Infostealers Weekly Report: 2024-01-15 – 2024-01-22
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 8,737
- #2 Brazil 5,930
- #3 Pakistan 3,541
- #4 Indonesia 3,326
- #5 Egypt 3,100
- #6 Turkey 2,346
- #7 Bangladesh 1,210
- #8 Philippines 1,204
- #9 Vietnam 1,178
- #10 Saudi Arabia 1,014
- #11 Algeria 962
- #12 Thailand 939
- #13 Morocco 915
- #14 Mexico 820
- #15 Argentina 791
- #16 Sri Lanka 716
- #17 Colombia 658
- #18 Malaysia 658
- #19 Iraq 629
- #20 Peru 614
- #21 South Africa 595
- #22 Nigeria 572
- #23 South Korea 452
- #24 United Arab Emirates 443
- #25 Jordan 441
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 47,229 users
-
#2
facebook.com 42,692 users
-
#3
live.com 39,900 users
-
#4
instagram.com 22,683 users
-
#5
com.facebook.katana 22,159 users
-
#6
netflix.com 18,482 users
-
#7
discord.com 17,601 users
-
#8
amazon.com 16,679 users
-
#9
com.instagram.android 15,860 users
-
#10
twitter.com 15,475 users
-
#11
com.netflix.mediaclient 14,121 users
-
#12
steampowered.com 13,670 users
-
#13
roblox.com 13,057 users
-
#14
paypal.com 12,286 users
-
#15
linkedin.com 11,804 users
-
#16
apple.com 11,143 users
-
#17
mega.nz 11,093 users
-
#18
spotify.com 9,330 users
-
#19
twitch.tv 9,268 users
-
#20
riotgames.com 9,266 users
-
#21
com.discord 9,150 users
-
#22
com.spotify.music 9,144 users
-
#23
epicgames.com 8,781 users
-
#24
com.pinterest 8,398 users
-
#25
com.roblox.client 8,308 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 325 employees
-
#2
qq.com 113 employees
-
#3
163.com 102 employees
-
#4
aiou.edu.pk 102 employees
-
#5
sts.net.pk 99 employees
-
#6
wp.pl 93 employees
-
#7
ig.com.br 88 employees
-
#8
icai.org 88 employees
-
#9
banquemisr.com 87 employees
-
#10
bobibanking.com 81 employees
-
#11
abv.bg 76 employees
-
#12
unionbankonline.co.in 75 employees
-
#13
atlassian.com 75 employees
-
#14
login.sp.gov.br 70 employees
-
#15
alxswe.com 69 employees
-
#16
secureserver.net 69 employees
-
#17
freemail.hu 61 employees
-
#18
web-hosting.com 60 employees
-
#19
hostinger.com 58 employees
-
#20
buenosaires.gob.ar 56 employees
-
#21
laureate.net 55 employees
-
#22
utp.edu.pe 51 employees
-
#23
ukr.net 50 employees
-
#24
aruba.it 50 employees
-
#25
secop.gov.co 49 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 22 employees
-
#2
ibm.com 15 employees
-
#3
microsoft.com 11 employees
-
#4
hp.com 10 employees
-
#5
amazon.com 7 employees
-
#6
cablevision.com 6 employees
-
#7
halliburton.com 5 employees
-
#8
davita.com 5 employees
-
#9
xerox.com 4 employees
-
#10
ncr.com 4 employees
-
#11
netflix.com 4 employees
-
#12
salesforce.com 4 employees
-
#13
apple.com 3 employees
-
#14
publix.com 3 employees
-
#15
aramark.com 3 employees
-
#16
pg.com 3 employees
-
#17
cisco.com 3 employees
-
#18
ford.com 2 employees
-
#19
oxy.com 2 employees
-
#20
cognizant.com 2 employees
Compromised users
-
#1
google.com 47,229 users
-
#2
facebook.com 42,692 users
-
#3
netflix.com 18,482 users
-
#4
amazon.com 16,679 users
-
#5
paypal.com 12,286 users
-
#6
apple.com 11,143 users
-
#7
oracle.com 2,402 users
-
#8
microsoft.com 2,312 users
-
#9
ebay.com 2,242 users
-
#10
cisco.com 1,686 users
-
#11
hp.com 1,451 users
-
#12
nike.com 1,069 users
-
#13
ibm.com 742 users
-
#14
walmart.com 492 users
-
#15
westernunion.com 365 users
-
#16
intel.com 341 users
-
#17
ups.com 310 users
-
#18
salesforce.com 260 users
-
#19
fedex.com 214 users
-
#20
adp.com 185 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
22,159 users
15,860 users
Netflix
14,121 users
Discord
9,150 users
Spotify
9,144 users
8,398 users
Roblox
8,308 users
Snapchat
7,109 users
6,949 users
Twitch
6,684 users
Wish
4,497 users
PayPal
3,976 users
Zoom
3,713 users
Mega
3,530 users
3,529 users
Mercadolibre
3,227 users
Disney
2,946 users
Alibaba
2,490 users
Xiaomi
2,444 users
Waze
2,306 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 2,007,583 users
-
#2
hotmail.com 243,471 users
-
#3
yahoo.com 86,528 users
-
#4
outlook.com 55,293 users
-
#5
icloud.com 12,001 users
-
#6
live.com 9,631 users
-
#7
yahoo.com.br 8,589 users
-
#8
mail.ru 7,274 users
-
#9
msn.com 4,254 users
-
#10
ymail.com 3,599 users
-
#11
hotmail.fr 3,498 users
-
#12
yahoo.fr 3,103 users
-
#13
yahoo.co.id 2,402 users
-
#14
mail.com 1,912 users
-
#15
gmx.com 1,833 users
-
#16
hotmail.es 1,774 users
-
#17
proton.me 1,542 users
-
#18
yandex.ru 1,518 users
-
#19
yandex.com 1,490 users
-
#20
live.fr 1,390 users
-
#21
email.com 1,284 users
-
#22
aol.com 1,220 users
-
#23
hotmail.it 1,187 users
-
#24
hotmail.com.br 1,173 users
-
#25
protonmail.com 1,148 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 47,035machines
- #2 RedLine 26,779machines
- #3 Generic Stealer 1,838machines
Anti-virus Coverage
- #1 Windows Defender 25,144machines
- #2 360 Total Security 796machines
- #3 Reason Cybersecurity 708machines
- #4 Avast Antivirus 634machines
- #5 ESET Security 291machines
- #6 McAfee Firewall 287machines
- #7 McAfee VirusScan 276machines
- #8 McAfee 189machines
- #9 AVG Antivirus 166machines
- #10 Kaspersky Internet Security 152machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 190,285hits
- #2 sso 50,090hits
- #3 zoom 18,568hits
- #4 github 11,776hits
- #5 oracle 5,017hits
- #6 sap 4,981hits
- #7 webmail 4,362hits
- #8 zendesk 3,103hits
- #9 vpn 2,364hits
- #10 adfs 2,349hits
- #11 ping 2,194hits
- #12 kaspersky 1,491hits
- #13 sts 1,317hits
- #14 salesforce 1,310hits
- #15 webex 1,303hits
- #16 extranet 1,192hits
- #17 owa 1,139hits
- #18 cpanel 949hits
- #19 st 927hits
- #20 ftp 881hits
- #21 twilio 623hits
- #22 gitlab 610hits
- #23 imap 559hits
- #24 roundcube 535hits
- #25 okta 327hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.