Skip to content
Weekly intelligence Jul 1 – Jul 8, 2024 13 min read

Infostealers Weekly Report: 2024-07-01 – 2024-07-08

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 22,191 Compromised Machines
#2 4,252 Compromised Employees
#3 6,600 Compromised Users
#4 11,339 Compromised Androids
#5 215,889 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 184
Infections by country

Top 25 countries

  1. #1 India 1,231
  2. #2 Turkey 886
  3. #3 Indonesia 857
  4. #4 Egypt 809
  5. #5 Pakistan 761
  6. #6 Brazil 681
  7. #7 Vietnam 648
  8. #8 Thailand 469
  9. #9 Argentina 349
  10. #10 Bangladesh 322
  11. #11 Philippines 289
  12. #12 Colombia 284
  13. #13 Mexico 267
  14. #14 Spain 241
  15. #15 United States of America 234
  16. #16 Algeria 232
  17. #17 Peru 210
  18. #18 Chile 205
  19. #19 Iraq 177
  20. #20 Morocco 176
  21. #21 Venezuela 161
  22. #22 Sri Lanka 121
  23. #23 Romania 101
  24. #24 Poland 99
  25. #25 South Africa 97

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 13,856 users
  2. #2 facebook.com 11,999 users
  3. #3 live.com 11,237 users
  4. #4 instagram.com 6,452 users
  5. #5 discord.com 5,993 users
  6. #6 com.facebook.katana 5,853 users
  7. #7 netflix.com 5,417 users
  8. #8 roblox.com 4,649 users
  9. #9 steampowered.com 4,598 users
  10. #10 amazon.com 4,460 users
  11. #11 twitter.com 4,108 users
  12. #12 com.instagram.android 4,068 users
  13. #13 com.netflix.mediaclient 3,896 users
  14. #14 microsoftonline.com 3,606 users
  15. #15 paypal.com 3,545 users
  16. #16 twitch.tv 3,373 users
  17. #17 riotgames.com 3,360 users
  18. #18 apple.com 3,286 users
  19. #19 spotify.com 3,232 users
  20. #20 mega.nz 3,201 users
  21. #21 epicgames.com 3,021 users
  22. #22 192.168.1.1 2,962 users
  23. #23 steamcommunity.com 2,815 users
  24. #24 com.discord 2,799 users
  25. #25 linkedin.com 2,729 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 hostinger.com 83 employees
  2. #2 163.com 53 employees
  3. #3 icicibank.com 51 employees
  4. #4 watchit.com 43 employees
  5. #5 qq.com 39 employees
  6. #6 rediff.com 37 employees
  7. #7 firstmail.ltd 32 employees
  8. #8 banquemisr.com 28 employees
  9. #9 wp.pl 27 employees
  10. #10 deped.gov.ph 24 employees
  11. #11 mail.tm 24 employees
  12. #12 secop.gov.co 24 employees
  13. #13 yandex.com.tr 23 employees
  14. #14 alxswe.com 21 employees
  15. #15 icai.org 20 employees
  16. #16 jwpub.org 20 employees
  17. #17 sts.net.pk 18 employees
  18. #18 santander.com.br 17 employees
  19. #19 rockwellautomation.com 17 employees
  20. #20 bni.co.id 16 employees
  21. #21 ionos.com 16 employees
  22. #22 laureate.net 16 employees
  23. #23 bobibanking.com 16 employees
  24. #24 bluehost.com 16 employees
  25. #25 inacap.cl 16 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 rockwellautomation.com 17 employees
  2. #2 microsoft.com 10 employees
  3. #3 netflix.com 4 employees
  4. #4 ups.com 4 employees
  5. #5 metlife.com 2 employees
  6. #6 ford.com 2 employees
  7. #7 hp.com 2 employees
  8. #8 emc.com 2 employees
  9. #9 csc.com 2 employees
  10. #10 publix.com 2 employees
  11. #11 cbre.com 2 employees
  12. #12 essendant.com 1 employees
  13. #13 google.com 1 employees
  14. #14 pvh.com 1 employees
  15. #15 jnj.com 1 employees
  16. #16 ibm.com 1 employees
  17. #17 marriott.com 1 employees
  18. #18 uhsinc.com 1 employees
  19. #19 paypal.com 1 employees
  20. #20 halliburton.com 1 employees

Compromised users

  1. #1 google.com 13,856 users
  2. #2 facebook.com 11,999 users
  3. #3 netflix.com 5,417 users
  4. #4 amazon.com 4,460 users
  5. #5 paypal.com 3,545 users
  6. #6 apple.com 3,286 users
  7. #7 oracle.com 563 users
  8. #8 ebay.com 557 users
  9. #9 microsoft.com 493 users
  10. #10 hp.com 472 users
  11. #11 nike.com 387 users
  12. #12 cisco.com 346 users
  13. #13 ibm.com 179 users
  14. #14 walmart.com 146 users
  15. #15 ups.com 130 users
  16. #16 westernunion.com 111 users
  17. #17 intel.com 88 users
  18. #18 fedex.com 87 users
  19. #19 bestbuy.com 65 users
  20. #20 target.com 60 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

5,853 users

#2

Instagram

instagram.com · com.instagram.android

4,068 users

#3

Netflix

netflix.com · com.netflix.mediaclient

3,896 users

#4

Discord

discord.com · com.discord

2,799 users

#5

Roblox

roblox.com · com.roblox.client

2,564 users

#6

Spotify

spotify.com · com.spotify.music

2,392 users

#7

Twitch

app.com · tv.twitch.android.app

2,067 users

#8

Twitter

twitter.com · com.twitter.android

1,844 users

#9

Pinterest

pinterest.com · com.pinterest

1,786 users

#10

Snapchat

snapchat.com · com.snapchat.android

1,743 users

#11

PayPal

paypal.com · com.paypal.android.p2pmobile

1,029 users

#12

Wish

contextlogic.com · com.contextlogic.wish

1,021 users

#13

Zoom

videomeetings.com · us.zoom.videomeetings

952 users

#14

Mega

app.com · mega.privacy.android.app

944 users

#15

Disney

disney.com · com.disney.disneyplus

910 users

#16

LinkedIn

linkedin.com · com.linkedin.android

762 users

#17

Xiaomi

xiaomi.com · com.xiaomi.account

723 users

#18

Mercadolibre

mercadolibre.com · com.mercadolibre

700 users

#19

Alibaba

alibaba.com · com.alibaba.aliexpresshd

577 users

#20

Waze

waze.com · com.waze

567 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 553,986 users
  2. #2 hotmail.com 63,877 users
  3. #3 yahoo.com 21,826 users
  4. #4 outlook.com 16,867 users
  5. #5 icloud.com 4,269 users
  6. #6 live.com 2,684 users
  7. #7 mail.ru 1,876 users
  8. #8 hotmail.es 1,779 users
  9. #9 msn.com 1,396 users
  10. #10 web.de 1,261 users
  11. #11 yahoo.com.br 1,182 users
  12. #12 yahoo.fr 856 users
  13. #13 mail.com 835 users
  14. #14 googlemail.com 825 users
  15. #15 ymail.com 816 users
  16. #16 hotmail.de 791 users
  17. #17 hotmail.fr 773 users
  18. #18 yandex.ru 737 users
  19. #19 aol.com 671 users
  20. #20 yahoo.co.id 660 users
  21. #21 yahoo.com.ar 635 users
  22. #22 gmx.com 620 users
  23. #23 orange.fr 615 users
  24. #24 yandex.com 579 users
  25. #25 me.com 497 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 11,999 accounts
  2. #2 twitter.com 4,108 accounts
  3. #3 instagram.com 6,452 accounts
  4. #4 linkedin.com 2,729 accounts
  5. #5 pinterest.com 964 accounts
  6. #6 tiktok.com 1,386 accounts
  7. #7 snapchat.com 1,112 accounts
  8. #8 reddit.com 535 accounts
  9. #9 youtube.com 84 accounts
  10. #10 weibo.com 70 accounts
  11. #11 vk.com 682 accounts
  12. #12 telegram.org 97 accounts
  13. #13 tumblr.com 325 accounts
  14. #14 discord.com 5,993 accounts
  15. #15 flickr.com 150 accounts
  16. #16 myspace.com 23 accounts
  17. #17 badoo.com 122 accounts
  18. #18 meetup.com 16 accounts
  19. #19 quora.com 62 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Lumma 7,260machines
  2. #2 Vidar 6,948machines
  3. #3 Generic Stealer 4,218machines
  4. #4 RedLine 3,755machines
  5. #5 StealC 10machines

Anti-virus Coverage

  1. #1 Windows Defender 12,634machines
  2. #2 Reason Cybersecurity 945machines
  3. #3 Unknown 683machines
  4. #4 Windows Defender [ON] 429machines
  5. #5 None 405machines
  6. #6 Avast Antivirus 162machines
  7. #7 360 Total Security 118machines
  8. #8 McAfee 76machines
  9. #9 ESET Security 66machines
  10. #10 Norton Security 48machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 57,622hits
  2. #2 sso 14,915hits
  3. #3 zoom 4,774hits
  4. #4 github 3,570hits
  5. #5 adfs 1,588hits
  6. #6 webmail 1,486hits
  7. #7 oracle 1,162hits
  8. #8 zendesk 863hits
  9. #9 owa 799hits
  10. #10 vpn 726hits
  11. #11 sap 686hits
  12. #12 ping 682hits
  13. #13 cpanel 577hits
  14. #14 sts 454hits
  15. #15 st 332hits
  16. #16 webex 280hits
  17. #17 kaspersky 279hits
  18. #18 extranet 277hits
  19. #19 roundcube 233hits
  20. #20 ftp 231hits
  21. #21 okta 206hits
  22. #22 imap 167hits
  23. #23 twilio 163hits
  24. #24 salesforce 162hits
  25. #25 gitlab 137hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure