Infostealers Weekly Report: 2025-06-23 – 2025-06-30
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,878
- #2 Brazil 614
- #3 Indonesia 465
- #4 Turkey 397
- #5 United States of America 354
- #6 Vietnam 352
- #7 Mexico 313
- #8 Philippines 252
- #9 France 249
- #10 Egypt 226
- #11 Pakistan 212
- #12 Argentina 197
- #13 Thailand 196
- #14 Bangladesh 183
- #15 Spain 173
- #16 United Kingdom 165
- #17 Italy 158
- #18 Germany 144
- #19 Colombia 136
- #20 South Africa 128
- #21 Canada 115
- #22 Portugal 115
- #23 Kenya 111
- #24 Algeria 109
- #25 Sri Lanka 101
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 9,009 users
-
#2
facebook.com 7,228 users
-
#3
live.com 6,643 users
-
#4
instagram.com 4,581 users
-
#5
netflix.com 4,103 users
-
#6
com.facebook.katana 3,918 users
-
#7
discord.com 3,801 users
-
#8
amazon.com 3,501 users
-
#9
com.instagram.android 3,129 users
-
#10
roblox.com 3,083 users
-
#11
paypal.com 2,802 users
-
#12
com.netflix.mediaclient 2,798 users
-
#13
steampowered.com 2,746 users
-
#14
twitter.com 2,623 users
-
#15
apple.com 2,473 users
-
#16
twitch.tv 2,379 users
-
#17
microsoftonline.com 2,191 users
-
#18
epicgames.com 2,120 users
-
#19
linkedin.com 2,026 users
-
#20
com.pinterest 2,025 users
-
#21
spotify.com 2,015 users
-
#22
com.roblox.client 1,909 users
-
#23
riotgames.com 1,903 users
-
#24
github.com 1,856 users
-
#25
com.discord 1,855 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 85 employees
-
#2
hostinger.com 68 employees
-
#3
rediff.com 61 employees
-
#4
aruba.it 60 employees
-
#5
tim.it 41 employees
-
#6
firstmail.ltd 37 employees
-
#7
pec.it 33 employees
-
#8
icai.org 32 employees
-
#9
bobibanking.com 27 employees
-
#10
atlassian.com 23 employees
-
#11
confused.com 23 employees
-
#12
wp.pl 20 employees
-
#13
sapo.pt 18 employees
-
#14
indusind.com 18 employees
-
#15
mail.tm 18 employees
-
#16
unionbankonline.co.in 16 employees
-
#17
accenture.com 16 employees
-
#18
buenosaires.gob.ar 16 employees
-
#19
netpnb.com 16 employees
-
#20
163.com 15 employees
-
#21
secureserver.net 15 employees
-
#22
payoneer.com 14 employees
-
#23
njoyn.com 13 employees
-
#24
sep.gob.mx 13 employees
-
#25
santander.com.br 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 4 employees
-
#2
cisco.com 4 employees
-
#3
apple.com 3 employees
-
#4
publix.com 3 employees
-
#5
ford.com 2 employees
-
#6
nov.com 2 employees
-
#7
ups.com 2 employees
-
#8
cummins.com 2 employees
-
#9
hp.com 2 employees
-
#10
twc.com 2 employees
-
#11
ibm.com 1 employees
-
#12
cbrands.com 1 employees
-
#13
cognizant.com 1 employees
-
#14
gm.com 1 employees
-
#15
fedex.com 1 employees
-
#16
essendant.com 1 employees
-
#17
pepsico.com 1 employees
-
#18
disney.com 1 employees
-
#19
textron.com 1 employees
-
#20
netflix.com 1 employees
Compromised users
-
#1
google.com 9,009 users
-
#2
facebook.com 7,228 users
-
#3
netflix.com 4,103 users
-
#4
amazon.com 3,501 users
-
#5
paypal.com 2,802 users
-
#6
apple.com 2,473 users
-
#7
ebay.com 544 users
-
#8
hp.com 441 users
-
#9
oracle.com 430 users
-
#10
nike.com 401 users
-
#11
microsoft.com 275 users
-
#12
cisco.com 259 users
-
#13
ups.com 222 users
-
#14
walmart.com 189 users
-
#15
ibm.com 138 users
-
#16
westernunion.com 111 users
-
#17
fedex.com 102 users
-
#18
adp.com 89 users
-
#19
salesforce.com 84 users
-
#20
bestbuy.com 80 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
3,918 users
3,129 users
Netflix
2,798 users
2,025 users
Roblox
1,909 users
Discord
1,855 users
Spotify
1,779 users
Twitch
1,414 users
Snapchat
1,341 users
1,209 users
Wish
1,062 users
PayPal
805 users
Disney
743 users
Zoom
682 users
632 users
Mega
601 users
Xiaomi
486 users
Mercadolibre
408 users
Alibaba
404 users
Waze
386 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 467,539 users
-
#2
hotmail.com 51,468 users
-
#3
yahoo.com 18,093 users
-
#4
outlook.com 11,676 users
-
#5
hotmail.fr 4,643 users
-
#6
live.com 3,555 users
-
#7
icloud.com 3,159 users
-
#8
libero.it 2,956 users
-
#9
hotmail.it 2,580 users
-
#10
yahoo.fr 1,896 users
-
#11
googlemail.com 1,782 users
-
#12
orange.fr 1,642 users
-
#13
free.fr 1,369 users
-
#14
yahoo.com.br 1,301 users
-
#15
live.fr 1,244 users
-
#16
hotmail.co.uk 1,243 users
-
#17
aol.com 1,170 users
-
#18
live.it 1,065 users
-
#19
ymail.com 1,040 users
-
#20
yahoo.it 1,000 users
-
#21
web.de 956 users
-
#22
outlook.com.br 929 users
-
#23
mail.com 738 users
-
#24
msn.com 735 users
-
#25
alice.it 717 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 10,587machines
- #2 Generic Stealer 2,854machines
Anti-virus Coverage
- #1 Windows Defender 6,527machines
- #2 Windows Defender [ON] 1,509machines
- #3 Reason Cybersecurity 506machines
- #4 None 323machines
- #5 153machines
- #6 126machines
- #7 Quick Heal Total Security 33machines
- #8 Malwarebytes [OFF] 26machines
- #9 Bkav Pro Internet Security 24machines
- #10 Kaspersky 21machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 48,138hits
- #2 sso 14,561hits
- #3 zoom 3,384hits
- #4 github 2,942hits
- #5 webmail 1,248hits
- #6 adfs 1,093hits
- #7 oracle 888hits
- #8 zendesk 736hits
- #9 sap 705hits
- #10 ping 521hits
- #11 vpn 514hits
- #12 imap 459hits
- #13 sts 436hits
- #14 cpanel 425hits
- #15 owa 380hits
- #16 salesforce 339hits
- #17 kaspersky 272hits
- #18 extranet 261hits
- #19 ftp 225hits
- #20 st 222hits
- #21 webex 193hits
- #22 okta 165hits
- #23 roundcube 164hits
- #24 gitlab 120hits
- #25 twilio 84hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.