Skip to content
Weekly intelligence Jul 21 – Jul 28, 2025 11 min read

Infostealers Weekly Report: 2025-07-21 – 2025-07-28

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 5,175 Compromised Machines
#2 1,867 Compromised Employees
#3 900 Compromised Users
#4 2,408 Compromised Androids
#5 68,574 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 125
Infections by country

Top 25 countries

  1. #1 India 444
  2. #2 Brazil 192
  3. #3 France 188
  4. #4 United States of America 185
  5. #5 Indonesia 153
  6. #6 Spain 138
  7. #7 Japan 117
  8. #8 Vietnam 115
  9. #9 Turkey 93
  10. #10 Pakistan 84
  11. #11 Philippines 80
  12. #12 Poland 80
  13. #13 Egypt 51
  14. #14 Mexico 39
  15. #15 Argentina 39
  16. #16 United Kingdom 37
  17. #17 Bangladesh 36
  18. #18 Romania 36
  19. #19 South Africa 34
  20. #20 Thailand 34
  21. #21 Algeria 33
  22. #22 Kenya 31
  23. #23 Morocco 30
  24. #24 Nepal 27
  25. #25 Serbia 23

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 3,642 users
  2. #2 facebook.com 2,565 users
  3. #3 live.com 2,094 users
  4. #4 instagram.com 1,635 users
  5. #5 netflix.com 1,568 users
  6. #6 microsoftonline.com 1,340 users
  7. #7 discord.com 1,312 users
  8. #8 com.facebook.katana 1,231 users
  9. #9 amazon.com 1,110 users
  10. #10 linkedin.com 1,036 users
  11. #11 roblox.com 1,017 users
  12. #12 com.instagram.android 999 users
  13. #13 twitter.com 977 users
  14. #14 zoom.us 918 users
  15. #15 spotify.com 863 users
  16. #16 steampowered.com 855 users
  17. #17 paypal.com 840 users
  18. #18 com.netflix.mediaclient 805 users
  19. #19 apple.com 789 users
  20. #20 github.com 708 users
  21. #21 slack.com 680 users
  22. #22 epicgames.com 670 users
  23. #23 twitch.tv 669 users
  24. #24 com.pinterest 640 users
  25. #25 com.roblox.client 607 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 hostinger.com 33 employees
  2. #2 icicibank.com 28 employees
  3. #3 firstmail.ltd 20 employees
  4. #4 rediff.com 18 employees
  5. #5 secureserver.net 16 employees
  6. #6 office365.com 14 employees
  7. #7 unionbankonline.co.in 10 employees
  8. #8 aiou.edu.pk 10 employees
  9. #9 skillssurge.ai 9 employees
  10. #10 waytobazaar.com 9 employees
  11. #11 web-hosting.com 9 employees
  12. #12 onet.pl 9 employees
  13. #13 bharatnet.internal 9 employees
  14. #14 netpnb.com 8 employees
  15. #15 office.com 8 employees
  16. #16 unibo.it 7 employees
  17. #17 payoneer.com 7 employees
  18. #18 ixyle.ai 7 employees
  19. #19 kalogistics.co.id 7 employees
  20. #20 alxswe.com 7 employees
  21. #21 hotline.solutions 6 employees
  22. #22 inmotionhosting.com 6 employees
  23. #23 pec.it 6 employees
  24. #24 wp.pl 6 employees
  25. #25 atlassian.com 6 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 rockwellautomation.com 4 employees
  2. #2 microsoft.com 4 employees
  3. #3 amazon.com 2 employees
  4. #4 csc.com 1 employees
  5. #5 oracle.com 1 employees
  6. #6 frontier.com 1 employees
  7. #7 jll.com 1 employees
  8. #8 cognizant.com 1 employees

Compromised users

  1. #1 google.com 3,642 users
  2. #2 facebook.com 2,565 users
  3. #3 netflix.com 1,568 users
  4. #4 amazon.com 1,110 users
  5. #5 paypal.com 840 users
  6. #6 apple.com 789 users
  7. #7 microsoft.com 143 users
  8. #8 ebay.com 139 users
  9. #9 oracle.com 135 users
  10. #10 salesforce.com 122 users
  11. #11 hp.com 113 users
  12. #12 nike.com 108 users
  13. #13 cisco.com 73 users
  14. #14 ibm.com 52 users
  15. #15 walmart.com 47 users
  16. #16 ups.com 33 users
  17. #17 intel.com 27 users
  18. #18 broadcom.com 23 users
  19. #19 fedex.com 23 users
  20. #20 target.com 23 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

1,231 users

#2

Instagram

instagram.com · com.instagram.android

999 users

#3

Netflix

netflix.com · com.netflix.mediaclient

805 users

#4

Pinterest

pinterest.com · com.pinterest

640 users

#5

Roblox

roblox.com · com.roblox.client

607 users

#6

Spotify

spotify.com · com.spotify.music

606 users

#7

Discord

discord.com · com.discord

574 users

#8

Snapchat

snapchat.com · com.snapchat.android

441 users

#9

Twitter

twitter.com · com.twitter.android

420 users

#10

Twitch

app.com · tv.twitch.android.app

391 users

#11

Wish

contextlogic.com · com.contextlogic.wish

248 users

#12

PayPal

paypal.com · com.paypal.android.p2pmobile

239 users

#13

LinkedIn

linkedin.com · com.linkedin.android

214 users

#14

Zoom

videomeetings.com · us.zoom.videomeetings

196 users

#15

Mega

app.com · mega.privacy.android.app

168 users

#16

Xiaomi

xiaomi.com · com.xiaomi.account

157 users

#17

Disney

disney.com · com.disney.disneyplus

145 users

#18

Alibaba

alibaba.com · com.alibaba.aliexpresshd

131 users

#19

Waze

waze.com · com.waze

109 users

#20

Mercadolibre

mercadolibre.com · com.mercadolibre

106 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 148,023 users
  2. #2 hotmail.com 11,506 users
  3. #3 yahoo.com 6,248 users
  4. #4 outlook.com 3,327 users
  5. #5 icloud.com 1,554 users
  6. #6 live.com 567 users
  7. #7 aol.com 561 users
  8. #8 yahoo.fr 485 users
  9. #9 hotmail.co.uk 416 users
  10. #10 yahoo.com.br 397 users
  11. #11 hotmail.fr 271 users
  12. #12 mail.com 236 users
  13. #13 yahoo.co.in 226 users
  14. #14 protonmail.com 221 users
  15. #15 yahoo.co.id 211 users
  16. #16 hotmail.it 198 users
  17. #17 ymail.com 193 users
  18. #18 rocketmail.com 141 users
  19. #19 web.de 136 users
  20. #20 yahoo.it 134 users
  21. #21 live.fr 129 users
  22. #22 msn.com 108 users
  23. #23 gmx.de 103 users
  24. #24 comcast.net 97 users
  25. #25 proton.me 92 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 2,565 accounts
  2. #2 twitter.com 977 accounts
  3. #3 instagram.com 1,635 accounts
  4. #4 linkedin.com 1,036 accounts
  5. #5 pinterest.com 245 accounts
  6. #6 tiktok.com 366 accounts
  7. #7 snapchat.com 311 accounts
  8. #8 reddit.com 183 accounts
  9. #9 youtube.com 29 accounts
  10. #10 weibo.com 6 accounts
  11. #11 vk.com 114 accounts
  12. #12 telegram.org 23 accounts
  13. #13 tumblr.com 78 accounts
  14. #14 discord.com 1,312 accounts
  15. #15 flickr.com 50 accounts
  16. #16 myspace.com 5 accounts
  17. #17 badoo.com 18 accounts
  18. #18 meetup.com 3 accounts
  19. #19 quora.com 25 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Lumma 2,714machines
  2. #2 Generic Stealer 2,461machines

Anti-virus Coverage

  1. #1 Windows Defender 1,770machines
  2. #2 None 459machines
  3. #3 Reason Cybersecurity 170machines
  4. #4 Windows Defender [ON] 145machines
  5. #5 Kaspersky 7machines
  6. #6 Bkav Pro Internet Security 6machines
  7. #7 Avast Antivirus 3machines
  8. #8 Spybot - Search and Destroy 3machines
  9. #9 Bkav Endpoint Security 3machines
  10. #10 Kaspersky [OFF] 3machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 16,359hits
  2. #2 sso 4,111hits
  3. #3 zoom 1,494hits
  4. #4 github 1,108hits
  5. #5 vpn 778hits
  6. #6 webmail 562hits
  7. #7 adfs 379hits
  8. #8 owa 303hits
  9. #9 cpanel 297hits
  10. #10 oracle 284hits
  11. #11 sap 241hits
  12. #12 jira 229hits
  13. #13 zendesk 206hits
  14. #14 salesforce 167hits
  15. #15 sts 127hits
  16. #16 ping 125hits
  17. #17 okta 87hits
  18. #18 kaspersky 87hits
  19. #19 st 78hits
  20. #20 gitlab 74hits
  21. #21 ftp 72hits
  22. #22 webex 66hits
  23. #23 roundcube 63hits
  24. #24 extranet 48hits
  25. #25 git 41hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure