Infostealers Weekly Report: 2023-10-30 – 2023-11-06
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 3,658
- #2 Turkey 2,036
- #3 Pakistan 1,616
- #4 Mexico 1,583
- #5 Thailand 1,451
- #6 Egypt 1,237
- #7 Philippines 1,234
- #8 Colombia 1,213
- #9 Peru 1,156
- #10 India 894
- #11 Algeria 847
- #12 Vietnam 830
- #13 Bangladesh 808
- #14 Argentina 707
- #15 Morocco 656
- #16 Indonesia 605
- #17 Chile 558
- #18 Ecuador 551
- #19 Spain 531
- #20 Sri Lanka 495
- #21 Malaysia 477
- #22 Venezuela 472
- #23 Iraq 416
- #24 United States of America 413
- #25 Dominican Republic 374
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 38,834 users
-
#2
facebook.com 35,446 users
-
#3
live.com 33,306 users
-
#4
discord.com 16,895 users
-
#5
instagram.com 16,803 users
-
#6
com.facebook.katana 16,611 users
-
#7
netflix.com 16,412 users
-
#8
roblox.com 14,553 users
-
#9
steampowered.com 12,866 users
-
#10
amazon.com 12,449 users
-
#11
twitter.com 11,924 users
-
#12
com.netflix.mediaclient 11,524 users
-
#13
com.instagram.android 10,575 users
-
#14
paypal.com 10,122 users
-
#15
microsoftonline.com 9,960 users
-
#16
mega.nz 9,845 users
-
#17
twitch.tv 9,484 users
-
#18
riotgames.com 9,416 users
-
#19
spotify.com 8,602 users
-
#20
linkedin.com 8,415 users
-
#21
epicgames.com 8,233 users
-
#22
apple.com 8,224 users
-
#23
steamcommunity.com 7,439 users
-
#24
com.roblox.client 7,356 users
-
#25
com.discord 6,997 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
laureate.net 155 employees
-
#2
wp.pl 149 employees
-
#3
hostinger.com 134 employees
-
#4
sempreser.com.br 134 employees
-
#5
buenosaires.gob.ar 96 employees
-
#6
secop.gov.co 94 employees
-
#7
utp.edu.pe 81 employees
-
#8
tigo.com.co 71 employees
-
#9
bcb.gov.br 70 employees
-
#10
sts.net.pk 69 employees
-
#11
login.sp.gov.br 67 employees
-
#12
uol.com.br 65 employees
-
#13
aruba.it 64 employees
-
#14
yandex.com.tr 63 employees
-
#15
inacap.cl 62 employees
-
#16
ionos.com 59 employees
-
#17
upc.edu.pe 58 employees
-
#18
aiou.edu.pk 57 employees
-
#19
telecom.pt 56 employees
-
#20
rockwellautomation.com 56 employees
-
#21
qq.com 55 employees
-
#22
jwpub.org 54 employees
-
#23
freemail.hu 53 employees
-
#24
o2.pl 52 employees
-
#25
secureserver.net 51 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 56 employees
-
#2
microsoft.com 24 employees
-
#3
ups.com 13 employees
-
#4
amazon.com 9 employees
-
#5
manpowergroup.com 6 employees
-
#6
att.com 6 employees
-
#7
goodyear.com 5 employees
-
#8
visteon.com 5 employees
-
#9
ibm.com 4 employees
-
#10
tenneco.com 4 employees
-
#11
jpmorganchase.com 2 employees
-
#12
csc.com 2 employees
-
#13
emc.com 1 employees
-
#14
frontier.com 1 employees
-
#15
netflix.com 1 employees
-
#16
publix.com 1 employees
-
#17
cablevision.com 1 employees
Compromised users
-
#1
google.com 38,834 users
-
#2
facebook.com 35,446 users
-
#3
netflix.com 16,412 users
-
#4
amazon.com 12,449 users
-
#5
paypal.com 10,122 users
-
#6
apple.com 8,224 users
-
#7
ebay.com 1,900 users
-
#8
microsoft.com 1,489 users
-
#9
oracle.com 1,211 users
-
#10
hp.com 1,167 users
-
#11
cisco.com 1,076 users
-
#12
nike.com 1,040 users
-
#13
ibm.com 405 users
-
#14
walmart.com 351 users
-
#15
ups.com 333 users
-
#16
westernunion.com 273 users
-
#17
intel.com 219 users
-
#18
fedex.com 199 users
-
#19
bestbuy.com 171 users
-
#20
salesforce.com 127 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
16,611 users
Netflix
11,524 users
10,575 users
Roblox
7,356 users
Discord
6,997 users
Twitch
6,505 users
Spotify
6,383 users
4,590 users
Snapchat
4,169 users
Disney
3,439 users
Mercadolibre
3,377 users
PayPal
3,035 users
Wish
2,928 users
Mega
2,732 users
Zoom
2,454 users
Waze
2,234 users
2,129 users
Alibaba
2,004 users
Xiaomi
1,719 users
1,668 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,381,450 users
-
#2
hotmail.com 234,345 users
-
#3
yahoo.com 50,528 users
-
#4
outlook.com 46,348 users
-
#5
icloud.com 8,340 users
-
#6
yahoo.com.br 7,944 users
-
#7
live.com 7,496 users
-
#8
mail.ru 3,781 users
-
#9
msn.com 3,340 users
-
#10
hotmail.fr 3,094 users
-
#11
yahoo.fr 2,753 users
-
#12
hotmail.es 2,468 users
-
#13
live.fr 1,989 users
-
#14
libero.it 1,874 users
-
#15
yahoo.com.ar 1,753 users
-
#16
gmx.com 1,451 users
-
#17
orange.fr 1,412 users
-
#18
yahoo.co.uk 1,389 users
-
#19
gmx.net 1,376 users
-
#20
yandex.com 1,195 users
-
#21
ymail.com 1,158 users
-
#22
mail.com 1,018 users
-
#23
hotmail.it 1,015 users
-
#24
yahoo.it 857 users
-
#25
aol.com 809 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 85,860machines
- #2 Generic Stealer 6,480machines
- #3 Lumma 3,399machines
Anti-virus Coverage
- #1 Windows Defender 78,764machines
- #2 Avast Antivirus 2,495machines
- #3 360 Total Security 2,480machines
- #4 Reason Cybersecurity 2,068machines
- #5 McAfee Firewall 1,531machines
- #6 McAfee VirusScan 1,096machines
- #7 AVG Antivirus 734machines
- #8 ESET Security 640machines
- #9 VirusScan de McAfee 499machines
- #10 Kaspersky 431machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 148,567hits
- #2 sso 40,072hits
- #3 zoom 14,509hits
- #4 webmail 7,062hits
- #5 github 6,347hits
- #6 adfs 4,201hits
- #7 sap 2,818hits
- #8 oracle 2,536hits
- #9 zendesk 2,295hits
- #10 owa 2,091hits
- #11 vpn 1,721hits
- #12 cpanel 1,484hits
- #13 ping 1,334hits
- #14 webex 1,148hits
- #15 kaspersky 1,148hits
- #16 sts 1,128hits
- #17 extranet 1,075hits
- #18 roundcube 987hits
- #19 ftp 829hits
- #20 okta 595hits
- #21 st 585hits
- #22 twilio 336hits
- #23 salesforce 325hits
- #24 gitlab 276hits
- #25 zimbra 228hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.