Infostealers Weekly Report: 2025-06-09 – 2025-06-16
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,469
- #2 Brazil 1,250
- #3 Argentina 976
- #4 Egypt 851
- #5 Indonesia 823
- #6 Turkey 777
- #7 Vietnam 681
- #8 United States of America 649
- #9 Philippines 592
- #10 Spain 561
- #11 Thailand 528
- #12 France 468
- #13 Pakistan 467
- #14 Mexico 438
- #15 Germany 431
- #16 Colombia 360
- #17 Bangladesh 354
- #18 Algeria 307
- #19 Italy 290
- #20 Morocco 283
- #21 Peru 238
- #22 Poland 221
- #23 Chile 221
- #24 United Kingdom 218
- #25 Romania 179
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 15,096 users
-
#2
facebook.com 12,112 users
-
#3
live.com 11,361 users
-
#4
instagram.com 7,801 users
-
#5
discord.com 7,300 users
-
#6
com.facebook.katana 6,745 users
-
#7
netflix.com 6,460 users
-
#8
roblox.com 6,184 users
-
#9
amazon.com 5,306 users
-
#10
com.instagram.android 5,302 users
-
#11
steampowered.com 5,224 users
-
#12
com.netflix.mediaclient 4,721 users
-
#13
twitch.tv 4,361 users
-
#14
paypal.com 4,293 users
-
#15
microsoftonline.com 4,257 users
-
#16
spotify.com 4,176 users
-
#17
twitter.com 3,978 users
-
#18
epicgames.com 3,969 users
-
#19
riotgames.com 3,872 users
-
#20
apple.com 3,785 users
-
#21
com.roblox.client 3,772 users
-
#22
com.spotify.music 3,650 users
-
#23
com.discord 3,576 users
-
#24
com.pinterest 3,385 users
-
#25
steamcommunity.com 3,365 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 124 employees
-
#2
icicibank.com 121 employees
-
#3
firstmail.ltd 113 employees
-
#4
rediff.com 75 employees
-
#5
buenosaires.gob.ar 73 employees
-
#6
aruba.it 60 employees
-
#7
wp.pl 54 employees
-
#8
tim.it 39 employees
-
#9
bobibanking.com 38 employees
-
#10
mail.tm 35 employees
-
#11
pec.it 34 employees
-
#12
163.com 33 employees
-
#13
watchit.com 32 employees
-
#14
unionbankonline.co.in 24 employees
-
#15
qq.com 24 employees
-
#16
freemail.hu 24 employees
-
#17
zsthost.com 23 employees
-
#18
o2.pl 22 employees
-
#19
abv.bg 22 employees
-
#20
santander.com.br 21 employees
-
#21
atlassian.com 21 employees
-
#22
icai.org 21 employees
-
#23
accenture.com 21 employees
-
#24
digimail.in 20 employees
-
#25
fednetbank.com 20 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 15 employees
-
#2
publix.com 5 employees
-
#3
rockwellautomation.com 5 employees
-
#4
cognizant.com 4 employees
-
#5
lear.com 3 employees
-
#6
amazon.com 3 employees
-
#7
ibm.com 2 employees
-
#8
att.com 2 employees
-
#9
csc.com 2 employees
-
#10
hp.com 2 employees
-
#11
centene.com 2 employees
-
#12
ford.com 2 employees
-
#13
gapinc.com 2 employees
-
#14
salesforce.com 2 employees
-
#15
centurylink.com 1 employees
-
#16
bnymellon.com 1 employees
-
#17
morganstanley.com 1 employees
-
#18
emc.com 1 employees
-
#19
uhsinc.com 1 employees
-
#20
ups.com 1 employees
Compromised users
-
#1
google.com 15,096 users
-
#2
facebook.com 12,112 users
-
#3
netflix.com 6,460 users
-
#4
amazon.com 5,306 users
-
#5
paypal.com 4,293 users
-
#6
apple.com 3,785 users
-
#7
ebay.com 635 users
-
#8
oracle.com 611 users
-
#9
hp.com 598 users
-
#10
nike.com 575 users
-
#11
microsoft.com 497 users
-
#12
cisco.com 307 users
-
#13
ups.com 202 users
-
#14
walmart.com 202 users
-
#15
ibm.com 181 users
-
#16
westernunion.com 134 users
-
#17
fedex.com 110 users
-
#18
intel.com 109 users
-
#19
disney.com 106 users
-
#20
adp.com 103 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
6,745 users
5,302 users
Netflix
4,721 users
Roblox
3,772 users
Spotify
3,650 users
Discord
3,576 users
3,385 users
Twitch
2,775 users
Snapchat
2,231 users
2,164 users
Wish
1,582 users
PayPal
1,304 users
Disney
1,258 users
Mega
1,117 users
Zoom
1,032 users
886 users
Xiaomi
849 users
Mercadolibre
792 users
Alibaba
525 users
Waze
524 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 700,912 users
-
#2
hotmail.com 69,745 users
-
#3
yahoo.com 24,968 users
-
#4
outlook.com 16,406 users
-
#5
icloud.com 4,885 users
-
#6
live.com 2,992 users
-
#7
hotmail.fr 2,329 users
-
#8
libero.it 1,883 users
-
#9
yahoo.fr 1,645 users
-
#10
yahoo.com.br 1,601 users
-
#11
hotmail.es 1,570 users
-
#12
gmx.de 1,506 users
-
#13
web.de 1,454 users
-
#14
msn.com 1,341 users
-
#15
live.fr 1,297 users
-
#16
aol.com 1,051 users
-
#17
hotmail.it 1,029 users
-
#18
yahoo.com.ar 1,012 users
-
#19
yahoo.de 1,007 users
-
#20
hotmail.co.uk 940 users
-
#21
orange.fr 881 users
-
#22
ymail.com 864 users
-
#23
laposte.net 787 users
-
#24
mail.com 742 users
-
#25
googlemail.com 652 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 16,186machines
- #2 Generic Stealer 6,591machines
- #3 Vidar 176machines
Anti-virus Coverage
- #1 Windows Defender 9,370machines
- #2 Windows Defender [ON] 1,012machines
- #3 Reason Cybersecurity 740machines
- #4 None 408machines
- #5 Disabled 176machines
- #6 ESET Security 39machines
- #7 Kaspersky 33machines
- #8 Malwarebytes [OFF] 31machines
- #9 Quick Heal Total Security 30machines
- #10 Avast Antivirus 22machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 74,262hits
- #2 sso 19,610hits
- #3 zoom 5,142hits
- #4 github 4,725hits
- #5 webmail 2,460hits
- #6 adfs 1,851hits
- #7 oracle 1,507hits
- #8 zendesk 960hits
- #9 vpn 872hits
- #10 sap 778hits
- #11 sts 755hits
- #12 owa 752hits
- #13 ping 558hits
- #14 cpanel 539hits
- #15 imap 457hits
- #16 salesforce 410hits
- #17 kaspersky 359hits
- #18 okta 345hits
- #19 webex 343hits
- #20 extranet 302hits
- #21 st 301hits
- #22 roundcube 252hits
- #23 ftp 247hits
- #24 citrix 209hits
- #25 twilio 203hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.