Infostealers Weekly Report: 2024-05-27 – 2024-06-03
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 4,433
- #2 India 2,681
- #3 Indonesia 2,384
- #4 Brazil 1,619
- #5 Egypt 1,188
- #6 United States of America 1,147
- #7 Vietnam 1,089
- #8 Pakistan 1,060
- #9 Thailand 1,024
- #10 Mexico 933
- #11 Colombia 889
- #12 Philippines 871
- #13 Argentina 711
- #14 Taiwan 699
- #15 Peru 688
- #16 Bangladesh 564
- #17 Chile 479
- #18 Spain 432
- #19 Algeria 419
- #20 Malaysia 352
- #21 Morocco 322
- #22 South Korea 301
- #23 Saudi Arabia 287
- #24 Poland 266
- #25 Venezuela 265
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 23,334 users
-
#2
facebook.com 20,206 users
-
#3
live.com 19,592 users
-
#4
instagram.com 11,488 users
-
#5
discord.com 10,629 users
-
#6
netflix.com 10,198 users
-
#7
com.facebook.katana 9,818 users
-
#8
steampowered.com 8,579 users
-
#9
amazon.com 8,491 users
-
#10
roblox.com 8,261 users
-
#11
twitter.com 8,239 users
-
#12
com.instagram.android 7,269 users
-
#13
microsoftonline.com 6,829 users
-
#14
com.netflix.mediaclient 6,732 users
-
#15
spotify.com 6,545 users
-
#16
twitch.tv 6,473 users
-
#17
paypal.com 6,227 users
-
#18
riotgames.com 6,110 users
-
#19
apple.com 6,038 users
-
#20
192.168.1.1 5,592 users
-
#21
epicgames.com 5,542 users
-
#22
linkedin.com 5,439 users
-
#23
mega.nz 5,383 users
-
#24
steamcommunity.com 5,213 users
-
#25
com.discord 4,798 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
yandex.com.tr 157 employees
-
#2
hostinger.com 144 employees
-
#3
icicibank.com 113 employees
-
#4
rediff.com 71 employees
-
#5
anadolu.edu.tr 68 employees
-
#6
watchit.com 66 employees
-
#7
wp.pl 59 employees
-
#8
secureserver.net 55 employees
-
#9
inacap.cl 50 employees
-
#10
secop.gov.co 49 employees
-
#11
aruba.it 48 employees
-
#12
163.com 46 employees
-
#13
laureate.net 44 employees
-
#14
buenosaires.gob.ar 44 employees
-
#15
qq.com 43 employees
-
#16
firstmail.ltd 41 employees
-
#17
naver.com 38 employees
-
#18
banquemisr.com 38 employees
-
#19
mail.com.tr 34 employees
-
#20
bluehost.com 34 employees
-
#21
mail.tm 33 employees
-
#22
deped.gov.ph 33 employees
-
#23
bni.co.id 31 employees
-
#24
hostgator.com 31 employees
-
#25
unionbankonline.co.in 30 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 29 employees
-
#2
rockwellautomation.com 18 employees
-
#3
publix.com 12 employees
-
#4
amazon.com 11 employees
-
#5
ibm.com 6 employees
-
#6
netflix.com 6 employees
-
#7
cognizant.com 6 employees
-
#8
hp.com 5 employees
-
#9
ford.com 4 employees
-
#10
twc.com 4 employees
-
#11
xerox.com 3 employees
-
#12
oracle.com 3 employees
-
#13
allstate.com 3 employees
-
#14
cisco.com 3 employees
-
#15
unitedhealthgroup.com 2 employees
-
#16
intel.com 2 employees
-
#17
starbucks.com 2 employees
-
#18
ge.com 2 employees
-
#19
fedex.com 2 employees
-
#20
google.com 1 employees
Compromised users
-
#1
google.com 23,334 users
-
#2
facebook.com 20,206 users
-
#3
netflix.com 10,198 users
-
#4
amazon.com 8,491 users
-
#5
paypal.com 6,227 users
-
#6
apple.com 6,038 users
-
#7
ebay.com 1,413 users
-
#8
oracle.com 949 users
-
#9
microsoft.com 926 users
-
#10
hp.com 907 users
-
#11
nike.com 831 users
-
#12
cisco.com 703 users
-
#13
walmart.com 515 users
-
#14
ups.com 387 users
-
#15
ibm.com 359 users
-
#16
bestbuy.com 357 users
-
#17
fedex.com 312 users
-
#18
adp.com 261 users
-
#19
target.com 258 users
-
#20
att.com 215 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
9,818 users
7,269 users
Netflix
6,732 users
Discord
4,798 users
Roblox
4,497 users
Spotify
4,221 users
Twitch
3,940 users
3,261 users
Snapchat
2,908 users
Disney
1,912 users
PayPal
1,679 users
Zoom
1,672 users
Wish
1,513 users
1,496 users
1,488 users
Mega
1,436 users
Xiaomi
1,315 users
Mercadolibre
1,202 users
Waze
1,082 users
Alibaba
1,035 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,017,977 users
-
#2
hotmail.com 146,153 users
-
#3
yahoo.com 45,240 users
-
#4
outlook.com 29,424 users
-
#5
icloud.com 7,831 users
-
#6
live.com 6,402 users
-
#7
msn.com 4,504 users
-
#8
yandex.com 2,276 users
-
#9
mail.ru 2,105 users
-
#10
hotmail.fr 2,054 users
-
#11
yahoo.com.br 2,050 users
-
#12
hotmail.es 2,027 users
-
#13
free.fr 1,767 users
-
#14
yahoo.co.id 1,681 users
-
#15
aol.com 1,542 users
-
#16
ymail.com 1,345 users
-
#17
live.co.uk 1,271 users
-
#18
yahoo.fr 1,236 users
-
#19
mail.com 1,212 users
-
#20
hotmail.it 1,137 users
-
#21
comcast.net 847 users
-
#22
protonmail.com 839 users
-
#23
web.de 828 users
-
#24
live.fr 773 users
-
#25
orange.fr 766 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 StealC 21,958machines
- #2 RedLine 8,458machines
- #3 Generic Stealer 4,165machines
- #4 Lumma 2,779machines
- #5 DarkCrystal 58machines
Anti-virus Coverage
- #1 Windows Defender 8,002machines
- #2 360 Total Security 527machines
- #3 Avast Antivirus 303machines
- #4 Reason Cybersecurity 284machines
- #5 McAfee 132machines
- #6 McAfee Firewall 125machines
- #7 McAfee VirusScan 106machines
- #8 AVG Antivirus 66machines
- #9 Kaspersky 53machines
- #10 Malwarebytes 52machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 112,008hits
- #2 sso 29,430hits
- #3 zoom 9,484hits
- #4 github 5,455hits
- #5 webmail 4,701hits
- #6 adfs 3,160hits
- #7 sap 2,134hits
- #8 oracle 2,035hits
- #9 owa 1,865hits
- #10 zendesk 1,735hits
- #11 ping 1,240hits
- #12 cpanel 1,194hits
- #13 sts 1,109hits
- #14 vpn 1,085hits
- #15 kaspersky 806hits
- #16 webex 776hits
- #17 ftp 705hits
- #18 st 629hits
- #19 roundcube 590hits
- #20 extranet 531hits
- #21 salesforce 525hits
- #22 okta 473hits
- #23 gitlab 302hits
- #24 twilio 267hits
- #25 imap 254hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.