Infostealers Weekly Report: 2024-11-18 – 2024-11-25
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 296
- #2 India 170
- #3 Egypt 123
- #4 Indonesia 122
- #5 Vietnam 108
- #6 Philippines 98
- #7 Argentina 79
- #8 Thailand 47
- #9 South Africa 43
- #10 Romania 40
- #11 Pakistan 33
- #12 Malaysia 32
- #13 Algeria 27
- #14 Bangladesh 27
- #15 Turkey 26
- #16 Mexico 26
- #17 Colombia 25
- #18 South Korea 25
- #19 Chile 20
- #20 Kenya 17
- #21 Sri Lanka 16
- #22 Morocco 15
- #23 Serbia 15
- #24 Peru 14
- #25 Nigeria 14
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,832 users
-
#2
facebook.com 1,588 users
-
#3
live.com 1,405 users
-
#4
instagram.com 867 users
-
#5
com.facebook.katana 827 users
-
#6
discord.com 803 users
-
#7
netflix.com 729 users
-
#8
roblox.com 711 users
-
#9
com.instagram.android 574 users
-
#10
amazon.com 553 users
-
#11
steampowered.com 538 users
-
#12
com.netflix.mediaclient 536 users
-
#13
twitter.com 500 users
-
#14
spotify.com 452 users
-
#15
paypal.com 445 users
-
#16
microsoftonline.com 444 users
-
#17
apple.com 443 users
-
#18
192.168.1.1 397 users
-
#19
mega.nz 395 users
-
#20
linkedin.com 392 users
-
#21
com.roblox.client 385 users
-
#22
twitch.tv 376 users
-
#23
riotgames.com 354 users
-
#24
com.spotify.music 348 users
-
#25
com.discord 344 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 20 employees
-
#2
hostinger.com 20 employees
-
#3
santander.com.br 18 employees
-
#4
login.sp.gov.br 13 employees
-
#5
rediff.com 9 employees
-
#6
sempreser.com.br 8 employees
-
#7
buenosaires.gob.ar 8 employees
-
#8
firstmail.ltd 7 employees
-
#9
indusind.com 6 employees
-
#10
skole.hr 6 employees
-
#11
abv.bg 6 employees
-
#12
bcb.gov.br 6 employees
-
#13
pnbibanking.in 6 employees
-
#14
concentrix.com 6 employees
-
#15
deped.gov.ph 6 employees
-
#16
watchit.com 6 employees
-
#17
atlassian.com 5 employees
-
#18
mail.gov.in 5 employees
-
#19
kinghost.com.br 5 employees
-
#20
correo.com.uy 5 employees
-
#21
microsoft.com 4 employees
-
#22
carnet.hr 4 employees
-
#23
buc.edu.eg 4 employees
-
#24
banquemisr.com 4 employees
-
#25
slimfemmeoficial.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 4 employees
-
#2
rockwellautomation.com 2 employees
-
#3
ibm.com 1 employees
Compromised users
-
#1
google.com 1,832 users
-
#2
facebook.com 1,588 users
-
#3
netflix.com 729 users
-
#4
amazon.com 553 users
-
#5
paypal.com 445 users
-
#6
apple.com 443 users
-
#7
ebay.com 68 users
-
#8
hp.com 64 users
-
#9
oracle.com 55 users
-
#10
nike.com 54 users
-
#11
microsoft.com 47 users
-
#12
cisco.com 34 users
-
#13
ibm.com 29 users
-
#14
westernunion.com 26 users
-
#15
ups.com 16 users
-
#16
fedex.com 12 users
-
#17
intel.com 12 users
-
#18
walmart.com 12 users
-
#19
visa.com 7 users
-
#20
salesforce.com 7 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
827 users
574 users
Netflix
536 users
Roblox
385 users
Spotify
348 users
Discord
344 users
310 users
250 users
Twitch
232 users
Snapchat
189 users
Wish
188 users
Mercadolibre
162 users
PayPal
158 users
Zoom
129 users
Disney
112 users
Waze
106 users
105 users
Mega
100 users
Alibaba
89 users
Xiaomi
88 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 74,606 users
-
#2
hotmail.com 9,953 users
-
#3
yahoo.com 2,694 users
-
#4
outlook.com 2,510 users
-
#5
yahoo.com.ar 467 users
-
#6
icloud.com 338 users
-
#7
terra.com.br 327 users
-
#8
live.com 296 users
-
#9
yahoo.com.br 262 users
-
#10
yahoo.co.id 183 users
-
#11
yahoo.co.in 146 users
-
#12
hotmail.com.br 130 users
-
#13
yandex.com 114 users
-
#14
outlook.com.br 104 users
-
#15
yahoo.fr 96 users
-
#16
protonmail.com 92 users
-
#17
email.com 91 users
-
#18
ymail.com 84 users
-
#19
yahoo.co.jp 74 users
-
#20
msn.com 71 users
-
#21
hotmail.fr 65 users
-
#22
mail.com 59 users
-
#23
me.com 49 users
-
#24
hotmail.com.ar 48 users
-
#25
live.com.ar 35 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 1,824machines
- #2 StealC 628machines
- #3 Generic Stealer 458machines
- #4 DarkCrystal 1machines
Anti-virus Coverage
- #1 Windows Defender 735machines
- #2 Windows Defender [ON] 512machines
- #3 None 105machines
- #4 Reason Cybersecurity 96machines
- #5 360 Total Security 20machines
- #6 Quick Heal Total Security 11machines
- #7 Quick Heal AntiVirus Pro 9machines
- #8 알약 8machines
- #9 Avast Antivirus 6machines
- #10 Reason Cybersecurity [OFF] 5machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 7,656hits
- #2 sso 2,232hits
- #3 zoom 550hits
- #4 github 358hits
- #5 adfs 304hits
- #6 webmail 274hits
- #7 zendesk 131hits
- #8 oracle 126hits
- #9 owa 125hits
- #10 sap 120hits
- #11 vpn 95hits
- #12 cpanel 78hits
- #13 ping 66hits
- #14 kaspersky 52hits
- #15 sts 42hits
- #16 st 33hits
- #17 webex 31hits
- #18 ftp 31hits
- #19 extranet 28hits
- #20 imap 21hits
- #21 jira 16hits
- #22 salesforce 15hits
- #23 okta 13hits
- #24 roundcube 12hits
- #25 gitlab 11hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.