Infostealers Weekly Report: 2023-11-27 – 2023-12-04
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 1,950
- #2 Turkey 1,922
- #3 Mexico 1,311
- #4 Peru 1,167
- #5 Colombia 1,133
- #6 Pakistan 1,083
- #7 Argentina 941
- #8 Thailand 855
- #9 Philippines 831
- #10 Vietnam 797
- #11 Bangladesh 741
- #12 Egypt 717
- #13 Algeria 668
- #14 Chile 648
- #15 Ecuador 636
- #16 Spain 609
- #17 Malaysia 491
- #18 Venezuela 465
- #19 Morocco 442
- #20 Bolivia 410
- #21 India 334
- #22 Sri Lanka 309
- #23 Dominican Republic 297
- #24 Iraq 295
- #25 Kenya 242
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 22,375 users
-
#2
facebook.com 20,938 users
-
#3
live.com 19,790 users
-
#4
com.facebook.katana 10,131 users
-
#5
instagram.com 9,682 users
-
#6
netflix.com 9,631 users
-
#7
discord.com 8,778 users
-
#8
amazon.com 7,624 users
-
#9
roblox.com 7,335 users
-
#10
com.netflix.mediaclient 7,120 users
-
#11
twitter.com 7,090 users
-
#12
steampowered.com 6,874 users
-
#13
com.instagram.android 6,557 users
-
#14
mega.nz 6,401 users
-
#15
paypal.com 6,000 users
-
#16
microsoftonline.com 5,920 users
-
#17
apple.com 5,139 users
-
#18
linkedin.com 5,092 users
-
#19
spotify.com 4,815 users
-
#20
twitch.tv 4,782 users
-
#21
riotgames.com 4,645 users
-
#22
epicgames.com 4,366 users
-
#23
com.roblox.client 4,160 users
-
#24
com.discord 4,066 users
-
#25
com.spotify.music 4,015 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 105 employees
-
#2
utp.edu.pe 89 employees
-
#3
secop.gov.co 86 employees
-
#4
buenosaires.gob.ar 59 employees
-
#5
wp.pl 56 employees
-
#6
yandex.com.tr 52 employees
-
#7
secureserver.net 52 employees
-
#8
tim.it 45 employees
-
#9
freemail.hu 43 employees
-
#10
jwpub.org 43 employees
-
#11
ovh.net 42 employees
-
#12
aruba.it 41 employees
-
#13
sempreser.com.br 40 employees
-
#14
sapo.pt 40 employees
-
#15
inacap.cl 40 employees
-
#16
ctonline.mx 40 employees
-
#17
utm.edu.ec 39 employees
-
#18
login.sp.gov.br 39 employees
-
#19
interia.pl 39 employees
-
#20
rappi.com 38 employees
-
#21
laureate.net 38 employees
-
#22
hostgator.com 38 employees
-
#23
one.com 36 employees
-
#24
bcb.gov.br 36 employees
-
#25
aiep.cl 35 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 31 employees
-
#2
microsoft.com 19 employees
-
#3
abbott.com 7 employees
-
#4
oracle.com 5 employees
-
#5
pg.com 5 employees
-
#6
twc.com 4 employees
-
#7
apple.com 3 employees
-
#8
verizon.com 3 employees
-
#9
netflix.com 3 employees
-
#10
amazon.com 2 employees
-
#11
frontier.com 2 employees
-
#12
hp.com 2 employees
-
#13
ups.com 2 employees
-
#14
autozone.com 1 employees
-
#15
bms.com 1 employees
-
#16
textron.com 1 employees
-
#17
cisco.com 1 employees
-
#18
fedex.com 1 employees
-
#19
alcoa.com 1 employees
Compromised users
-
#1
google.com 22,375 users
-
#2
facebook.com 20,938 users
-
#3
netflix.com 9,631 users
-
#4
amazon.com 7,624 users
-
#5
paypal.com 6,000 users
-
#6
apple.com 5,139 users
-
#7
ebay.com 1,333 users
-
#8
microsoft.com 841 users
-
#9
oracle.com 811 users
-
#10
cisco.com 738 users
-
#11
hp.com 709 users
-
#12
nike.com 518 users
-
#13
ibm.com 251 users
-
#14
ups.com 242 users
-
#15
walmart.com 192 users
-
#16
westernunion.com 162 users
-
#17
intel.com 150 users
-
#18
salesforce.com 104 users
-
#19
fedex.com 79 users
-
#20
bestbuy.com 78 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
10,131 users
Netflix
7,120 users
6,557 users
Roblox
4,160 users
Discord
4,066 users
Spotify
4,015 users
Twitch
3,700 users
2,906 users
Snapchat
2,534 users
Disney
2,252 users
Mercadolibre
2,027 users
Wish
1,924 users
PayPal
1,862 users
Mega
1,664 users
1,640 users
Zoom
1,590 users
Alibaba
1,403 users
Waze
1,356 users
1,301 users
Xiaomi
1,234 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 818,228 users
-
#2
hotmail.com 156,485 users
-
#3
yahoo.com 31,882 users
-
#4
outlook.com 20,307 users
-
#5
live.com 6,914 users
-
#6
icloud.com 4,956 users
-
#7
yahoo.com.br 3,661 users
-
#8
hotmail.es 3,495 users
-
#9
mail.ru 2,636 users
-
#10
ymail.com 2,051 users
-
#11
msn.com 1,896 users
-
#12
yahoo.fr 1,503 users
-
#13
hotmail.fr 1,472 users
-
#14
live.fr 1,323 users
-
#15
mail.com 1,190 users
-
#16
yahoo.com.ar 1,136 users
-
#17
alice.it 1,074 users
-
#18
libero.it 1,067 users
-
#19
free.fr 1,042 users
-
#20
yahoo.co.uk 1,004 users
-
#21
yandex.com 952 users
-
#22
gmx.de 912 users
-
#23
yahoo.com.mx 800 users
-
#24
live.com.ar 668 users
-
#25
web.de 640 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 47,865machines
- #2 Generic Stealer 8,984machines
Anti-virus Coverage
- #1 Windows Defender 42,996machines
- #2 Avast Antivirus 1,681machines
- #3 Reason Cybersecurity 1,265machines
- #4 360 Total Security 1,149machines
- #5 McAfee Firewall 670machines
- #6 AVG Antivirus 489machines
- #7 McAfee VirusScan 416machines
- #8 ESET Security 407machines
- #9 Kaspersky Internet Security 296machines
- #10 VirusScan de McAfee 293machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 84,073hits
- #2 sso 22,699hits
- #3 zoom 8,483hits
- #4 webmail 3,812hits
- #5 github 3,566hits
- #6 adfs 2,438hits
- #7 oracle 1,611hits
- #8 owa 1,544hits
- #9 zendesk 1,315hits
- #10 sap 1,179hits
- #11 cpanel 1,170hits
- #12 vpn 872hits
- #13 ping 864hits
- #14 sts 782hits
- #15 roundcube 768hits
- #16 kaspersky 755hits
- #17 extranet 754hits
- #18 ftp 588hits
- #19 webex 542hits
- #20 st 391hits
- #21 imap 323hits
- #22 okta 304hits
- #23 gitlab 284hits
- #24 salesforce 219hits
- #25 twilio 210hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.