Skip to content
Weekly intelligence Sep 8 – Sep 15, 2025 13 min read

Infostealers Weekly Report: 2025-09-08 – 2025-09-15

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 18,247 Compromised Machines
#2 3,093 Compromised Employees
#3 5,389 Compromised Users
#4 9,765 Compromised Androids
#5 197,399 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 179
Infections by country

Top 25 countries

  1. #1 United States of America 1,654
  2. #2 India 1,465
  3. #3 Brazil 1,014
  4. #4 Vietnam 839
  5. #5 Indonesia 833
  6. #6 Philippines 807
  7. #7 Turkey 558
  8. #8 Bangladesh 483
  9. #9 Germany 433
  10. #10 France 349
  11. #11 United Kingdom 340
  12. #12 Colombia 318
  13. #13 Poland 315
  14. #14 Thailand 304
  15. #15 Pakistan 279
  16. #16 Egypt 272
  17. #17 Mexico 259
  18. #18 Argentina 222
  19. #19 Spain 205
  20. #20 Romania 198
  21. #21 Italy 195
  22. #22 Malaysia 192
  23. #23 Netherlands 146
  24. #24 Morocco 146
  25. #25 Peru 145

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 12,417 users
  2. #2 live.com 9,293 users
  3. #3 facebook.com 9,163 users
  4. #4 roblox.com 8,787 users
  5. #5 discord.com 8,184 users
  6. #6 instagram.com 6,005 users
  7. #7 steampowered.com 5,132 users
  8. #8 com.facebook.katana 5,109 users
  9. #9 netflix.com 4,948 users
  10. #10 com.roblox.client 4,534 users
  11. #11 twitch.tv 4,218 users
  12. #12 epicgames.com 4,037 users
  13. #13 riotgames.com 3,857 users
  14. #14 com.instagram.android 3,853 users
  15. #15 amazon.com 3,772 users
  16. #16 spotify.com 3,521 users
  17. #17 apple.com 3,380 users
  18. #18 paypal.com 3,353 users
  19. #19 com.netflix.mediaclient 3,306 users
  20. #20 steamcommunity.com 3,155 users
  21. #21 com.discord 3,134 users
  22. #22 microsoftonline.com 2,842 users
  23. #23 twitter.com 2,721 users
  24. #24 rockstargames.com 2,435 users
  25. #25 tlauncher.org 2,382 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 firstmail.ltd 187 employees
  2. #2 hostinger.com 59 employees
  3. #3 icicibank.com 57 employees
  4. #4 wp.pl 56 employees
  5. #5 zsthost.com 42 employees
  6. #6 rediff.com 31 employees
  7. #7 secop.gov.co 30 employees
  8. #8 163.com 29 employees
  9. #9 bobibanking.com 26 employees
  10. #10 unionbankonline.co.in 23 employees
  11. #11 deped.gov.ph 20 employees
  12. #12 interia.pl 19 employees
  13. #13 netpnb.com 19 employees
  14. #14 mail.tm 17 employees
  15. #15 aruba.it 17 employees
  16. #16 digimail.in 17 employees
  17. #17 imbamail.com 17 employees
  18. #18 rmunify.com 16 employees
  19. #19 onet.pl 15 employees
  20. #20 naver.com 15 employees
  21. #21 buenosaires.gob.ar 15 employees
  22. #22 seznam.cz 14 employees
  23. #23 p1177.net 14 employees
  24. #24 77mail.cc 13 employees
  25. #25 gygmail4.com 13 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 microsoft.com 6 employees
  2. #2 publix.com 5 employees
  3. #3 fedex.com 3 employees
  4. #4 ups.com 3 employees
  5. #5 rockwellautomation.com 2 employees
  6. #6 ibm.com 2 employees
  7. #7 cisco.com 2 employees
  8. #8 cbre.com 2 employees
  9. #9 amazon.com 2 employees
  10. #10 netflix.com 1 employees
  11. #11 jpmorganchase.com 1 employees
  12. #12 nov.com 1 employees
  13. #13 honeywell.com 1 employees
  14. #14 chsinc.com 1 employees
  15. #15 statefarm.com 1 employees
  16. #16 autonation.com 1 employees
  17. #17 csc.com 1 employees
  18. #18 bnymellon.com 1 employees
  19. #19 frontier.com 1 employees
  20. #20 bms.com 1 employees

Compromised users

  1. #1 google.com 12,417 users
  2. #2 facebook.com 9,163 users
  3. #3 netflix.com 4,948 users
  4. #4 amazon.com 3,772 users
  5. #5 apple.com 3,380 users
  6. #6 paypal.com 3,353 users
  7. #7 ebay.com 457 users
  8. #8 nike.com 443 users
  9. #9 hp.com 377 users
  10. #10 oracle.com 345 users
  11. #11 microsoft.com 273 users
  12. #12 walmart.com 265 users
  13. #13 cisco.com 163 users
  14. #14 ups.com 132 users
  15. #15 bestbuy.com 129 users
  16. #16 target.com 124 users
  17. #17 adp.com 119 users
  18. #18 fedex.com 108 users
  19. #19 disney.com 108 users
  20. #20 capitalone.com 100 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

5,109 users

#2

Roblox

roblox.com · com.roblox.client

4,534 users

#3

Instagram

instagram.com · com.instagram.android

3,853 users

#4

Netflix

netflix.com · com.netflix.mediaclient

3,306 users

#5

Discord

discord.com · com.discord

3,134 users

#6

Spotify

spotify.com · com.spotify.music

1,981 users

#7

Twitch

app.com · tv.twitch.android.app

1,969 users

#8

Snapchat

snapchat.com · com.snapchat.android

1,653 users

#9

Twitter

twitter.com · com.twitter.android

1,376 users

#10

Pinterest

pinterest.com · com.pinterest

1,011 users

#11

PayPal

paypal.com · com.paypal.android.p2pmobile

997 users

#12

Mega

app.com · mega.privacy.android.app

774 users

#13

Disney

disney.com · com.disney.disneyplus

710 users

#14

Xiaomi

xiaomi.com · com.xiaomi.account

681 users

#15

Zoom

videomeetings.com · us.zoom.videomeetings

677 users

#16

Wish

contextlogic.com · com.contextlogic.wish

620 users

#17

LinkedIn

linkedin.com · com.linkedin.android

384 users

#18

Mercadolibre

mercadolibre.com · com.mercadolibre

321 users

#19

Alibaba

alibaba.com · com.alibaba.aliexpresshd

294 users

#20

Waze

waze.com · com.waze

289 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 499,737 users
  2. #2 hotmail.com 31,258 users
  3. #3 yahoo.com 18,340 users
  4. #4 outlook.com 14,336 users
  5. #5 icloud.com 7,220 users
  6. #6 live.com 1,697 users
  7. #7 web.de 1,240 users
  8. #8 yahoo.fr 1,144 users
  9. #9 mail.com 936 users
  10. #10 hotmail.fr 838 users
  11. #11 aol.com 802 users
  12. #12 msn.com 781 users
  13. #13 gmx.de 723 users
  14. #14 proton.me 711 users
  15. #15 mail.ru 648 users
  16. #16 yahoo.co.uk 609 users
  17. #17 yahoo.co.id 599 users
  18. #18 ymail.com 528 users
  19. #19 gmx.net 492 users
  20. #20 yahoo.com.br 473 users
  21. #21 hotmail.co.uk 424 users
  22. #22 orange.fr 420 users
  23. #23 libero.it 407 users
  24. #24 yahoo.com.ar 396 users
  25. #25 outlook.com.br 394 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 9,163 accounts
  2. #2 twitter.com 2,721 accounts
  3. #3 instagram.com 6,005 accounts
  4. #4 linkedin.com 1,423 accounts
  5. #5 pinterest.com 892 accounts
  6. #6 tiktok.com 2,028 accounts
  7. #7 snapchat.com 1,800 accounts
  8. #8 reddit.com 493 accounts
  9. #9 youtube.com 56 accounts
  10. #10 weibo.com 26 accounts
  11. #11 vk.com 575 accounts
  12. #12 telegram.org 84 accounts
  13. #13 tumblr.com 150 accounts
  14. #14 discord.com 8,184 accounts
  15. #15 flickr.com 65 accounts
  16. #16 myspace.com 19 accounts
  17. #17 badoo.com 51 accounts
  18. #18 meetup.com 14 accounts
  19. #19 quora.com 46 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Generic Stealer 13,850machines
  2. #2 Lumma 4,307machines
  3. #3 Acreed 90machines

Anti-virus Coverage

  1. #1 Windows Defender 1,354machines
  2. #2 Windows Defender [ON] 919machines
  3. #3 None 874machines
  4. #4 316machines
  5. #5 Reason Cybersecurity 95machines
  6. #6 Windows Defender. 49machines
  7. #7 Malwarebytes [OFF] 8machines
  8. #8 Windows Defender, McAfee. 6machines
  9. #9 Malwarebytes 6machines
  10. #10 360 Total Security 5machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 56,972hits
  2. #2 sso 14,417hits
  3. #3 github 3,503hits
  4. #4 zoom 3,404hits
  5. #5 adfs 1,403hits
  6. #6 webmail 1,395hits
  7. #7 zendesk 765hits
  8. #8 oracle 727hits
  9. #9 vpn 599hits
  10. #10 sap 501hits
  11. #11 ping 481hits
  12. #12 sts 445hits
  13. #13 owa 355hits
  14. #14 cpanel 301hits
  15. #15 st 252hits
  16. #16 okta 244hits
  17. #17 salesforce 242hits
  18. #18 webex 218hits
  19. #19 extranet 214hits
  20. #20 kaspersky 186hits
  21. #21 webvpn 182hits
  22. #22 ftp 134hits
  23. #23 twilio 126hits
  24. #24 roundcube 119hits
  25. #25 gitlab 88hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure