Infostealers Weekly Report: 2024-05-13 – 2024-05-20
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Egypt 659
- #2 Brazil 451
- #3 India 448
- #4 Argentina 415
- #5 Thailand 414
- #6 Indonesia 395
- #7 Turkey 367
- #8 Colombia 347
- #9 Peru 331
- #10 Pakistan 291
- #11 Spain 280
- #12 Vietnam 273
- #13 Philippines 242
- #14 Mexico 238
- #15 Algeria 190
- #16 Bangladesh 188
- #17 Chile 160
- #18 Venezuela 158
- #19 Morocco 152
- #20 Ecuador 102
- #21 Bolivia 99
- #22 Taiwan 99
- #23 Iraq 93
- #24 Dominican Republic 82
- #25 Malaysia 79
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 12,369 users
-
#2
facebook.com 11,183 users
-
#3
live.com 10,465 users
-
#4
com.facebook.katana 5,796 users
-
#5
instagram.com 5,573 users
-
#6
netflix.com 5,058 users
-
#7
discord.com 4,714 users
-
#8
amazon.com 4,095 users
-
#9
twitter.com 3,997 users
-
#10
com.instagram.android 3,846 users
-
#11
steampowered.com 3,799 users
-
#12
com.netflix.mediaclient 3,690 users
-
#13
roblox.com 3,566 users
-
#14
microsoftonline.com 3,351 users
-
#15
paypal.com 3,218 users
-
#16
192.168.1.1 3,016 users
-
#17
mega.nz 3,005 users
-
#18
linkedin.com 2,927 users
-
#19
apple.com 2,809 users
-
#20
spotify.com 2,697 users
-
#21
twitch.tv 2,580 users
-
#22
epicgames.com 2,559 users
-
#23
com.roblox.client 2,345 users
-
#24
riotgames.com 2,274 users
-
#25
com.discord 2,257 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 57 employees
-
#2
secop.gov.co 51 employees
-
#3
icicibank.com 49 employees
-
#4
watchit.com 45 employees
-
#5
buenosaires.gob.ar 40 employees
-
#6
laureate.net 35 employees
-
#7
banquemisr.com 33 employees
-
#8
inacap.cl 33 employees
-
#9
utp.edu.pe 31 employees
-
#10
aruba.it 29 employees
-
#11
rediff.com 28 employees
-
#12
yandex.com.tr 27 employees
-
#13
wp.pl 27 employees
-
#14
dnp.gov.co 26 employees
-
#15
alxswe.com 25 employees
-
#16
unionbankonline.co.in 25 employees
-
#17
pec.it 25 employees
-
#18
bluehost.com 25 employees
-
#19
jwpub.org 24 employees
-
#20
britanico.edu.pe 23 employees
-
#21
uol.com.br 23 employees
-
#22
onet.pl 21 employees
-
#23
bni.co.id 20 employees
-
#24
tigo.com.co 19 employees
-
#25
policia.gob.pe 18 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 17 employees
-
#2
rockwellautomation.com 15 employees
-
#3
ups.com 5 employees
-
#4
netflix.com 3 employees
-
#5
henryschein.com 2 employees
-
#6
apple.com 2 employees
-
#7
statefarm.com 2 employees
-
#8
hp.com 2 employees
-
#9
jll.com 2 employees
-
#10
cognizant.com 2 employees
-
#11
ibm.com 2 employees
-
#12
csc.com 1 employees
-
#13
jpmorganchase.com 1 employees
-
#14
viacom.com 1 employees
-
#15
marriott.com 1 employees
Compromised users
-
#1
google.com 12,369 users
-
#2
facebook.com 11,183 users
-
#3
netflix.com 5,058 users
-
#4
amazon.com 4,095 users
-
#5
paypal.com 3,218 users
-
#6
apple.com 2,809 users
-
#7
ebay.com 659 users
-
#8
hp.com 487 users
-
#9
oracle.com 482 users
-
#10
microsoft.com 466 users
-
#11
cisco.com 377 users
-
#12
nike.com 309 users
-
#13
ibm.com 151 users
-
#14
ups.com 122 users
-
#15
salesforce.com 91 users
-
#16
walmart.com 87 users
-
#17
westernunion.com 83 users
-
#18
intel.com 77 users
-
#19
fedex.com 66 users
-
#20
bankofamerica.com 52 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
5,796 users
3,846 users
Netflix
3,690 users
Roblox
2,345 users
Discord
2,257 users
Spotify
2,109 users
Twitch
1,981 users
1,557 users
Snapchat
1,486 users
Disney
1,193 users
Mercadolibre
1,011 users
Zoom
944 users
PayPal
889 users
Wish
875 users
857 users
Mega
840 users
826 users
Xiaomi
680 users
Alibaba
641 users
Waze
641 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 462,976 users
-
#2
hotmail.com 79,493 users
-
#3
yahoo.com 19,258 users
-
#4
outlook.com 12,887 users
-
#5
live.com 3,817 users
-
#6
icloud.com 3,027 users
-
#7
hotmail.es 2,094 users
-
#8
hotmail.fr 1,798 users
-
#9
orange.fr 1,655 users
-
#10
mail.ru 1,338 users
-
#11
yahoo.fr 1,252 users
-
#12
yahoo.com.br 1,211 users
-
#13
yahoo.com.ar 889 users
-
#14
live.it 881 users
-
#15
msn.com 805 users
-
#16
libero.it 766 users
-
#17
sfr.fr 754 users
-
#18
hotmail.it 683 users
-
#19
free.fr 643 users
-
#20
yahoo.co.id 594 users
-
#21
mail.com 485 users
-
#22
gmx.net 470 users
-
#23
live.com.mx 453 users
-
#24
outlook.com.br 402 users
-
#25
ymail.com 373 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 RedLine 15,381machines
- #2 Generic Stealer 1,832machines
- #3 DarkCrystal 1,213machines
- #4 Lumma 6machines
Anti-virus Coverage
- #1 Windows Defender 15,341machines
- #2 360 Total Security 888machines
- #3 Avast Antivirus 522machines
- #4 Reason Cybersecurity 412machines
- #5 Unknown 305machines
- #6 McAfee Firewall 205machines
- #7 McAfee 201machines
- #8 McAfee VirusScan 169machines
- #9 ESET Security 135machines
- #10 AVG Antivirus 133machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 51,191hits
- #2 sso 13,397hits
- #3 zoom 5,239hits
- #4 github 2,308hits
- #5 webmail 1,805hits
- #6 adfs 1,283hits
- #7 oracle 1,125hits
- #8 sap 687hits
- #9 owa 681hits
- #10 zendesk 660hits
- #11 vpn 506hits
- #12 sts 476hits
- #13 ping 475hits
- #14 extranet 438hits
- #15 cpanel 402hits
- #16 kaspersky 401hits
- #17 webex 358hits
- #18 ftp 291hits
- #19 imap 272hits
- #20 salesforce 244hits
- #21 st 244hits
- #22 roundcube 241hits
- #23 okta 206hits
- #24 gitlab 95hits
- #25 sharepoint 82hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.