Infostealers Weekly Report: 2025-09-01 – 2025-09-08
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,603
- #2 Bangladesh 426
- #3 Brazil 370
- #4 Indonesia 315
- #5 Vietnam 291
- #6 United States of America 271
- #7 Philippines 242
- #8 Pakistan 238
- #9 Mexico 190
- #10 Egypt 179
- #11 Turkey 158
- #12 France 140
- #13 Germany 127
- #14 Argentina 111
- #15 Spain 103
- #16 Colombia 102
- #17 Thailand 99
- #18 Peru 82
- #19 United Kingdom 76
- #20 Italy 73
- #21 South Africa 73
- #22 Poland 70
- #23 Nigeria 67
- #24 Canada 67
- #25 Algeria 64
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,235 users
-
#2
facebook.com 5,016 users
-
#3
live.com 4,317 users
-
#4
instagram.com 2,910 users
-
#5
com.facebook.katana 2,849 users
-
#6
discord.com 2,509 users
-
#7
netflix.com 2,337 users
-
#8
roblox.com 2,188 users
-
#9
amazon.com 2,050 users
-
#10
com.instagram.android 2,028 users
-
#11
apple.com 1,837 users
-
#12
steampowered.com 1,692 users
-
#13
paypal.com 1,664 users
-
#14
com.netflix.mediaclient 1,620 users
-
#15
twitter.com 1,435 users
-
#16
mega.nz 1,416 users
-
#17
microsoftonline.com 1,413 users
-
#18
twitch.tv 1,354 users
-
#19
spotify.com 1,336 users
-
#20
192.168.1.1 1,290 users
-
#21
com.roblox.client 1,215 users
-
#22
epicgames.com 1,200 users
-
#23
riotgames.com 1,150 users
-
#24
linkedin.com 1,116 users
-
#25
openai.com 1,093 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 79 employees
-
#2
rediff.com 45 employees
-
#3
firstmail.ltd 44 employees
-
#4
hostinger.com 42 employees
-
#5
netpnb.com 27 employees
-
#6
pnbibanking.in 26 employees
-
#7
bobibanking.com 23 employees
-
#8
indusind.com 21 employees
-
#9
unionbankonline.co.in 20 employees
-
#10
aruba.it 18 employees
-
#11
mail.tm 17 employees
-
#12
wp.pl 15 employees
-
#13
seznam.cz 14 employees
-
#14
qq.com 11 employees
-
#15
microchip.com 11 employees
-
#16
maximintegrated.com 11 employees
-
#17
zsthost.com 11 employees
-
#18
freemail.hu 11 employees
-
#19
analog.com 11 employees
-
#20
karnataka.gov.in 11 employees
-
#21
digimail.in 11 employees
-
#22
web-hosting.com 10 employees
-
#23
jwpub.org 9 employees
-
#24
naver.com 9 employees
-
#25
atlassian.com 9 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
oracle.com 4 employees
-
#2
microsoft.com 4 employees
-
#3
rockwellautomation.com 3 employees
-
#4
cbre.com 2 employees
-
#5
ebay.com 2 employees
-
#6
paypal.com 1 employees
-
#7
manpowergroup.com 1 employees
-
#8
intel.com 1 employees
-
#9
hp.com 1 employees
-
#10
facebook.com 1 employees
-
#11
jpmorganchase.com 1 employees
-
#12
ford.com 1 employees
-
#13
frontier.com 1 employees
-
#14
ibm.com 1 employees
-
#15
quintiles.com 1 employees
-
#16
cognizant.com 1 employees
-
#17
xerox.com 1 employees
-
#18
honeywell.com 1 employees
-
#19
staples.com 1 employees
-
#20
salesforce.com 1 employees
Compromised users
-
#1
google.com 6,235 users
-
#2
facebook.com 5,016 users
-
#3
netflix.com 2,337 users
-
#4
amazon.com 2,050 users
-
#5
apple.com 1,837 users
-
#6
paypal.com 1,664 users
-
#7
ebay.com 281 users
-
#8
hp.com 249 users
-
#9
oracle.com 217 users
-
#10
microsoft.com 173 users
-
#11
nike.com 170 users
-
#12
cisco.com 137 users
-
#13
walmart.com 82 users
-
#14
ups.com 81 users
-
#15
ibm.com 74 users
-
#16
westernunion.com 64 users
-
#17
fedex.com 51 users
-
#18
broadcom.com 45 users
-
#19
salesforce.com 43 users
-
#20
adp.com 41 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
2,849 users
2,028 users
Netflix
1,620 users
Roblox
1,215 users
Discord
1,076 users
Spotify
997 users
Snapchat
948 users
798 users
781 users
Twitch
715 users
PayPal
499 users
Mega
498 users
Xiaomi
433 users
Zoom
427 users
Wish
412 users
343 users
Disney
297 users
Alibaba
235 users
Mercadolibre
189 users
Waze
184 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 286,967 users
-
#2
hotmail.com 22,500 users
-
#3
yahoo.com 13,061 users
-
#4
outlook.com 6,656 users
-
#5
icloud.com 2,567 users
-
#6
aol.com 851 users
-
#7
hotmail.fr 776 users
-
#8
yahoo.fr 667 users
-
#9
mail.ru 665 users
-
#10
orange.fr 643 users
-
#11
live.com 591 users
-
#12
mail.com 395 users
-
#13
ymail.com 380 users
-
#14
yahoo.co.id 380 users
-
#15
live.fr 365 users
-
#16
yahoo.com.ar 353 users
-
#17
yahoo.co.in 345 users
-
#18
hotmail.es 328 users
-
#19
msn.com 316 users
-
#20
laposte.net 313 users
-
#21
rocketmail.com 313 users
-
#22
sfr.fr 301 users
-
#23
proton.me 301 users
-
#24
libero.it 292 users
-
#25
live.com.mx 258 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 7,232machines
- #2 Lumma 2,379machines
- #3 Acreed 4machines
- #4 RedLine 1machines
Anti-virus Coverage
- #1 Windows Defender 1,846machines
- #2 None 745machines
- #3 Windows Defender [ON] 477machines
- #4 Windows Defender. 164machines
- #5 126machines
- #6 Reason Cybersecurity 112machines
- #7 Windows Defender, Avast Antivirus. 13machines
- #8 Windows Defender, McAfee. 10machines
- #9 McAfee 9machines
- #10 N/A 8machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 33,066hits
- #2 sso 10,719hits
- #3 zoom 1,958hits
- #4 github 1,938hits
- #5 webmail 920hits
- #6 adfs 772hits
- #7 oracle 556hits
- #8 sap 462hits
- #9 cpanel 449hits
- #10 vpn 442hits
- #11 owa 424hits
- #12 zendesk 351hits
- #13 sts 325hits
- #14 webvpn 271hits
- #15 ping 261hits
- #16 salesforce 189hits
- #17 st 173hits
- #18 kaspersky 162hits
- #19 okta 147hits
- #20 ftp 131hits
- #21 webex 130hits
- #22 roundcube 104hits
- #23 extranet 96hits
- #24 imap 81hits
- #25 twilio 64hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.