Infostealers Weekly Report: 2024-01-01 – 2024-01-08
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 2,181
- #2 India 1,543
- #3 Egypt 1,270
- #4 Turkey 1,157
- #5 Pakistan 1,112
- #6 Philippines 995
- #7 Argentina 759
- #8 Mexico 728
- #9 Algeria 671
- #10 Indonesia 657
- #11 Vietnam 565
- #12 Bangladesh 539
- #13 Thailand 529
- #14 Peru 497
- #15 Colombia 482
- #16 Morocco 473
- #17 Iraq 437
- #18 Spain 417
- #19 Sri Lanka 413
- #20 Chile 410
- #21 Malaysia 358
- #22 United States of America 340
- #23 Poland 337
- #24 Romania 317
- #25 Germany 307
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 23,835 users
-
#2
facebook.com 21,988 users
-
#3
live.com 20,402 users
-
#4
instagram.com 10,141 users
-
#5
com.facebook.katana 10,132 users
-
#6
netflix.com 9,865 users
-
#7
discord.com 9,849 users
-
#8
roblox.com 8,455 users
-
#9
steampowered.com 7,700 users
-
#10
amazon.com 7,340 users
-
#11
twitter.com 7,228 users
-
#12
com.netflix.mediaclient 6,640 users
-
#13
com.instagram.android 6,497 users
-
#14
paypal.com 6,228 users
-
#15
mega.nz 6,021 users
-
#16
microsoftonline.com 5,661 users
-
#17
twitch.tv 5,458 users
-
#18
apple.com 5,300 users
-
#19
spotify.com 5,198 users
-
#20
riotgames.com 5,171 users
-
#21
epicgames.com 5,112 users
-
#22
linkedin.com 4,858 users
-
#23
com.roblox.client 4,458 users
-
#24
steamcommunity.com 4,318 users
-
#25
com.discord 4,143 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 114 employees
-
#2
hostinger.com 75 employees
-
#3
abv.bg 71 employees
-
#4
buenosaires.gob.ar 62 employees
-
#5
banquemisr.com 61 employees
-
#6
o2.pl 53 employees
-
#7
jwpub.org 53 employees
-
#8
login.sp.gov.br 51 employees
-
#9
skole.hr 50 employees
-
#10
freemail.hu 48 employees
-
#11
yandex.com.tr 45 employees
-
#12
laureate.net 43 employees
-
#13
nauta.cu 43 employees
-
#14
secop.gov.co 43 employees
-
#15
firstmail.ltd 42 employees
-
#16
sempreser.com.br 40 employees
-
#17
bcb.gov.br 39 employees
-
#18
mail.tm 38 employees
-
#19
utpl.edu.ec 37 employees
-
#20
seznam.cz 37 employees
-
#21
ovh.net 32 employees
-
#22
mail.bg 32 employees
-
#23
bluehost.com 32 employees
-
#24
microsoft.com 32 employees
-
#25
web-hosting.com 30 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 32 employees
-
#2
rockwellautomation.com 27 employees
-
#3
publix.com 5 employees
-
#4
ppg.com 5 employees
-
#5
frontier.com 3 employees
-
#6
hp.com 3 employees
-
#7
amazon.com 3 employees
-
#8
emc.com 2 employees
-
#9
ibm.com 1 employees
-
#10
cisco.com 1 employees
Compromised users
-
#1
google.com 23,835 users
-
#2
facebook.com 21,988 users
-
#3
netflix.com 9,865 users
-
#4
amazon.com 7,340 users
-
#5
paypal.com 6,228 users
-
#6
apple.com 5,300 users
-
#7
ebay.com 1,253 users
-
#8
microsoft.com 878 users
-
#9
hp.com 740 users
-
#10
oracle.com 653 users
-
#11
cisco.com 632 users
-
#12
nike.com 519 users
-
#13
walmart.com 238 users
-
#14
ibm.com 206 users
-
#15
westernunion.com 185 users
-
#16
ups.com 180 users
-
#17
intel.com 178 users
-
#18
adp.com 112 users
-
#19
fedex.com 89 users
-
#20
bestbuy.com 82 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
10,132 users
Netflix
6,640 users
6,497 users
Roblox
4,458 users
Discord
4,143 users
Twitch
3,987 users
Spotify
3,736 users
2,791 users
Snapchat
2,634 users
Disney
1,954 users
PayPal
1,823 users
Mercadolibre
1,790 users
Mega
1,629 users
Wish
1,599 users
Zoom
1,367 users
1,295 users
Waze
1,149 users
Alibaba
1,136 users
Xiaomi
1,038 users
900 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 861,255 users
-
#2
hotmail.com 133,715 users
-
#3
yahoo.com 39,779 users
-
#4
outlook.com 28,628 users
-
#5
icloud.com 6,379 users
-
#6
live.com 4,579 users
-
#7
hotmail.es 4,514 users
-
#8
msn.com 4,213 users
-
#9
yahoo.com.br 4,136 users
-
#10
yahoo.fr 4,117 users
-
#11
hotmail.fr 2,946 users
-
#12
mail.ru 2,929 users
-
#13
free.fr 2,222 users
-
#14
googlemail.com 1,630 users
-
#15
aol.com 1,399 users
-
#16
libero.it 1,356 users
-
#17
yandex.com 1,351 users
-
#18
hotmail.com.ar 1,317 users
-
#19
live.fr 1,305 users
-
#20
yahoo.com.ar 1,220 users
-
#21
mail.com 1,005 users
-
#22
protonmail.com 995 users
-
#23
live.co.uk 797 users
-
#24
web.de 752 users
-
#25
ymail.com 732 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 57,958machines
- #2 Lumma 12,770machines
- #3 Generic Stealer 411machines
Anti-virus Coverage
- #1 Windows Defender 53,282machines
- #2 Reason Cybersecurity 2,085machines
- #3 Avast Antivirus 1,623machines
- #4 360 Total Security 1,540machines
- #5 McAfee Firewall 784machines
- #6 ESET Security 571machines
- #7 McAfee VirusScan 546machines
- #8 Kaspersky Internet Security 373machines
- #9 McAfee 362machines
- #10 Kaspersky 352machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 112,300hits
- #2 sso 23,329hits
- #3 zoom 9,788hits
- #4 github 3,563hits
- #5 webmail 3,114hits
- #6 adfs 2,270hits
- #7 zendesk 1,742hits
- #8 sap 1,337hits
- #9 extranet 1,282hits
- #10 oracle 1,280hits
- #11 owa 1,178hits
- #12 sts 865hits
- #13 vpn 847hits
- #14 ping 816hits
- #15 kaspersky 792hits
- #16 cpanel 755hits
- #17 roundcube 582hits
- #18 st 525hits
- #19 webex 509hits
- #20 ftp 492hits
- #21 okta 289hits
- #22 twilio 177hits
- #23 gitlab 167hits
- #24 zimbra 153hits
- #25 imap 149hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.