users
Discord
13,085 users
Spotify
11,693 users
Roblox
11,559 users
Twitch
10,218 users
9,282 users
Snapchat
9,013 users
PayPal
5,562 users
5,000 users
Zoom
4,945 users
Mega
4,659 users
Wish
4,482 users
Mercadolibre
4,354 users
Disney
4,314 users
Alibaba
3,832 users
Waze
3,629 users
Xiaomi
3,383 users
2,540 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 3,262,121 users
-
#2
hotmail.com 418,172 users
-
#3
yahoo.com 153,192 users
-
#4
outlook.com 101,528 users
-
#5
icloud.com 22,289 users
-
#6
live.com 17,313 users
-
#7
yahoo.com.br 16,640 users
-
#8
hotmail.fr 14,864 users
-
#9
mail.ru 12,608 users
-
#10
yahoo.fr 12,256 users
-
#11
msn.com 10,494 users
-
#12
libero.it 9,802 users
-
#13
web.de 7,625 users
-
#14
hotmail.it 7,331 users
-
#15
gmx.de 6,636 users
-
#16
ymail.com 6,505 users
-
#17
live.fr 6,407 users
-
#18
googlemail.com 6,109 users
-
#19
yahoo.co.id 5,029 users
-
#20
mail.com 5,026 users
-
#21
sfr.fr 4,444 users
-
#22
hotmail.es 4,401 users
-
#23
aol.com 3,909 users
-
#24
orange.fr 3,600 users
-
#25
protonmail.com 3,242 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 77,924machines
- #2 RedLine 76,053machines
- #3 Generic Stealer 18,724machines
- #4 9,142machines
- #5 Mystic 1,787machines
- #6 racoon 972machines
Anti-virus Coverage
- #1 Windows Defender 78,521machines
- #2 360 Total Security 2,829machines
- #3 Avast Antivirus 2,690machines
- #4 Reason Cybersecurity 1,774machines
- #5 McAfee Firewall 1,360machines
- #6 McAfee VirusScan 1,051machines
- #7 AVG Antivirus 635machines
- #8 ESET Security 570machines
- #9 Kaspersky Internet Security 492machines
- #10 Norton Security Ultra 423machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 300,322hits
- #2 sso 79,487hits
- #3 zoom 29,581hits
- #4 github 16,027hits
- #5 webmail 11,308hits
- #6 adfs 7,280hits
- #7 oracle 6,158hits
- #8 sap 5,968hits
- #9 zendesk 4,719hits
- #10 owa 3,741hits
- #11 cpanel 3,619hits
- #12 vpn 3,524hits
- #13 ping 3,512hits
- #14 kaspersky 2,499hits
- #15 sts 2,478hits
- #16 webex 2,289hits
- #17 ftp 1,951hits
- #18 extranet 1,925hits
- #19 imap 1,720hits
- #20 st 1,590hits
- #21 roundcube 1,458hits
- #22 salesforce 1,318hits
- #23 okta 1,015hits
- #24 twilio 1,003hits
- #25 gitlab 959hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains