Infostealers Weekly Report: 2023-09-25 – 2023-10-02
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 6,890
- #2 Turkey 5,060
- #3 Philippines 4,557
- #4 Thailand 4,490
- #5 Pakistan 3,793
- #6 Mexico 3,588
- #7 Bangladesh 3,076
- #8 Peru 3,071
- #9 Egypt 2,986
- #10 Algeria 2,259
- #11 Vietnam 2,119
- #12 Argentina 1,964
- #13 Morocco 1,719
- #14 Colombia 1,689
- #15 United States of America 1,663
- #16 Sri Lanka 1,631
- #17 Spain 1,590
- #18 Iraq 1,450
- #19 Venezuela 1,329
- #20 Bolivia 1,171
- #21 Malaysia 1,151
- #22 Kenya 1,122
- #23 Nigeria 1,119
- #24 Germany 1,101
- #25 Chile 990
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 36,673 users
-
#2
facebook.com 33,031 users
-
#3
live.com 30,072 users
-
#4
instagram.com 15,298 users
-
#5
com.facebook.katana 15,214 users
-
#6
discord.com 15,161 users
-
#7
netflix.com 14,038 users
-
#8
roblox.com 13,773 users
-
#9
amazon.com 11,237 users
-
#10
steampowered.com 11,208 users
-
#11
twitter.com 11,056 users
-
#12
com.netflix.mediaclient 9,683 users
-
#13
paypal.com 9,578 users
-
#14
com.instagram.android 9,108 users
-
#15
mega.nz 8,591 users
-
#16
microsoftonline.com 8,384 users
-
#17
twitch.tv 8,100 users
-
#18
riotgames.com 7,856 users
-
#19
apple.com 7,842 users
-
#20
epicgames.com 7,654 users
-
#21
spotify.com 7,399 users
-
#22
linkedin.com 7,380 users
-
#23
com.roblox.client 6,952 users
-
#24
steamcommunity.com 6,204 users
-
#25
com.discord 6,150 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
163.com 130 employees
-
#2
wp.pl 123 employees
-
#3
freemail.hu 116 employees
-
#4
laureate.net 95 employees
-
#5
qq.com 91 employees
-
#6
sempreser.com.br 89 employees
-
#7
upc.edu.pe 72 employees
-
#8
banquemisr.com 65 employees
-
#9
hostinger.com 65 employees
-
#10
aruba.it 64 employees
-
#11
yandex.com.tr 63 employees
-
#12
login.sp.gov.br 62 employees
-
#13
uol.com.br 58 employees
-
#14
interia.pl 55 employees
-
#15
jwpub.org 53 employees
-
#16
buenosaires.gob.ar 49 employees
-
#17
secureserver.net 49 employees
-
#18
sts.net.pk 47 employees
-
#19
globo.com 46 employees
-
#20
utp.edu.pe 46 employees
-
#21
bcb.gov.br 45 employees
-
#22
ionos.es 45 employees
-
#23
o2.pl 45 employees
-
#24
britanico.edu.pe 44 employees
-
#25
web-hosting.com 43 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 42 employees
-
#2
microsoft.com 17 employees
-
#3
ibm.com 8 employees
-
#4
publix.com 7 employees
-
#5
ford.com 7 employees
-
#6
oracle.com 6 employees
-
#7
goodyear.com 5 employees
-
#8
newmont.com 4 employees
-
#9
hp.com 4 employees
-
#10
fedex.com 3 employees
-
#11
labcorp.com 2 employees
-
#12
broadcom.com 2 employees
-
#13
ncr.com 2 employees
-
#14
facebook.com 2 employees
-
#15
att.com 2 employees
-
#16
disney.com 2 employees
-
#17
baxter.com 1 employees
-
#18
abbvie.com 1 employees
Compromised users
-
#1
google.com 36,673 users
-
#2
facebook.com 33,031 users
-
#3
netflix.com 14,038 users
-
#4
amazon.com 11,237 users
-
#5
paypal.com 9,578 users
-
#6
apple.com 7,842 users
-
#7
ebay.com 1,755 users
-
#8
oracle.com 1,045 users
-
#9
microsoft.com 1,043 users
-
#10
cisco.com 1,015 users
-
#11
hp.com 960 users
-
#12
nike.com 822 users
-
#13
westernunion.com 308 users
-
#14
walmart.com 293 users
-
#15
ibm.com 284 users
-
#16
ups.com 259 users
-
#17
intel.com 222 users
-
#18
fedex.com 195 users
-
#19
bestbuy.com 111 users
-
#20
americanexpress.com 106 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
15,214 users
Netflix
9,683 users
9,108 users
Roblox
6,952 users
Discord
6,150 users
Twitch
5,420 users
Spotify
5,095 users
4,107 users
Snapchat
4,054 users
PayPal
2,740 users
Wish
2,492 users
Zoom
2,412 users
Disney
2,369 users
Mega
2,281 users
Mercadolibre
2,197 users
2,024 users
Alibaba
1,764 users
Waze
1,701 users
Xiaomi
1,547 users
887 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,503,245 users
-
#2
hotmail.com 211,786 users
-
#3
yahoo.com 63,709 users
-
#4
outlook.com 43,670 users
-
#5
icloud.com 11,663 users
-
#6
live.com 7,914 users
-
#7
yahoo.com.br 7,041 users
-
#8
hotmail.fr 5,586 users
-
#9
yahoo.fr 5,008 users
-
#10
mail.ru 5,006 users
-
#11
hotmail.es 3,549 users
-
#12
orange.fr 3,030 users
-
#13
msn.com 2,900 users
-
#14
ymail.com 2,826 users
-
#15
yahoo.com.ar 2,404 users
-
#16
live.com.mx 2,301 users
-
#17
live.fr 2,220 users
-
#18
libero.it 1,803 users
-
#19
aol.com 1,680 users
-
#20
gmx.de 1,449 users
-
#21
t-online.de 1,339 users
-
#22
rocketmail.com 1,265 users
-
#23
bk.ru 1,255 users
-
#24
hotmail.co.uk 1,185 users
-
#25
hotmail.it 1,167 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 103,374machines
- #2 Lumma 1,030machines
- #3 Generic Stealer 657machines
Anti-virus Coverage
- #1 Windows Defender 79,531machines
- #2 360 Total Security 4,068machines
- #3 Avast Antivirus 2,972machines
- #4 Reason Cybersecurity 2,045machines
- #5 McAfee Firewall 1,562machines
- #6 McAfee VirusScan 1,191machines
- #7 ESET Security 767machines
- #8 AVG Antivirus 692machines
- #9 Kaspersky Internet Security 476machines
- #10 Norton Security Ultra 447machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 130,064hits
- #2 sso 32,072hits
- #3 zoom 12,937hits
- #4 github 6,146hits
- #5 webmail 5,119hits
- #6 adfs 3,450hits
- #7 sap 2,414hits
- #8 oracle 1,962hits
- #9 zendesk 1,957hits
- #10 owa 1,585hits
- #11 vpn 1,364hits
- #12 ping 1,063hits
- #13 cpanel 1,048hits
- #14 sts 1,043hits
- #15 kaspersky 816hits
- #16 extranet 716hits
- #17 roundcube 691hits
- #18 webex 675hits
- #19 st 653hits
- #20 ftp 502hits
- #21 okta 453hits
- #22 twilio 379hits
- #23 gitlab 322hits
- #24 sharepoint 178hits
- #25 jira 156hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains