Infostealers Weekly Report: 2024-04-01 – 2024-04-08
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 1,306
- #2 Egypt 1,103
- #3 Vietnam 893
- #4 India 876
- #5 Brazil 871
- #6 Indonesia 772
- #7 Argentina 686
- #8 Thailand 667
- #9 Bangladesh 555
- #10 Philippines 535
- #11 Pakistan 455
- #12 Algeria 443
- #13 Colombia 421
- #14 Peru 412
- #15 Mexico 406
- #16 United States of America 380
- #17 Spain 320
- #18 Chile 265
- #19 Venezuela 225
- #20 Morocco 217
- #21 Poland 182
- #22 Iraq 176
- #23 Germany 174
- #24 Ecuador 165
- #25 Malaysia 164
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 24,044 users
-
#2
facebook.com 21,948 users
-
#3
live.com 20,610 users
-
#4
com.facebook.katana 11,205 users
-
#5
instagram.com 11,191 users
-
#6
discord.com 10,197 users
-
#7
netflix.com 9,779 users
-
#8
roblox.com 8,993 users
-
#9
steampowered.com 8,168 users
-
#10
twitter.com 7,891 users
-
#11
amazon.com 7,795 users
-
#12
com.instagram.android 7,442 users
-
#13
com.netflix.mediaclient 7,097 users
-
#14
microsoftonline.com 6,555 users
-
#15
paypal.com 6,173 users
-
#16
mega.nz 5,742 users
-
#17
riotgames.com 5,628 users
-
#18
192.168.1.1 5,608 users
-
#19
spotify.com 5,571 users
-
#20
twitch.tv 5,539 users
-
#21
epicgames.com 5,513 users
-
#22
apple.com 5,456 users
-
#23
com.roblox.client 5,284 users
-
#24
linkedin.com 5,146 users
-
#25
com.discord 4,682 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 99 employees
-
#2
watchit.com 98 employees
-
#3
rediff.com 86 employees
-
#4
secop.gov.co 78 employees
-
#5
wp.pl 78 employees
-
#6
banquemisr.com 70 employees
-
#7
icicibank.com 63 employees
-
#8
firstmail.ltd 61 employees
-
#9
aruba.it 57 employees
-
#10
163.com 52 employees
-
#11
yandex.com.tr 51 employees
-
#12
mail.tm 51 employees
-
#13
tim.it 47 employees
-
#14
buenosaires.gob.ar 47 employees
-
#15
laureate.net 44 employees
-
#16
bcb.gov.br 44 employees
-
#17
ovh.net 42 employees
-
#18
secureserver.net 40 employees
-
#19
inacap.cl 39 employees
-
#20
qq.com 39 employees
-
#21
alxswe.com 37 employees
-
#22
ionos.es 35 employees
-
#23
pec.it 35 employees
-
#24
abv.bg 33 employees
-
#25
rockwellautomation.com 32 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 32 employees
-
#2
microsoft.com 23 employees
-
#3
goodyear.com 7 employees
-
#4
amazon.com 6 employees
-
#5
baxter.com 5 employees
-
#6
google.com 5 employees
-
#7
generalmills.com 4 employees
-
#8
hp.com 4 employees
-
#9
xerox.com 3 employees
-
#10
publix.com 3 employees
-
#11
jpmorganchase.com 3 employees
-
#12
jll.com 3 employees
-
#13
ups.com 2 employees
-
#14
parker.com 1 employees
-
#15
ibm.com 1 employees
-
#16
oracle.com 1 employees
-
#17
salesforce.com 1 employees
-
#18
conocophillips.com 1 employees
-
#19
pepsico.com 1 employees
-
#20
jnj.com 1 employees
Compromised users
-
#1
google.com 24,044 users
-
#2
facebook.com 21,948 users
-
#3
netflix.com 9,779 users
-
#4
amazon.com 7,795 users
-
#5
paypal.com 6,173 users
-
#6
apple.com 5,456 users
-
#7
ebay.com 1,029 users
-
#8
microsoft.com 957 users
-
#9
hp.com 858 users
-
#10
oracle.com 788 users
-
#11
nike.com 686 users
-
#12
cisco.com 641 users
-
#13
walmart.com 260 users
-
#14
ibm.com 253 users
-
#15
westernunion.com 209 users
-
#16
ups.com 194 users
-
#17
intel.com 177 users
-
#18
fedex.com 107 users
-
#19
bestbuy.com 98 users
-
#20
adp.com 83 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
11,205 users
7,442 users
Netflix
7,097 users
Roblox
5,284 users
Discord
4,682 users
Spotify
4,118 users
Twitch
3,947 users
3,253 users
Snapchat
3,032 users
Disney
2,041 users
PayPal
2,022 users
2,009 users
Zoom
1,888 users
Wish
1,850 users
Mega
1,766 users
Mercadolibre
1,591 users
1,504 users
Xiaomi
1,348 users
Alibaba
1,087 users
Waze
1,033 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 954,187 users
-
#2
hotmail.com 136,653 users
-
#3
yahoo.com 49,063 users
-
#4
outlook.com 29,108 users
-
#5
icloud.com 7,258 users
-
#6
live.com 6,021 users
-
#7
msn.com 3,926 users
-
#8
yahoo.fr 3,844 users
-
#9
mail.ru 2,944 users
-
#10
hotmail.es 2,520 users
-
#11
yahoo.com.br 2,364 users
-
#12
hotmail.fr 2,289 users
-
#13
libero.it 1,384 users
-
#14
googlemail.com 1,353 users
-
#15
ymail.com 1,346 users
-
#16
yahoo.co.uk 1,181 users
-
#17
yahoo.co.id 1,180 users
-
#18
yahoo.com.ar 1,144 users
-
#19
web.de 1,013 users
-
#20
tiscali.it 952 users
-
#21
free.fr 931 users
-
#22
mail.com 864 users
-
#23
aol.com 849 users
-
#24
hotmail.it 800 users
-
#25
hotmail.co.uk 730 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 26,494machines
- #2 Lumma 5,307machines
- #3 Generic Stealer 4,151machines
- #4 DarkCrystal 205machines
- #5 Atomic 20machines
Anti-virus Coverage
- #1 Windows Defender 25,004machines
- #2 Reason Cybersecurity 1,240machines
- #3 Avast Antivirus 1,071machines
- #4 360 Total Security 958machines
- #5 McAfee 411machines
- #6 McAfee Firewall 350machines
- #7 McAfee VirusScan 302machines
- #8 AVG Antivirus 296machines
- #9 ESET Security 213machines
- #10 Kaspersky Internet Security 163machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 99,768hits
- #2 sso 30,322hits
- #3 zoom 10,274hits
- #4 github 4,745hits
- #5 webmail 3,439hits
- #6 adfs 2,598hits
- #7 oracle 1,578hits
- #8 sap 1,348hits
- #9 zendesk 1,323hits
- #10 owa 1,192hits
- #11 ping 1,027hits
- #12 vpn 1,022hits
- #13 cpanel 950hits
- #14 sts 746hits
- #15 kaspersky 717hits
- #16 webex 623hits
- #17 roundcube 611hits
- #18 imap 551hits
- #19 salesforce 536hits
- #20 ftp 458hits
- #21 extranet 428hits
- #22 st 415hits
- #23 okta 333hits
- #24 twilio 264hits
- #25 gitlab 140hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.