Infostealers Weekly Report: 2025-07-21 – 2025-07-28
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 444
- #2 Brazil 192
- #3 France 188
- #4 United States of America 185
- #5 Indonesia 153
- #6 Spain 138
- #7 Japan 117
- #8 Vietnam 115
- #9 Turkey 93
- #10 Pakistan 84
- #11 Philippines 80
- #12 Poland 80
- #13 Egypt 51
- #14 Mexico 39
- #15 Argentina 39
- #16 United Kingdom 37
- #17 Bangladesh 36
- #18 Romania 36
- #19 South Africa 34
- #20 Thailand 34
- #21 Algeria 33
- #22 Kenya 31
- #23 Morocco 30
- #24 Nepal 27
- #25 Serbia 23
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,642 users
-
#2
facebook.com 2,565 users
-
#3
live.com 2,094 users
-
#4
instagram.com 1,635 users
-
#5
netflix.com 1,568 users
-
#6
microsoftonline.com 1,340 users
-
#7
discord.com 1,312 users
-
#8
com.facebook.katana 1,231 users
-
#9
amazon.com 1,110 users
-
#10
linkedin.com 1,036 users
-
#11
roblox.com 1,017 users
-
#12
com.instagram.android 999 users
-
#13
twitter.com 977 users
-
#14
zoom.us 918 users
-
#15
spotify.com 863 users
-
#16
steampowered.com 855 users
-
#17
paypal.com 840 users
-
#18
com.netflix.mediaclient 805 users
-
#19
apple.com 789 users
-
#20
github.com 708 users
-
#21
slack.com 680 users
-
#22
epicgames.com 670 users
-
#23
twitch.tv 669 users
-
#24
com.pinterest 640 users
-
#25
com.roblox.client 607 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 33 employees
-
#2
icicibank.com 28 employees
-
#3
firstmail.ltd 20 employees
-
#4
rediff.com 18 employees
-
#5
secureserver.net 16 employees
-
#6
office365.com 14 employees
-
#7
unionbankonline.co.in 10 employees
-
#8
aiou.edu.pk 10 employees
-
#9
skillssurge.ai 9 employees
-
#10
waytobazaar.com 9 employees
-
#11
web-hosting.com 9 employees
-
#12
onet.pl 9 employees
-
#13
bharatnet.internal 9 employees
-
#14
netpnb.com 8 employees
-
#15
office.com 8 employees
-
#16
unibo.it 7 employees
-
#17
payoneer.com 7 employees
-
#18
ixyle.ai 7 employees
-
#19
kalogistics.co.id 7 employees
-
#20
alxswe.com 7 employees
-
#21
hotline.solutions 6 employees
-
#22
inmotionhosting.com 6 employees
-
#23
pec.it 6 employees
-
#24
wp.pl 6 employees
-
#25
atlassian.com 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 4 employees
-
#2
microsoft.com 4 employees
-
#3
amazon.com 2 employees
-
#4
csc.com 1 employees
-
#5
oracle.com 1 employees
-
#6
frontier.com 1 employees
-
#7
jll.com 1 employees
-
#8
cognizant.com 1 employees
Compromised users
-
#1
google.com 3,642 users
-
#2
facebook.com 2,565 users
-
#3
netflix.com 1,568 users
-
#4
amazon.com 1,110 users
-
#5
paypal.com 840 users
-
#6
apple.com 789 users
-
#7
microsoft.com 143 users
-
#8
ebay.com 139 users
-
#9
oracle.com 135 users
-
#10
salesforce.com 122 users
-
#11
hp.com 113 users
-
#12
nike.com 108 users
-
#13
cisco.com 73 users
-
#14
ibm.com 52 users
-
#15
walmart.com 47 users
-
#16
ups.com 33 users
-
#17
intel.com 27 users
-
#18
broadcom.com 23 users
-
#19
fedex.com 23 users
-
#20
target.com 23 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,231 users
999 users
Netflix
805 users
640 users
Roblox
607 users
Spotify
606 users
Discord
574 users
Snapchat
441 users
420 users
Twitch
391 users
Wish
248 users
PayPal
239 users
214 users
Zoom
196 users
Mega
168 users
Xiaomi
157 users
Disney
145 users
Alibaba
131 users
Waze
109 users
Mercadolibre
106 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 148,023 users
-
#2
hotmail.com 11,506 users
-
#3
yahoo.com 6,248 users
-
#4
outlook.com 3,327 users
-
#5
icloud.com 1,554 users
-
#6
live.com 567 users
-
#7
aol.com 561 users
-
#8
yahoo.fr 485 users
-
#9
hotmail.co.uk 416 users
-
#10
yahoo.com.br 397 users
-
#11
hotmail.fr 271 users
-
#12
mail.com 236 users
-
#13
yahoo.co.in 226 users
-
#14
protonmail.com 221 users
-
#15
yahoo.co.id 211 users
-
#16
hotmail.it 198 users
-
#17
ymail.com 193 users
-
#18
rocketmail.com 141 users
-
#19
web.de 136 users
-
#20
yahoo.it 134 users
-
#21
live.fr 129 users
-
#22
msn.com 108 users
-
#23
gmx.de 103 users
-
#24
comcast.net 97 users
-
#25
proton.me 92 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Lumma 2,714machines
- #2 Generic Stealer 2,461machines
Anti-virus Coverage
- #1 Windows Defender 1,770machines
- #2 None 459machines
- #3 Reason Cybersecurity 170machines
- #4 Windows Defender [ON] 145machines
- #5 Kaspersky 7machines
- #6 Bkav Pro Internet Security 6machines
- #7 Avast Antivirus 3machines
- #8 Spybot - Search and Destroy 3machines
- #9 Bkav Endpoint Security 3machines
- #10 Kaspersky [OFF] 3machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 16,359hits
- #2 sso 4,111hits
- #3 zoom 1,494hits
- #4 github 1,108hits
- #5 vpn 778hits
- #6 webmail 562hits
- #7 adfs 379hits
- #8 owa 303hits
- #9 cpanel 297hits
- #10 oracle 284hits
- #11 sap 241hits
- #12 jira 229hits
- #13 zendesk 206hits
- #14 salesforce 167hits
- #15 sts 127hits
- #16 ping 125hits
- #17 okta 87hits
- #18 kaspersky 87hits
- #19 st 78hits
- #20 gitlab 74hits
- #21 ftp 72hits
- #22 webex 66hits
- #23 roundcube 63hits
- #24 extranet 48hits
- #25 git 41hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.