Infostealers Weekly Report: 2024-10-14 – 2024-10-21
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 916
- #2 Brazil 593
- #3 Indonesia 459
- #4 Vietnam 416
- #5 Thailand 385
- #6 Philippines 339
- #7 United States of America 335
- #8 Pakistan 312
- #9 Turkey 259
- #10 Egypt 258
- #11 Germany 167
- #12 Colombia 167
- #13 Poland 162
- #14 Bangladesh 162
- #15 France 157
- #16 Peru 155
- #17 Italy 141
- #18 Mexico 141
- #19 Spain 133
- #20 Argentina 110
- #21 United Kingdom 104
- #22 South Africa 102
- #23 Morocco 101
- #24 South Korea 90
- #25 Romania 89
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 7,156 users
-
#2
facebook.com 5,923 users
-
#3
live.com 5,472 users
-
#4
instagram.com 3,402 users
-
#5
discord.com 3,342 users
-
#6
roblox.com 3,066 users
-
#7
com.facebook.katana 2,984 users
-
#8
netflix.com 2,760 users
-
#9
amazon.com 2,207 users
-
#10
steampowered.com 2,162 users
-
#11
com.instagram.android 2,061 users
-
#12
twitter.com 2,030 users
-
#13
com.netflix.mediaclient 1,907 users
-
#14
paypal.com 1,900 users
-
#15
apple.com 1,763 users
-
#16
microsoftonline.com 1,705 users
-
#17
spotify.com 1,688 users
-
#18
twitch.tv 1,652 users
-
#19
riotgames.com 1,603 users
-
#20
epicgames.com 1,563 users
-
#21
com.roblox.client 1,510 users
-
#22
linkedin.com 1,457 users
-
#23
192.168.1.1 1,411 users
-
#24
mega.nz 1,402 users
-
#25
com.discord 1,307 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 44 employees
-
#2
hostinger.com 36 employees
-
#3
firstmail.ltd 34 employees
-
#4
rediff.com 31 employees
-
#5
wp.pl 28 employees
-
#6
secureserver.net 23 employees
-
#7
163.com 23 employees
-
#8
aruba.it 20 employees
-
#9
secop.gov.co 16 employees
-
#10
unionbankonline.co.in 15 employees
-
#11
santander.com.br 15 employees
-
#12
deped.gov.ph 15 employees
-
#13
yandex.com.tr 14 employees
-
#14
icai.org 13 employees
-
#15
digimail.in 13 employees
-
#16
bluehost.com 12 employees
-
#17
indusind.com 12 employees
-
#18
netpnb.com 12 employees
-
#19
interia.pl 12 employees
-
#20
sts.net.pk 12 employees
-
#21
o2.pl 12 employees
-
#22
naver.com 12 employees
-
#23
bobibanking.com 12 employees
-
#24
tim.it 11 employees
-
#25
mail.tm 11 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 4 employees
-
#2
apple.com 2 employees
-
#3
cisco.com 2 employees
-
#4
gm.com 2 employees
-
#5
cognizant.com 1 employees
-
#6
paypal.com 1 employees
-
#7
oracle.com 1 employees
-
#8
jacobs.com 1 employees
-
#9
salesforce.com 1 employees
-
#10
ch2m.com 1 employees
-
#11
xerox.com 1 employees
Compromised users
-
#1
google.com 7,156 users
-
#2
facebook.com 5,923 users
-
#3
netflix.com 2,760 users
-
#4
amazon.com 2,207 users
-
#5
paypal.com 1,900 users
-
#6
apple.com 1,763 users
-
#7
ebay.com 300 users
-
#8
hp.com 258 users
-
#9
microsoft.com 239 users
-
#10
oracle.com 237 users
-
#11
nike.com 201 users
-
#12
cisco.com 185 users
-
#13
walmart.com 74 users
-
#14
westernunion.com 66 users
-
#15
ups.com 64 users
-
#16
intel.com 61 users
-
#17
ibm.com 59 users
-
#18
fedex.com 49 users
-
#19
adp.com 39 users
-
#20
salesforce.com 38 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
2,984 users
2,061 users
Netflix
1,907 users
Roblox
1,510 users
Discord
1,307 users
Spotify
1,179 users
Twitch
948 users
903 users
901 users
Snapchat
880 users
PayPal
566 users
Wish
489 users
Zoom
428 users
Disney
418 users
417 users
Mega
413 users
Xiaomi
365 users
Waze
280 users
Mercadolibre
278 users
Alibaba
250 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 297,063 users
-
#2
hotmail.com 34,504 users
-
#3
yahoo.com 13,103 users
-
#4
outlook.com 7,545 users
-
#5
icloud.com 2,211 users
-
#6
live.com 1,127 users
-
#7
hotmail.fr 1,070 users
-
#8
yahoo.fr 919 users
-
#9
mail.ru 836 users
-
#10
yahoo.com.br 624 users
-
#11
ymail.com 540 users
-
#12
yahoo.co.id 496 users
-
#13
orange.fr 460 users
-
#14
mail.com 448 users
-
#15
aol.com 442 users
-
#16
hotmail.es 437 users
-
#17
hotmail.co.uk 359 users
-
#18
googlemail.com 355 users
-
#19
live.fr 318 users
-
#20
yahoo.ca 315 users
-
#21
gmx.de 310 users
-
#22
protonmail.com 306 users
-
#23
yahoo.co.in 296 users
-
#24
msn.com 288 users
-
#25
live.co.uk 250 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 5,148machines
- #2 RedLine 2,943machines
- #3 Generic Stealer 1,319machines
- #4 StealC 1,115machines
Anti-virus Coverage
- #1 Windows Defender 6,496machines
- #2 Windows Defender [ON] 538machines
- #3 Reason Cybersecurity 387machines
- #4 None 214machines
- #5 360 Total Security 183machines
- #6 Avast Antivirus 83machines
- #7 McAfee 56machines
- #8 Unknown 51machines
- #9 ESET Security 45machines
- #10 Quick Heal Total Security 41machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 30,920hits
- #2 sso 9,653hits
- #3 zoom 2,406hits
- #4 github 1,699hits
- #5 webmail 989hits
- #6 adfs 763hits
- #7 oracle 513hits
- #8 sap 452hits
- #9 zendesk 421hits
- #10 owa 388hits
- #11 vpn 321hits
- #12 cpanel 314hits
- #13 ping 289hits
- #14 sts 289hits
- #15 salesforce 189hits
- #16 webex 173hits
- #17 ftp 159hits
- #18 st 154hits
- #19 kaspersky 152hits
- #20 imap 132hits
- #21 roundcube 124hits
- #22 extranet 115hits
- #23 okta 112hits
- #24 twilio 94hits
- #25 gitlab 46hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.