Infostealers Weekly Report: 2024-02-12 – 2024-02-19
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 2,008
- #2 Pakistan 1,159
- #3 Philippines 1,076
- #4 Turkey 1,062
- #5 Argentina 1,044
- #6 Mexico 875
- #7 Vietnam 862
- #8 Peru 852
- #9 Egypt 765
- #10 Colombia 744
- #11 Bangladesh 636
- #12 Thailand 631
- #13 United States of America 609
- #14 Indonesia 531
- #15 India 491
- #16 Algeria 488
- #17 Spain 480
- #18 Chile 428
- #19 Sri Lanka 396
- #20 Malaysia 394
- #21 Ecuador 371
- #22 Morocco 369
- #23 Saudi Arabia 281
- #24 Venezuela 278
- #25 Iraq 259
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 32,416 users
-
#2
facebook.com 29,826 users
-
#3
live.com 28,327 users
-
#4
com.facebook.katana 15,780 users
-
#5
discord.com 14,935 users
-
#6
instagram.com 14,815 users
-
#7
netflix.com 13,585 users
-
#8
roblox.com 13,372 users
-
#9
steampowered.com 11,355 users
-
#10
amazon.com 10,955 users
-
#11
com.netflix.mediaclient 10,365 users
-
#12
twitter.com 10,169 users
-
#13
com.instagram.android 10,149 users
-
#14
paypal.com 8,728 users
-
#15
mega.nz 8,535 users
-
#16
microsoftonline.com 8,505 users
-
#17
twitch.tv 8,027 users
-
#18
com.roblox.client 7,788 users
-
#19
riotgames.com 7,453 users
-
#20
spotify.com 7,411 users
-
#21
epicgames.com 7,407 users
-
#22
apple.com 7,258 users
-
#23
linkedin.com 6,876 users
-
#24
com.discord 6,768 users
-
#25
steamcommunity.com 6,234 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
secop.gov.co 146 employees
-
#2
hostinger.com 120 employees
-
#3
buenosaires.gob.ar 100 employees
-
#4
laureate.net 87 employees
-
#5
wp.pl 84 employees
-
#6
qq.com 73 employees
-
#7
deped.gov.ph 71 employees
-
#8
firstmail.ltd 69 employees
-
#9
icicibank.com 64 employees
-
#10
freemail.hu 61 employees
-
#11
aruba.it 58 employees
-
#12
inacap.cl 57 employees
-
#13
telecom.pt 56 employees
-
#14
utpl.edu.ec 56 employees
-
#15
163.com 56 employees
-
#16
rediff.com 53 employees
-
#17
utp.edu.pe 51 employees
-
#18
abv.bg 50 employees
-
#19
login.sp.gov.br 50 employees
-
#20
rappi.com 49 employees
-
#21
cibertec.edu.pe 48 employees
-
#22
seznam.cz 46 employees
-
#23
mail.tm 45 employees
-
#24
rockwellautomation.com 45 employees
-
#25
aiep.cl 44 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 45 employees
-
#2
microsoft.com 32 employees
-
#3
netflix.com 25 employees
-
#4
ibm.com 10 employees
-
#5
jpmorganchase.com 8 employees
-
#6
airproducts.com 8 employees
-
#7
hp.com 6 employees
-
#8
salesforce.com 6 employees
-
#9
paypal.com 6 employees
-
#10
ford.com 5 employees
-
#11
cognizant.com 4 employees
-
#12
visteon.com 4 employees
-
#13
abbvie.com 4 employees
-
#14
johnsoncontrols.com 4 employees
-
#15
baxter.com 3 employees
-
#16
dupont.com 3 employees
-
#17
ajg.com 2 employees
-
#18
frontier.com 2 employees
-
#19
csc.com 2 employees
-
#20
ups.com 2 employees
Compromised users
-
#1
google.com 32,416 users
-
#2
facebook.com 29,826 users
-
#3
netflix.com 13,585 users
-
#4
amazon.com 10,955 users
-
#5
paypal.com 8,728 users
-
#6
apple.com 7,258 users
-
#7
ebay.com 1,486 users
-
#8
microsoft.com 1,200 users
-
#9
hp.com 1,041 users
-
#10
oracle.com 1,010 users
-
#11
nike.com 909 users
-
#12
cisco.com 852 users
-
#13
ibm.com 353 users
-
#14
walmart.com 345 users
-
#15
westernunion.com 239 users
-
#16
ups.com 231 users
-
#17
intel.com 222 users
-
#18
fedex.com 190 users
-
#19
adp.com 141 users
-
#20
bestbuy.com 141 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
15,780 users
Netflix
10,365 users
10,149 users
Roblox
7,788 users
Discord
6,768 users
Spotify
5,807 users
Twitch
5,720 users
4,354 users
Snapchat
3,993 users
3,058 users
Disney
3,044 users
Wish
3,024 users
Mercadolibre
2,656 users
PayPal
2,646 users
Zoom
2,453 users
Mega
2,286 users
1,959 users
Waze
1,756 users
Xiaomi
1,705 users
Alibaba
1,670 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,243,624 users
-
#2
hotmail.com 191,691 users
-
#3
yahoo.com 47,551 users
-
#4
outlook.com 39,031 users
-
#5
icloud.com 9,086 users
-
#6
live.com 6,137 users
-
#7
yahoo.com.br 5,566 users
-
#8
yahoo.fr 3,450 users
-
#9
hotmail.es 3,393 users
-
#10
libero.it 3,355 users
-
#11
mail.ru 3,148 users
-
#12
hotmail.fr 2,652 users
-
#13
msn.com 2,467 users
-
#14
gmx.de 1,767 users
-
#15
free.fr 1,727 users
-
#16
web.de 1,661 users
-
#17
yahoo.com.ar 1,533 users
-
#18
ymail.com 1,384 users
-
#19
alice.it 1,376 users
-
#20
mail.com 1,273 users
-
#21
hotmail.com.ar 1,129 users
-
#22
yahoo.com.mx 1,073 users
-
#23
yahoo.co.id 997 users
-
#24
aol.com 836 users
-
#25
tiscali.it 830 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 32,894machines
- #2 Lumma 11,636machines
- #3 Generic Stealer 3,988machines
Anti-virus Coverage
- #1 Windows Defender 30,793machines
- #2 Reason Cybersecurity 1,433machines
- #3 360 Total Security 1,109machines
- #4 Avast Antivirus 894machines
- #5 McAfee Firewall 486machines
- #6 McAfee VirusScan 398machines
- #7 McAfee 345machines
- #8 ESET Security 339machines
- #9 AVG Antivirus 262machines
- #10 Kaspersky 199machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 124,394hits
- #2 sso 32,442hits
- #3 zoom 12,644hits
- #4 github 5,899hits
- #5 webmail 4,535hits
- #6 adfs 3,251hits
- #7 oracle 2,488hits
- #8 sap 2,110hits
- #9 zendesk 2,046hits
- #10 salesforce 1,764hits
- #11 owa 1,762hits
- #12 cpanel 1,305hits
- #13 vpn 1,235hits
- #14 ping 1,200hits
- #15 sts 1,088hits
- #16 webex 1,033hits
- #17 extranet 927hits
- #18 imap 802hits
- #19 kaspersky 787hits
- #20 st 556hits
- #21 ftp 554hits
- #22 roundcube 509hits
- #23 okta 462hits
- #24 twilio 276hits
- #25 zimbra 191hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.