Infostealers Weekly Report: 2023-12-04 – 2023-12-11
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 1,627
- #2 Brazil 1,398
- #3 Mexico 1,081
- #4 Argentina 841
- #5 Colombia 819
- #6 Peru 810
- #7 Egypt 692
- #8 Philippines 641
- #9 Pakistan 632
- #10 Thailand 595
- #11 Spain 552
- #12 Bangladesh 550
- #13 Chile 489
- #14 Algeria 480
- #15 Vietnam 477
- #16 Morocco 434
- #17 Ecuador 434
- #18 Malaysia 338
- #19 Venezuela 331
- #20 India 305
- #21 Sri Lanka 291
- #22 Bolivia 282
- #23 Germany 273
- #24 Iraq 266
- #25 Poland 259
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 22,414 users
-
#2
facebook.com 20,893 users
-
#3
live.com 19,491 users
-
#4
instagram.com 9,983 users
-
#5
com.facebook.katana 9,831 users
-
#6
netflix.com 9,464 users
-
#7
discord.com 9,427 users
-
#8
roblox.com 8,378 users
-
#9
amazon.com 7,551 users
-
#10
steampowered.com 7,408 users
-
#11
twitter.com 7,330 users
-
#12
com.netflix.mediaclient 6,987 users
-
#13
com.instagram.android 6,650 users
-
#14
mega.nz 6,150 users
-
#15
paypal.com 6,093 users
-
#16
twitch.tv 5,620 users
-
#17
microsoftonline.com 5,564 users
-
#18
spotify.com 5,257 users
-
#19
epicgames.com 5,190 users
-
#20
apple.com 5,108 users
-
#21
riotgames.com 4,937 users
-
#22
linkedin.com 4,799 users
-
#23
com.roblox.client 4,609 users
-
#24
steamcommunity.com 4,114 users
-
#25
com.discord 4,018 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 82 employees
-
#2
laureate.net 80 employees
-
#3
wp.pl 77 employees
-
#4
utp.edu.pe 70 employees
-
#5
freemail.hu 67 employees
-
#6
yandex.com.tr 63 employees
-
#7
utpl.edu.ec 55 employees
-
#8
secop.gov.co 53 employees
-
#9
buenosaires.gob.ar 51 employees
-
#10
sempreser.com.br 46 employees
-
#11
britanico.edu.pe 39 employees
-
#12
banquemisr.com 37 employees
-
#13
aruba.it 35 employees
-
#14
jwpub.org 34 employees
-
#15
interia.pl 34 employees
-
#16
uol.com.br 32 employees
-
#17
login.sp.gov.br 32 employees
-
#18
cibertec.edu.pe 31 employees
-
#19
aiep.cl 30 employees
-
#20
inacap.cl 29 employees
-
#21
o2.pl 28 employees
-
#22
santander.com.br 27 employees
-
#23
telecom.pt 27 employees
-
#24
mail.tm 27 employees
-
#25
firstmail.ltd 27 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 18 employees
-
#2
rockwellautomation.com 13 employees
-
#3
ford.com 8 employees
-
#4
netflix.com 4 employees
-
#5
publix.com 4 employees
-
#6
pvh.com 4 employees
-
#7
ingredion.com 3 employees
-
#8
manpowergroup.com 3 employees
-
#9
hp.com 3 employees
-
#10
ecolab.com 3 employees
-
#11
ingrammicro.com 2 employees
-
#12
fedex.com 2 employees
-
#13
nov.com 2 employees
-
#14
drhorton.com 2 employees
-
#15
ups.com 2 employees
-
#16
aa.com 2 employees
-
#17
jpmorganchase.com 1 employees
-
#18
amazon.com 1 employees
-
#19
ibm.com 1 employees
-
#20
bestbuy.com 1 employees
Compromised users
-
#1
google.com 22,414 users
-
#2
facebook.com 20,893 users
-
#3
netflix.com 9,464 users
-
#4
amazon.com 7,551 users
-
#5
paypal.com 6,093 users
-
#6
apple.com 5,108 users
-
#7
ebay.com 1,122 users
-
#8
hp.com 755 users
-
#9
microsoft.com 753 users
-
#10
oracle.com 713 users
-
#11
cisco.com 690 users
-
#12
nike.com 595 users
-
#13
ibm.com 239 users
-
#14
westernunion.com 208 users
-
#15
walmart.com 203 users
-
#16
intel.com 165 users
-
#17
ups.com 157 users
-
#18
fedex.com 122 users
-
#19
bestbuy.com 113 users
-
#20
adp.com 88 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
9,831 users
Netflix
6,987 users
6,650 users
Roblox
4,609 users
Discord
4,018 users
Twitch
3,844 users
Spotify
3,829 users
2,789 users
Snapchat
2,687 users
Disney
2,137 users
Mercadolibre
1,894 users
PayPal
1,874 users
Wish
1,648 users
Mega
1,603 users
Zoom
1,405 users
1,329 users
Alibaba
1,259 users
Waze
1,183 users
Xiaomi
1,076 users
696 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 789,192 users
-
#2
hotmail.com 146,745 users
-
#3
yahoo.com 28,738 users
-
#4
outlook.com 23,686 users
-
#5
icloud.com 6,066 users
-
#6
live.com 4,899 users
-
#7
hotmail.es 3,520 users
-
#8
hotmail.fr 2,456 users
-
#9
yahoo.fr 2,393 users
-
#10
yahoo.com.br 2,311 users
-
#11
ymail.com 1,849 users
-
#12
web.de 1,699 users
-
#13
mail.ru 1,484 users
-
#14
msn.com 1,471 users
-
#15
yahoo.com.ar 1,352 users
-
#16
yahoo.co.uk 1,142 users
-
#17
live.com.mx 1,087 users
-
#18
libero.it 1,026 users
-
#19
gmx.de 989 users
-
#20
hotmail.com.ar 873 users
-
#21
mail.com 858 users
-
#22
live.fr 825 users
-
#23
free.fr 798 users
-
#24
tiscali.it 749 users
-
#25
hotmail.it 630 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 55,859machines
- #2 Lumma 330machines
- #3 Generic Stealer 79machines
Anti-virus Coverage
- #1 Windows Defender 50,445machines
- #2 Avast Antivirus 1,854machines
- #3 360 Total Security 1,356machines
- #4 Reason Cybersecurity 1,317machines
- #5 McAfee Firewall 850machines
- #6 McAfee VirusScan 592machines
- #7 AVG Antivirus 528machines
- #8 ESET Security 482machines
- #9 VirusScan de McAfee 347machines
- #10 McAfee 328machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 83,947hits
- #2 sso 18,855hits
- #3 zoom 8,879hits
- #4 github 3,474hits
- #5 webmail 3,443hits
- #6 adfs 2,274hits
- #7 oracle 1,540hits
- #8 sap 1,482hits
- #9 zendesk 1,418hits
- #10 owa 1,009hits
- #11 vpn 783hits
- #12 cpanel 749hits
- #13 ping 726hits
- #14 kaspersky 719hits
- #15 sts 717hits
- #16 webex 624hits
- #17 extranet 602hits
- #18 roundcube 393hits
- #19 st 380hits
- #20 okta 361hits
- #21 ftp 353hits
- #22 twilio 172hits
- #23 salesforce 150hits
- #24 gitlab 143hits
- #25 zimbra 73hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.