Infostealers Weekly Report: 2025-06-16 – 2025-06-23
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,029
- #2 Indonesia 928
- #3 Brazil 913
- #4 Philippines 482
- #5 United States of America 408
- #6 Vietnam 392
- #7 Pakistan 268
- #8 Turkey 255
- #9 France 250
- #10 Argentina 239
- #11 Thailand 214
- #12 Germany 213
- #13 Mexico 209
- #14 Egypt 207
- #15 Bangladesh 194
- #16 Poland 167
- #17 Colombia 159
- #18 South Africa 158
- #19 Spain 153
- #20 United Kingdom 136
- #21 Morocco 132
- #22 Romania 125
- #23 Italy 121
- #24 Algeria 120
- #25 Peru 116
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 8,078 users
-
#2
facebook.com 6,839 users
-
#3
live.com 6,121 users
-
#4
instagram.com 4,392 users
-
#5
discord.com 4,076 users
-
#6
netflix.com 3,727 users
-
#7
com.facebook.katana 3,619 users
-
#8
roblox.com 3,253 users
-
#9
amazon.com 2,969 users
-
#10
steampowered.com 2,856 users
-
#11
com.instagram.android 2,793 users
-
#12
paypal.com 2,624 users
-
#13
twitch.tv 2,423 users
-
#14
com.netflix.mediaclient 2,408 users
-
#15
microsoftonline.com 2,389 users
-
#16
twitter.com 2,382 users
-
#17
spotify.com 2,361 users
-
#18
apple.com 2,329 users
-
#19
riotgames.com 2,157 users
-
#20
epicgames.com 2,108 users
-
#21
steamcommunity.com 1,932 users
-
#22
com.roblox.client 1,899 users
-
#23
com.discord 1,876 users
-
#24
com.spotify.music 1,831 users
-
#25
github.com 1,793 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 68 employees
-
#2
firstmail.ltd 66 employees
-
#3
icicibank.com 54 employees
-
#4
rediff.com 39 employees
-
#5
wp.pl 35 employees
-
#6
163.com 25 employees
-
#7
buenosaires.gob.ar 25 employees
-
#8
bni.co.id 22 employees
-
#9
watchit.com 20 employees
-
#10
santander.com.br 19 employees
-
#11
bobibanking.com 18 employees
-
#12
mail.tm 17 employees
-
#13
alxswe.com 17 employees
-
#14
aruba.it 16 employees
-
#15
interia.pl 16 employees
-
#16
abv.bg 15 employees
-
#17
accenture.com 15 employees
-
#18
concentrix.com 15 employees
-
#19
sempreser.com.br 15 employees
-
#20
onet.pl 15 employees
-
#21
zsthost.com 14 employees
-
#22
tim.it 14 employees
-
#23
netpnb.com 13 employees
-
#24
bluehost.com 13 employees
-
#25
qq.com 13 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 12 employees
-
#2
oracle.com 4 employees
-
#3
cbre.com 2 employees
-
#4
publix.com 2 employees
-
#5
ups.com 2 employees
-
#6
amazon.com 2 employees
-
#7
rockwellautomation.com 2 employees
-
#8
google.com 2 employees
-
#9
hp.com 2 employees
-
#10
jpmorganchase.com 2 employees
-
#11
ibm.com 2 employees
-
#12
fedex.com 1 employees
-
#13
jnj.com 1 employees
-
#14
nov.com 1 employees
-
#15
essendant.com 1 employees
-
#16
pepsico.com 1 employees
-
#17
ball.com 1 employees
-
#18
visteon.com 1 employees
-
#19
cognizant.com 1 employees
-
#20
honeywell.com 1 employees
Compromised users
-
#1
google.com 8,078 users
-
#2
facebook.com 6,839 users
-
#3
netflix.com 3,727 users
-
#4
amazon.com 2,969 users
-
#5
paypal.com 2,624 users
-
#6
apple.com 2,329 users
-
#7
ebay.com 433 users
-
#8
nike.com 385 users
-
#9
oracle.com 383 users
-
#10
hp.com 342 users
-
#11
microsoft.com 293 users
-
#12
cisco.com 221 users
-
#13
walmart.com 131 users
-
#14
ups.com 129 users
-
#15
ibm.com 127 users
-
#16
westernunion.com 82 users
-
#17
bestbuy.com 79 users
-
#18
broadcom.com 73 users
-
#19
intel.com 70 users
-
#20
adp.com 68 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
3,619 users
2,793 users
Netflix
2,408 users
Roblox
1,899 users
Discord
1,876 users
Spotify
1,831 users
1,660 users
Twitch
1,368 users
1,228 users
Snapchat
1,130 users
PayPal
800 users
Wish
748 users
Zoom
577 users
Mega
538 users
Disney
527 users
490 users
Xiaomi
437 users
Waze
359 users
Mercadolibre
347 users
Alibaba
329 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 434,269 users
-
#2
hotmail.com 36,864 users
-
#3
yahoo.com 17,757 users
-
#4
outlook.com 10,605 users
-
#5
icloud.com 3,997 users
-
#6
hotmail.fr 1,716 users
-
#7
live.com 1,688 users
-
#8
web.de 1,054 users
-
#9
free.fr 989 users
-
#10
gmx.de 957 users
-
#11
yahoo.com.br 919 users
-
#12
libero.it 898 users
-
#13
aol.com 891 users
-
#14
yahoo.fr 864 users
-
#15
msn.com 811 users
-
#16
yahoo.co.id 773 users
-
#17
live.fr 769 users
-
#18
orange.fr 730 users
-
#19
ymail.com 683 users
-
#20
hotmail.co.uk 556 users
-
#21
hotmail.it 529 users
-
#22
yahoo.de 463 users
-
#23
hotmail.es 441 users
-
#24
googlemail.com 436 users
-
#25
yandex.com 412 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 10,474machines
- #2 Generic Stealer 1,379machines
Anti-virus Coverage
- #1 Windows Defender 3,565machines
- #2 Windows Defender [ON] 490machines
- #3 Reason Cybersecurity 307machines
- #4 None 240machines
- #5 Kaspersky 24machines
- #6 ESET Security 18machines
- #7 Malwarebytes [OFF] 17machines
- #8 360 Total Security 10machines
- #9 Kaspersky [OFF] 9machines
- #10 Norton Security Ultra [OFF] 6machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 47,616hits
- #2 sso 11,935hits
- #3 zoom 3,030hits
- #4 github 2,816hits
- #5 webmail 1,586hits
- #6 adfs 1,211hits
- #7 oracle 836hits
- #8 zendesk 687hits
- #9 sap 621hits
- #10 vpn 558hits
- #11 cpanel 487hits
- #12 ping 463hits
- #13 owa 439hits
- #14 sts 421hits
- #15 webex 297hits
- #16 roundcube 258hits
- #17 kaspersky 235hits
- #18 extranet 233hits
- #19 okta 218hits
- #20 imap 192hits
- #21 st 187hits
- #22 ftp 164hits
- #23 salesforce 159hits
- #24 twilio 136hits
- #25 gitlab 123hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.