Infostealers Weekly Report: 2025-01-20 – 2025-01-27
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 261
- #2 Brazil 187
- #3 Vietnam 165
- #4 Indonesia 161
- #5 Pakistan 110
- #6 Turkey 104
- #7 Philippines 103
- #8 Egypt 70
- #9 United States of America 65
- #10 Argentina 64
- #11 Bangladesh 57
- #12 Germany 43
- #13 Thailand 40
- #14 South Africa 39
- #15 Portugal 37
- #16 France 37
- #17 Serbia 33
- #18 South Korea 32
- #19 Romania 32
- #20 Morocco 31
- #21 Poland 28
- #22 Italy 28
- #23 Mexico 27
- #24 United Kingdom 26
- #25 Malaysia 26
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,521 users
-
#2
facebook.com 2,041 users
-
#3
live.com 1,781 users
-
#4
discord.com 1,175 users
-
#5
instagram.com 1,140 users
-
#6
roblox.com 1,088 users
-
#7
com.facebook.katana 1,044 users
-
#8
netflix.com 983 users
-
#9
steampowered.com 746 users
-
#10
com.instagram.android 732 users
-
#11
amazon.com 703 users
-
#12
com.netflix.mediaclient 694 users
-
#13
spotify.com 648 users
-
#14
paypal.com 624 users
-
#15
twitter.com 621 users
-
#16
epicgames.com 610 users
-
#17
twitch.tv 574 users
-
#18
apple.com 568 users
-
#19
riotgames.com 551 users
-
#20
com.roblox.client 542 users
-
#21
microsoftonline.com 533 users
-
#22
steamcommunity.com 496 users
-
#23
com.pinterest 485 users
-
#24
192.168.1.1 485 users
-
#25
mega.nz 479 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 17 employees
-
#2
hostinger.com 16 employees
-
#3
firstmail.ltd 16 employees
-
#4
buenosaires.gob.ar 9 employees
-
#5
bobibanking.com 9 employees
-
#6
rediff.com 9 employees
-
#7
163.com 9 employees
-
#8
icai.org 8 employees
-
#9
concentrix.com 8 employees
-
#10
sts.net.pk 7 employees
-
#11
qq.com 7 employees
-
#12
isacombank.com.vn 6 employees
-
#13
bestmergeltd.co.ke 5 employees
-
#14
testversalis.net 5 employees
-
#15
pakizaknit.com 5 employees
-
#16
mail.tm 5 employees
-
#17
netpnb.com 5 employees
-
#18
zukufiber.com 5 employees
-
#19
kpu.go.id 5 employees
-
#20
secureserver.net 5 employees
-
#21
zsthost.com 5 employees
-
#22
52you.in 5 employees
-
#23
aruba.it 5 employees
-
#24
cepa.co.ke 5 employees
-
#25
deped.gov.ph 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
spglobal.com 2 employees
-
#2
emerson.com 2 employees
-
#3
cisco.com 2 employees
-
#4
facebook.com 1 employees
-
#5
gm.com 1 employees
-
#6
harman.com 1 employees
-
#7
rockwellautomation.com 1 employees
-
#8
lear.com 1 employees
Compromised users
-
#1
google.com 2,521 users
-
#2
facebook.com 2,041 users
-
#3
netflix.com 983 users
-
#4
amazon.com 703 users
-
#5
paypal.com 624 users
-
#6
apple.com 568 users
-
#7
ebay.com 97 users
-
#8
nike.com 74 users
-
#9
microsoft.com 72 users
-
#10
hp.com 68 users
-
#11
oracle.com 61 users
-
#12
cisco.com 40 users
-
#13
ibm.com 31 users
-
#14
westernunion.com 24 users
-
#15
walmart.com 20 users
-
#16
intel.com 19 users
-
#17
americanexpress.com 17 users
-
#18
salesforce.com 16 users
-
#19
broadcom.com 12 users
-
#20
ups.com 11 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,044 users
732 users
Netflix
694 users
Roblox
542 users
485 users
Discord
456 users
Spotify
444 users
Twitch
331 users
308 users
Snapchat
300 users
Wish
198 users
PayPal
158 users
Mega
156 users
Zoom
149 users
Disney
125 users
115 users
Xiaomi
114 users
Mercadolibre
98 users
Waze
90 users
Alibaba
85 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 104,667 users
-
#2
hotmail.com 8,366 users
-
#3
yahoo.com 4,647 users
-
#4
outlook.com 2,695 users
-
#5
live.com 1,148 users
-
#6
icloud.com 759 users
-
#7
ymail.com 364 users
-
#8
hotmail.fr 314 users
-
#9
email.com 198 users
-
#10
gmx.de 169 users
-
#11
yahoo.fr 169 users
-
#12
msn.com 160 users
-
#13
yahoo.co.id 142 users
-
#14
yahoo.com.br 118 users
-
#15
web.de 106 users
-
#16
mail.com 73 users
-
#17
yahoo.com.ar 49 users
-
#18
yahoo.com.sg 48 users
-
#19
hanmail.net 40 users
-
#20
yahoo.de 39 users
-
#21
proton.me 37 users
-
#22
facebook.com 36 users
-
#23
libero.it 36 users
-
#24
hotmail.com.ar 36 users
-
#25
aol.com 33 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 3,195machines
- #2 Generic Stealer 603machines
- #3 DarkCrystal 2machines
Anti-virus Coverage
- #1 Windows Defender 1,872machines
- #2 Windows Defender [ON] 372machines
- #3 None 163machines
- #4 Reason Cybersecurity 92machines
- #5 Avast Antivirus 11machines
- #6 Reason Cybersecurity [OFF] 10machines
- #7 Malwarebytes [OFF] 8machines
- #8 360 Total Security 8machines
- #9 Kaspersky Anti‑Virus [OFF] 7machines
- #10 ESET Security 7machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 10,335hits
- #2 sso 2,362hits
- #3 zoom 758hits
- #4 github 595hits
- #5 webmail 324hits
- #6 adfs 205hits
- #7 zendesk 144hits
- #8 sap 128hits
- #9 oracle 118hits
- #10 vpn 106hits
- #11 owa 100hits
- #12 sts 96hits
- #13 extranet 96hits
- #14 imap 71hits
- #15 cpanel 65hits
- #16 roundcube 63hits
- #17 ping 61hits
- #18 kaspersky 52hits
- #19 ftp 42hits
- #20 okta 41hits
- #21 st 35hits
- #22 webex 33hits
- #23 salesforce 28hits
- #24 dana-na 23hits
- #25 citrix 14hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.