Infostealers Weekly Report: 2024-02-19 – 2024-02-26
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 1,252
- #2 Pakistan 890
- #3 Argentina 749
- #4 Philippines 723
- #5 Mexico 664
- #6 Turkey 664
- #7 Peru 659
- #8 Colombia 605
- #9 Vietnam 579
- #10 India 551
- #11 Egypt 492
- #12 Bangladesh 466
- #13 Indonesia 459
- #14 Thailand 425
- #15 Ecuador 380
- #16 Chile 352
- #17 Algeria 316
- #18 Morocco 282
- #19 United States of America 268
- #20 Venezuela 264
- #21 Malaysia 250
- #22 Saudi Arabia 245
- #23 Spain 215
- #24 Poland 194
- #25 Iraq 192
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 27,517 users
-
#2
facebook.com 25,052 users
-
#3
live.com 24,148 users
-
#4
com.facebook.katana 13,163 users
-
#5
instagram.com 12,856 users
-
#6
discord.com 12,509 users
-
#7
roblox.com 11,874 users
-
#8
netflix.com 11,563 users
-
#9
steampowered.com 9,439 users
-
#10
amazon.com 9,287 users
-
#11
twitter.com 8,889 users
-
#12
com.netflix.mediaclient 8,810 users
-
#13
com.instagram.android 8,684 users
-
#14
microsoftonline.com 7,464 users
-
#15
paypal.com 7,198 users
-
#16
mega.nz 7,160 users
-
#17
twitch.tv 7,066 users
-
#18
com.roblox.client 6,754 users
-
#19
epicgames.com 6,514 users
-
#20
apple.com 6,476 users
-
#21
riotgames.com 6,429 users
-
#22
spotify.com 6,330 users
-
#23
com.discord 5,777 users
-
#24
192.168.1.1 5,679 users
-
#25
linkedin.com 5,582 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 113 employees
-
#2
buenosaires.gob.ar 105 employees
-
#3
utp.edu.pe 81 employees
-
#4
laureate.net 72 employees
-
#5
secop.gov.co 70 employees
-
#6
wp.pl 69 employees
-
#7
deped.gov.ph 65 employees
-
#8
mail.tm 64 employees
-
#9
firstmail.ltd 64 employees
-
#10
rediff.com 63 employees
-
#11
inacap.cl 60 employees
-
#12
secureserver.net 59 employees
-
#13
jwpub.org 58 employees
-
#14
163.com 55 employees
-
#15
bluehost.com 52 employees
-
#16
icicibank.com 51 employees
-
#17
banquemisr.com 47 employees
-
#18
freemail.hu 41 employees
-
#19
qq.com 40 employees
-
#20
web-hosting.com 40 employees
-
#21
britanico.edu.pe 38 employees
-
#22
rockwellautomation.com 36 employees
-
#23
utm.edu.ec 35 employees
-
#24
watchit.com 35 employees
-
#25
upc.edu.pe 35 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 36 employees
-
#2
netflix.com 34 employees
-
#3
microsoft.com 24 employees
-
#4
amazon.com 10 employees
-
#5
ibm.com 8 employees
-
#6
cognizant.com 7 employees
-
#7
paypal.com 6 employees
-
#8
oracle.com 6 employees
-
#9
ups.com 5 employees
-
#10
csc.com 5 employees
-
#11
emc.com 4 employees
-
#12
hp.com 4 employees
-
#13
frontier.com 4 employees
-
#14
jacobs.com 3 employees
-
#15
apple.com 2 employees
-
#16
facebook.com 2 employees
-
#17
johnsoncontrols.com 1 employees
-
#18
borgwarner.com 1 employees
-
#19
fisglobal.com 1 employees
-
#20
cisco.com 1 employees
Compromised users
-
#1
google.com 27,568 users
-
#2
facebook.com 25,098 users
-
#3
netflix.com 11,580 users
-
#4
amazon.com 9,308 users
-
#5
paypal.com 7,217 users
-
#6
apple.com 6,490 users
-
#7
ebay.com 1,145 users
-
#8
microsoft.com 1,046 users
-
#9
oracle.com 958 users
-
#10
cisco.com 866 users
-
#11
hp.com 817 users
-
#12
nike.com 742 users
-
#13
ibm.com 293 users
-
#14
walmart.com 259 users
-
#15
westernunion.com 208 users
-
#16
ups.com 200 users
-
#17
intel.com 191 users
-
#18
adp.com 114 users
-
#19
fedex.com 104 users
-
#20
bestbuy.com 98 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
13,194 users
Netflix
8,823 users
8,700 users
Roblox
6,771 users
Discord
5,789 users
Spotify
5,149 users
Twitch
4,915 users
3,713 users
Snapchat
3,574 users
3,152 users
Disney
2,618 users
Wish
2,481 users
PayPal
2,352 users
Mercadolibre
2,280 users
Zoom
2,083 users
Mega
1,926 users
1,672 users
Waze
1,430 users
Xiaomi
1,413 users
Alibaba
1,348 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,031,635 users
-
#2
hotmail.com 163,020 users
-
#3
yahoo.com 47,919 users
-
#4
outlook.com 34,660 users
-
#5
icloud.com 7,086 users
-
#6
hotmail.es 4,804 users
-
#7
msn.com 4,329 users
-
#8
live.com 4,285 users
-
#9
yahoo.com.br 2,812 users
-
#10
mail.ru 2,087 users
-
#11
hotmail.fr 1,921 users
-
#12
hotmail.com.ar 1,622 users
-
#13
yahoo.fr 1,592 users
-
#14
mail.com 1,258 users
-
#15
ymail.com 1,183 users
-
#16
yahoo.com.ar 1,092 users
-
#17
yahoo.co.id 1,021 users
-
#18
hotmail.it 985 users
-
#19
aol.com 983 users
-
#20
laposte.net 947 users
-
#21
web.de 863 users
-
#22
live.fr 788 users
-
#23
yahoo.com.ph 769 users
-
#24
proton.me 740 users
-
#25
hotmail.co.uk 731 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 24,801machines
- #2 Lumma 14,308machines
- #3 Generic Stealer 2,179machines
Anti-virus Coverage
- #1 Windows Defender 23,003machines
- #2 360 Total Security 941machines
- #3 Reason Cybersecurity 719machines
- #4 Avast Antivirus 710machines
- #5 McAfee Firewall 361machines
- #6 ESET Security 335machines
- #7 McAfee 295machines
- #8 McAfee VirusScan 273machines
- #9 AVG Antivirus 155machines
- #10 Kaspersky Internet Security 139machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 107,769hits
- #2 sso 28,443hits
- #3 zoom 11,180hits
- #4 github 5,004hits
- #5 webmail 3,720hits
- #6 adfs 3,321hits
- #7 oracle 1,984hits
- #8 sap 1,845hits
- #9 zendesk 1,483hits
- #10 owa 1,316hits
- #11 ping 1,162hits
- #12 vpn 1,086hits
- #13 cpanel 1,073hits
- #14 st 1,048hits
- #15 sts 793hits
- #16 kaspersky 757hits
- #17 webex 729hits
- #18 extranet 685hits
- #19 imap 684hits
- #20 ftp 589hits
- #21 roundcube 461hits
- #22 zimbra 399hits
- #23 okta 370hits
- #24 twilio 246hits
- #25 salesforce 215hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.