Skip to content
Weekly intelligence Sep 18 – Sep 25, 2023 14 min read

Infostealers Weekly Report: 2023-09-18 – 2023-09-25

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 172,254 Compromised Machines
#2 22,560 Compromised Employees
#3 90,622 Compromised Users
#4 59,072 Compromised Androids
#5 305,571 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 209
Infections by country

Top 25 countries

  1. #1 Unknown 29,696
  2. #2 Brazil 14,050
  3. #3 India 8,494
  4. #4 Pakistan 7,721
  5. #5 Turkey 6,890
  6. #6 Indonesia 6,514
  7. #7 Philippines 4,944
  8. #8 Egypt 4,528
  9. #9 Thailand 4,086
  10. #10 Bangladesh 4,019
  11. #11 Algeria 3,221
  12. #12 Mexico 3,145
  13. #13 Peru 2,962
  14. #14 Vietnam 2,836
  15. #15 Morocco 2,645
  16. #16 Colombia 2,600
  17. #17 United States of America 2,514
  18. #18 Germany 2,449
  19. #19 Argentina 2,387
  20. #20 Sri Lanka 2,016
  21. #21 Spain 1,950
  22. #22 Italy 1,839
  23. #23 Iraq 1,677
  24. #24 Nigeria 1,660
  25. #25 France 1,637

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 75,329 users
  2. #2 facebook.com 66,398 users
  3. #3 live.com 61,448 users
  4. #4 instagram.com 34,355 users
  5. #5 com.facebook.katana 30,437 users
  6. #6 discord.com 28,909 users
  7. #7 netflix.com 28,636 users
  8. #8 amazon.com 25,321 users
  9. #9 twitter.com 24,063 users
  10. #10 com.instagram.android 21,970 users
  11. #11 steampowered.com 21,650 users
  12. #12 roblox.com 21,483 users
  13. #13 paypal.com 20,440 users
  14. #14 com.netflix.mediaclient 19,932 users
  15. #15 linkedin.com 18,313 users
  16. #16 mega.nz 17,140 users
  17. #17 apple.com 16,721 users
  18. #18 microsoftonline.com 16,118 users
  19. #19 spotify.com 15,598 users
  20. #20 twitch.tv 15,380 users
  21. #21 epicgames.com 14,205 users
  22. #22 riotgames.com 13,849 users
  23. #23 zoom.us 13,128 users
  24. #24 com.discord 13,085 users
  25. #25 yahoo.com 12,903 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 icicibank.com 378 employees
  2. #2 163.com 273 employees
  3. #3 hostinger.com 263 employees
  4. #4 qq.com 242 employees
  5. #5 aruba.it 233 employees
  6. #6 rediff.com 194 employees
  7. #7 wp.pl 191 employees
  8. #8 tim.it 164 employees
  9. #9 alxswe.com 163 employees
  10. #10 freemail.hu 162 employees
  11. #11 pec.it 160 employees
  12. #12 banquemisr.com 147 employees
  13. #13 sempreser.com.br 147 employees
  14. #14 laureate.net 116 employees
  15. #15 secureserver.net 114 employees
  16. #16 aiou.edu.pk 113 employees
  17. #17 netpnb.com 110 employees
  18. #18 login.sp.gov.br 107 employees
  19. #19 bcb.gov.br 105 employees
  20. #20 abv.bg 104 employees
  21. #21 secop.gov.co 104 employees
  22. #22 ukr.net 102 employees
  23. #23 bobibanking.com 102 employees
  24. #24 icai.org 101 employees
  25. #25 unionbankonline.co.in 100 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 rockwellautomation.com 86 employees
  2. #2 microsoft.com 72 employees
  3. #3 netflix.com 14 employees
  4. #4 ibm.com 14 employees
  5. #5 twc.com 9 employees
  6. #6 hp.com 8 employees
  7. #7 honeywell.com 7 employees
  8. #8 frontier.com 7 employees
  9. #9 cognizant.com 6 employees
  10. #10 amazon.com 6 employees
  11. #11 publix.com 5 employees
  12. #12 csc.com 5 employees
  13. #13 cablevision.com 4 employees
  14. #14 cbre.com 4 employees
  15. #15 oracle.com 4 employees
  16. #16 facebook.com 4 employees
  17. #17 apple.com 4 employees
  18. #18 salesforce.com 4 employees
  19. #19 ups.com 3 employees
  20. #20 quintiles.com 3 employees

Compromised users

  1. #1 google.com 75,329 users
  2. #2 facebook.com 66,398 users
  3. #3 netflix.com 28,636 users
  4. #4 amazon.com 25,321 users
  5. #5 paypal.com 20,440 users
  6. #6 apple.com 16,721 users
  7. #7 ebay.com 3,982 users
  8. #8 oracle.com 3,052 users
  9. #9 microsoft.com 2,913 users
  10. #10 hp.com 2,464 users
  11. #11 cisco.com 2,428 users
  12. #12 nike.com 1,863 users
  13. #13 ibm.com 998 users
  14. #14 ups.com 781 users
  15. #15 walmart.com 668 users
  16. #16 westernunion.com 656 users
  17. #17 intel.com 563 users
  18. #18 fedex.com 408 users
  19. #19 salesforce.com 344 users
  20. #20 adp.com 316 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

30,437 users

#2

Instagram

instagram.com · com.instagram.android

21,970 users

#3

Netflix

netflix.com · com.netflix.mediaclient

19,932 users

#4

Discord

discord.com · com.discord

13,085 users

#5

Spotify

spotify.com · com.spotify.music

11,693 users

#6

Roblox

roblox.com · com.roblox.client

11,559 users

#7

Twitch

app.com · tv.twitch.android.app

10,218 users

#8

Twitter

twitter.com · com.twitter.android

9,282 users

#9

Snapchat

snapchat.com · com.snapchat.android

9,013 users

#10

PayPal

paypal.com · com.paypal.android.p2pmobile

5,562 users

#11

LinkedIn

linkedin.com · com.linkedin.android

5,000 users

#12

Zoom

videomeetings.com · us.zoom.videomeetings

4,945 users

#13

Mega

app.com · mega.privacy.android.app

4,659 users

#14

Wish

contextlogic.com · com.contextlogic.wish

4,482 users

#15

Mercadolibre

mercadolibre.com · com.mercadolibre

4,354 users

#16

Disney

disney.com · com.disney.disneyplus

4,314 users

#17

Alibaba

alibaba.com · com.alibaba.aliexpresshd

3,832 users

#18

Waze

waze.com · com.waze

3,629 users

#19

Xiaomi

xiaomi.com · com.xiaomi.account

3,383 users

#20

Pinterest

pinterest.com · com.pinterest

2,540 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 3,262,121 users
  2. #2 hotmail.com 418,172 users
  3. #3 yahoo.com 153,192 users
  4. #4 outlook.com 101,528 users
  5. #5 icloud.com 22,289 users
  6. #6 live.com 17,313 users
  7. #7 yahoo.com.br 16,640 users
  8. #8 hotmail.fr 14,864 users
  9. #9 mail.ru 12,608 users
  10. #10 yahoo.fr 12,256 users
  11. #11 msn.com 10,494 users
  12. #12 libero.it 9,802 users
  13. #13 web.de 7,625 users
  14. #14 hotmail.it 7,331 users
  15. #15 gmx.de 6,636 users
  16. #16 ymail.com 6,505 users
  17. #17 live.fr 6,407 users
  18. #18 googlemail.com 6,109 users
  19. #19 yahoo.co.id 5,029 users
  20. #20 mail.com 5,026 users
  21. #21 sfr.fr 4,444 users
  22. #22 hotmail.es 4,401 users
  23. #23 aol.com 3,909 users
  24. #24 orange.fr 3,600 users
  25. #25 protonmail.com 3,242 users

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Lumma 77,924machines
  2. #2 RedLine 76,053machines
  3. #3 Generic Stealer 18,724machines
  4. #4 9,142machines
  5. #5 Mystic 1,787machines
  6. #6 racoon 972machines

Anti-virus Coverage

  1. #1 Windows Defender 78,521machines
  2. #2 360 Total Security 2,829machines
  3. #3 Avast Antivirus 2,690machines
  4. #4 Reason Cybersecurity 1,774machines
  5. #5 McAfee Firewall 1,360machines
  6. #6 McAfee VirusScan 1,051machines
  7. #7 AVG Antivirus 635machines
  8. #8 ESET Security 570machines
  9. #9 Kaspersky Internet Security 492machines
  10. #10 Norton Security Ultra 423machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 300,322hits
  2. #2 sso 79,487hits
  3. #3 zoom 29,581hits
  4. #4 github 16,027hits
  5. #5 webmail 11,308hits
  6. #6 adfs 7,280hits
  7. #7 oracle 6,158hits
  8. #8 sap 5,968hits
  9. #9 zendesk 4,719hits
  10. #10 owa 3,741hits
  11. #11 cpanel 3,619hits
  12. #12 vpn 3,524hits
  13. #13 ping 3,512hits
  14. #14 kaspersky 2,499hits
  15. #15 sts 2,478hits
  16. #16 webex 2,289hits
  17. #17 ftp 1,951hits
  18. #18 extranet 1,925hits
  19. #19 imap 1,720hits
  20. #20 st 1,590hits
  21. #21 roundcube 1,458hits
  22. #22 salesforce 1,318hits
  23. #23 okta 1,015hits
  24. #24 twilio 1,003hits
  25. #25 gitlab 959hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure