Infostealers Weekly Report: 2025-08-11 – 2025-08-18
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 3,967
- #2 France 3,349
- #3 India 2,588
- #4 Japan 2,257
- #5 Brazil 959
- #6 Indonesia 723
- #7 Nigeria 660
- #8 Mexico 625
- #9 Philippines 584
- #10 Pakistan 499
- #11 Colombia 483
- #12 Bangladesh 466
- #13 Vietnam 368
- #14 Germany 362
- #15 Egypt 347
- #16 Spain 320
- #17 Argentina 309
- #18 South Korea 306
- #19 Peru 280
- #20 Italy 276
- #21 Turkey 251
- #22 United Kingdom 247
- #23 South Africa 205
- #24 Chile 159
- #25 Kenya 158
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 53,097 users
-
#2
facebook.com 39,639 users
-
#3
microsoftonline.com 22,237 users
-
#4
live.com 21,042 users
-
#5
netflix.com 20,106 users
-
#6
amazon.com 19,606 users
-
#7
linkedin.com 18,912 users
-
#8
instagram.com 18,426 users
-
#9
slack.com 17,316 users
-
#10
zoom.us 16,910 users
-
#11
twitter.com 13,778 users
-
#12
discord.com 11,545 users
-
#13
com.facebook.katana 11,466 users
-
#14
com.instagram.android 9,550 users
-
#15
dropbox.com 9,224 users
-
#16
spotify.com 9,081 users
-
#17
paypal.com 9,073 users
-
#18
canva.com 8,831 users
-
#19
roblox.com 8,751 users
-
#20
openai.com 8,094 users
-
#21
github.com 7,944 users
-
#22
com.netflix.mediaclient 7,670 users
-
#23
apple.com 7,180 users
-
#24
godaddy.com 7,157 users
-
#25
steampowered.com 6,463 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
emailsrvr.com 743 employees
-
#2
zgraph.com 734 employees
-
#3
hostinger.com 682 employees
-
#4
parisnet.internal 234 employees
-
#5
icicibank.com 224 employees
-
#6
firstmail.ltd 220 employees
-
#7
stynique.com 214 employees
-
#8
bdlearninghub.com 214 employees
-
#9
choicebird.com 214 employees
-
#10
rediff.com 191 employees
-
#11
aruba.it 171 employees
-
#12
miraitech.internal 141 employees
-
#13
company.local 138 employees
-
#14
prairiestate.edu 138 employees
-
#15
xpertessays.com 138 employees
-
#16
rencon.co.ke 138 employees
-
#17
naver.com 115 employees
-
#18
mail.tm 103 employees
-
#19
fr.internal 101 employees
-
#20
americorp.internal 96 employees
-
#21
pec.it 93 employees
-
#22
parisnet.intern 91 employees
-
#23
payoneer.com 88 employees
-
#24
northstar.intern 82 employees
-
#25
bobibanking.com 79 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 31 employees
-
#2
netflix.com 25 employees
-
#3
hp.com 22 employees
-
#4
cognizant.com 22 employees
-
#5
amazon.com 21 employees
-
#6
publix.com 11 employees
-
#7
pfizer.com 9 employees
-
#8
ford.com 7 employees
-
#9
oracle.com 6 employees
-
#10
rockwellautomation.com 6 employees
-
#11
ebay.com 4 employees
-
#12
apple.com 3 employees
-
#13
ibm.com 3 employees
-
#14
ups.com 3 employees
-
#15
metlife.com 3 employees
-
#16
wrberkley.com 3 employees
-
#17
visteon.com 3 employees
-
#18
aflac.com 3 employees
-
#19
manpowergroup.com 3 employees
-
#20
gm.com 3 employees
Compromised users
-
#1
google.com 53,097 users
-
#2
facebook.com 39,639 users
-
#3
netflix.com 20,106 users
-
#4
amazon.com 19,606 users
-
#5
paypal.com 9,073 users
-
#6
apple.com 7,180 users
-
#7
att.com 5,551 users
-
#8
salesforce.com 3,290 users
-
#9
microsoft.com 1,957 users
-
#10
ebay.com 1,742 users
-
#11
hp.com 1,315 users
-
#12
oracle.com 1,210 users
-
#13
wellsfargo.com 1,116 users
-
#14
nike.com 982 users
-
#15
bankofamerica.com 946 users
-
#16
marriott.com 905 users
-
#17
walmart.com 787 users
-
#18
cisco.com 748 users
-
#19
ibm.com 559 users
-
#20
ups.com 482 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
11,466 users
9,550 users
Netflix
7,670 users
Roblox
4,556 users
Discord
4,474 users
Spotify
4,416 users
Snapchat
4,139 users
3,888 users
3,878 users
Twitch
3,070 users
2,546 users
PayPal
2,147 users
Wish
2,059 users
Zoom
1,858 users
Disney
1,650 users
Mega
1,508 users
Xiaomi
1,283 users
Mercadolibre
1,025 users
Alibaba
913 users
Waze
894 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,751,679 users
-
#2
hotmail.com 128,638 users
-
#3
yahoo.com 62,931 users
-
#4
outlook.com 37,705 users
-
#5
att.net 29,397 users
-
#6
icloud.com 12,145 users
-
#7
mail.ru 5,426 users
-
#8
live.com 5,217 users
-
#9
yahoo.fr 3,898 users
-
#10
aol.com 2,966 users
-
#11
msn.com 2,966 users
-
#12
yahoo.com.br 2,862 users
-
#13
hotmail.fr 2,594 users
-
#14
web.de 2,289 users
-
#15
orange.fr 2,190 users
-
#16
comcast.net 2,176 users
-
#17
mail.com 2,062 users
-
#18
libero.it 2,013 users
-
#19
hotmail.es 1,910 users
-
#20
hotmail.co.uk 1,727 users
-
#21
yahoo.com.ar 1,695 users
-
#22
ymail.com 1,577 users
-
#23
hotmail.it 1,390 users
-
#24
hanmail.net 1,355 users
-
#25
gmx.de 1,224 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 53,656machines
- #2 Lumma 39,598machines
- #3 RedLine 231machines
Anti-virus Coverage
- #1 Windows Defender 30,879machines
- #2 None 9,196machines
- #3 Sentinel Agent, Windows Defender 4,573machines
- #4 Windows Defender, Webroot SecureAnywhere 4,491machines
- #5 Windows Defender, Sentinel Agent 3,924machines
- #6 Windows Defender [ON] 1,826machines
- #7 Reason Cybersecurity 347machines
- #8 328machines
- #9 Windows Defender, McAfee 272machines
- #10 McAfee, Windows Defender 164machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 189,340hits
- #2 sso 60,416hits
- #3 zoom 25,160hits
- #4 vpn 16,141hits
- #5 github 11,939hits
- #6 webmail 8,002hits
- #7 jira 4,656hits
- #8 adfs 3,864hits
- #9 salesforce 3,727hits
- #10 zendesk 2,419hits
- #11 oracle 2,388hits
- #12 sap 2,232hits
- #13 owa 2,132hits
- #14 ping 2,092hits
- #15 cpanel 1,797hits
- #16 sts 1,512hits
- #17 gitlab 1,466hits
- #18 git 1,104hits
- #19 okta 986hits
- #20 roundcube 981hits
- #21 webex 914hits
- #22 kaspersky 896hits
- #23 extranet 800hits
- #24 twilio 586hits
- #25 ftp 577hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.