Infostealers Weekly Report: 2025-02-17 – 2025-02-24
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 355
- #2 Brazil 232
- #3 Indonesia 189
- #4 Vietnam 182
- #5 Argentina 145
- #6 Thailand 133
- #7 Pakistan 114
- #8 Egypt 110
- #9 Turkey 104
- #10 Mexico 102
- #11 Philippines 89
- #12 Peru 81
- #13 South Korea 58
- #14 Colombia 54
- #15 Morocco 46
- #16 Bangladesh 44
- #17 Chile 43
- #18 Romania 41
- #19 South Africa 36
- #20 Algeria 34
- #21 Dominican Republic 29
- #22 Taiwan 27
- #23 Kenya 26
- #24 Malaysia 26
- #25 Portugal 25
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,523 users
-
#2
facebook.com 2,163 users
-
#3
live.com 1,840 users
-
#4
instagram.com 1,183 users
-
#5
com.facebook.katana 1,112 users
-
#6
netflix.com 1,001 users
-
#7
discord.com 932 users
-
#8
com.instagram.android 789 users
-
#9
amazon.com 778 users
-
#10
com.netflix.mediaclient 755 users
-
#11
roblox.com 744 users
-
#12
steampowered.com 681 users
-
#13
apple.com 646 users
-
#14
twitter.com 644 users
-
#15
paypal.com 642 users
-
#16
microsoftonline.com 608 users
-
#17
spotify.com 567 users
-
#18
mega.nz 559 users
-
#19
linkedin.com 504 users
-
#20
192.168.1.1 502 users
-
#21
twitch.tv 493 users
-
#22
com.spotify.music 489 users
-
#23
com.pinterest 481 users
-
#24
riotgames.com 460 users
-
#25
com.roblox.client 459 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 21 employees
-
#2
icicibank.com 17 employees
-
#3
rediff.com 14 employees
-
#4
santander.com.br 11 employees
-
#5
payoneer.com 10 employees
-
#6
naver.com 10 employees
-
#7
firstmail.ltd 8 employees
-
#8
buenosaires.gob.ar 8 employees
-
#9
bobibanking.com 7 employees
-
#10
secureserver.net 6 employees
-
#11
sapo.pt 6 employees
-
#12
sts.net.pk 6 employees
-
#13
telecom.pt 6 employees
-
#14
digimail.in 6 employees
-
#15
indusind.com 6 employees
-
#16
justhost.com 6 employees
-
#17
comprasdominicana.gob.do 6 employees
-
#18
kemenag.go.id 6 employees
-
#19
sempreser.com.br 6 employees
-
#20
nate.com 5 employees
-
#21
unionbankonline.co.in 5 employees
-
#22
accenture.com 5 employees
-
#23
login.sp.gov.br 4 employees
-
#24
kivumafamille.net 4 employees
-
#25
atlassian.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
ibm.com 3 employees
-
#2
att.com 2 employees
-
#3
hp.com 1 employees
-
#4
ti.com 1 employees
-
#5
microsoft.com 1 employees
-
#6
netflix.com 1 employees
-
#7
jll.com 1 employees
-
#8
jacobs.com 1 employees
Compromised users
-
#1
google.com 2,523 users
-
#2
facebook.com 2,163 users
-
#3
netflix.com 1,001 users
-
#4
amazon.com 778 users
-
#5
apple.com 646 users
-
#6
paypal.com 642 users
-
#7
ebay.com 118 users
-
#8
hp.com 94 users
-
#9
oracle.com 92 users
-
#10
microsoft.com 90 users
-
#11
nike.com 62 users
-
#12
cisco.com 53 users
-
#13
ibm.com 30 users
-
#14
westernunion.com 26 users
-
#15
salesforce.com 18 users
-
#16
intel.com 16 users
-
#17
ups.com 15 users
-
#18
walmart.com 14 users
-
#19
fedex.com 10 users
-
#20
adp.com 9 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,112 users
789 users
Netflix
755 users
Spotify
489 users
481 users
Roblox
459 users
Discord
431 users
357 users
Twitch
314 users
Snapchat
305 users
Wish
250 users
PayPal
207 users
Mega
189 users
Mercadolibre
188 users
Zoom
182 users
Disney
181 users
144 users
Xiaomi
119 users
Alibaba
117 users
Waze
116 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 106,656 users
-
#2
hotmail.com 11,808 users
-
#3
yahoo.com 3,247 users
-
#4
outlook.com 2,726 users
-
#5
live.com 692 users
-
#6
icloud.com 519 users
-
#7
yahoo.com.br 438 users
-
#8
yahoo.co.id 203 users
-
#9
prodigy.net.mx 171 users
-
#10
yahoo.com.ar 155 users
-
#11
hanmail.net 144 users
-
#12
hotmail.es 131 users
-
#13
yahoo.fr 120 users
-
#14
outlook.com.br 112 users
-
#15
googlemail.com 100 users
-
#16
proton.me 93 users
-
#17
me.com 84 users
-
#18
live.com.ar 79 users
-
#19
hotmail.fr 71 users
-
#20
msn.com 66 users
-
#21
hotmail.com.br 64 users
-
#22
mail.com 59 users
-
#23
foxmail.com 57 users
-
#24
ymail.com 55 users
-
#25
terra.com.br 53 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 2,922machines
- #2 Generic Stealer 649machines
- #3 StealC 183machines
Anti-virus Coverage
- #1 Windows Defender 2,086machines
- #2 Windows Defender [ON] 286machines
- #3 None 146machines
- #4 Reason Cybersecurity 141machines
- #5 Reason Cybersecurity [OFF] 9machines
- #6 ESET Security 7machines
- #7 Quick Heal AntiVirus Pro 6machines
- #8 Panda Dome 6machines
- #9 Malwarebytes [OFF] 6machines
- #10 Quick Heal Total Security 6machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 11,419hits
- #2 sso 3,238hits
- #3 zoom 883hits
- #4 github 606hits
- #5 webmail 302hits
- #6 oracle 199hits
- #7 adfs 175hits
- #8 zendesk 153hits
- #9 cpanel 131hits
- #10 sap 128hits
- #11 vpn 126hits
- #12 owa 109hits
- #13 ping 96hits
- #14 extranet 93hits
- #15 kaspersky 87hits
- #16 sts 82hits
- #17 salesforce 66hits
- #18 roundcube 58hits
- #19 ftp 47hits
- #20 webex 46hits
- #21 st 43hits
- #22 okta 22hits
- #23 twilio 22hits
- #24 imap 21hits
- #25 gitlab 20hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.