Infostealers Weekly Report: 2025-09-22 – 2025-09-29
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 622
- #2 Brazil 320
- #3 Indonesia 278
- #4 Mexico 273
- #5 Vietnam 269
- #6 United States of America 237
- #7 Philippines 214
- #8 Peru 144
- #9 Colombia 144
- #10 Turkey 114
- #11 Bangladesh 112
- #12 Pakistan 112
- #13 Argentina 109
- #14 Egypt 104
- #15 Thailand 64
- #16 France 62
- #17 Chile 60
- #18 Malaysia 59
- #19 Italy 51
- #20 Ecuador 51
- #21 Morocco 50
- #22 Spain 47
- #23 Saudi Arabia 46
- #24 United Kingdom 45
- #25 Poland 44
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,188 users
-
#2
facebook.com 3,507 users
-
#3
live.com 3,166 users
-
#4
instagram.com 2,143 users
-
#5
discord.com 2,001 users
-
#6
netflix.com 1,844 users
-
#7
roblox.com 1,758 users
-
#8
com.facebook.katana 1,752 users
-
#9
amazon.com 1,516 users
-
#10
steampowered.com 1,335 users
-
#11
com.instagram.android 1,287 users
-
#12
microsoftonline.com 1,276 users
-
#13
com.netflix.mediaclient 1,190 users
-
#14
paypal.com 1,183 users
-
#15
twitter.com 1,117 users
-
#16
apple.com 1,086 users
-
#17
spotify.com 1,058 users
-
#18
com.roblox.client 1,005 users
-
#19
linkedin.com 971 users
-
#20
twitch.tv 965 users
-
#21
openai.com 936 users
-
#22
epicgames.com 880 users
-
#23
riotgames.com 863 users
-
#24
github.com 835 users
-
#25
com.discord 831 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 75 employees
-
#2
icicibank.com 39 employees
-
#3
wp.pl 24 employees
-
#4
firstmail.ltd 22 employees
-
#5
rediff.com 20 employees
-
#6
bobibanking.com 19 employees
-
#7
163.com 19 employees
-
#8
mail.tm 17 employees
-
#9
aruba.it 16 employees
-
#10
buenosaires.gob.ar 15 employees
-
#11
netpnb.com 13 employees
-
#12
interia.pl 12 employees
-
#13
onet.pl 12 employees
-
#14
secop.gov.co 12 employees
-
#15
laureate.net 12 employees
-
#16
pnbibanking.in 10 employees
-
#17
qq.com 10 employees
-
#18
unionbankonline.co.in 10 employees
-
#19
deped.gov.ph 10 employees
-
#20
web-hosting.com 9 employees
-
#21
accenture.com 9 employees
-
#22
secureserver.net 9 employees
-
#23
o2.pl 9 employees
-
#24
icai.org 8 employees
-
#25
santander.com.br 8 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 5 employees
-
#2
microsoft.com 5 employees
-
#3
netflix.com 2 employees
-
#4
ibm.com 2 employees
-
#5
hp.com 2 employees
-
#6
salesforce.com 2 employees
-
#7
cognizant.com 2 employees
-
#8
intel.com 1 employees
-
#9
frontier.com 1 employees
-
#10
publix.com 1 employees
-
#11
oracle.com 1 employees
-
#12
cbre.com 1 employees
-
#13
ups.com 1 employees
-
#14
cbrands.com 1 employees
-
#15
pepsico.com 1 employees
-
#16
citigroup.com 1 employees
-
#17
bnymellon.com 1 employees
-
#18
sandisk.com 1 employees
-
#19
google.com 1 employees
-
#20
paypal.com 1 employees
Compromised users
-
#1
google.com 4,188 users
-
#2
facebook.com 3,507 users
-
#3
netflix.com 1,844 users
-
#4
amazon.com 1,516 users
-
#5
paypal.com 1,183 users
-
#6
apple.com 1,086 users
-
#7
ebay.com 230 users
-
#8
hp.com 208 users
-
#9
oracle.com 187 users
-
#10
microsoft.com 176 users
-
#11
nike.com 149 users
-
#12
cisco.com 93 users
-
#13
walmart.com 92 users
-
#14
ibm.com 71 users
-
#15
ups.com 52 users
-
#16
broadcom.com 50 users
-
#17
fedex.com 46 users
-
#18
salesforce.com 42 users
-
#19
capitalone.com 42 users
-
#20
westernunion.com 41 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
1,752 users
1,287 users
Netflix
1,190 users
Roblox
1,005 users
Discord
831 users
Spotify
762 users
Twitch
592 users
550 users
Snapchat
529 users
518 users
PayPal
335 users
Zoom
296 users
Wish
280 users
Disney
262 users
234 users
Mega
222 users
Xiaomi
216 users
Mercadolibre
196 users
Alibaba
154 users
Waze
136 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 247,289 users
-
#2
hotmail.com 22,671 users
-
#3
yahoo.com 8,825 users
-
#4
outlook.com 6,289 users
-
#5
icloud.com 2,128 users
-
#6
libero.it 1,061 users
-
#7
ymail.com 938 users
-
#8
yahoo.fr 926 users
-
#9
virgilio.it 803 users
-
#10
yahoo.co.uk 792 users
-
#11
ntlworld.com 639 users
-
#12
hotmail.fr 564 users
-
#13
live.com 510 users
-
#14
web.de 495 users
-
#15
aol.com 492 users
-
#16
yahoo.com.br 418 users
-
#17
hotmail.co.uk 401 users
-
#18
mail.ru 308 users
-
#19
mail.com 304 users
-
#20
protonmail.com 258 users
-
#21
yahoo.co.id 226 users
-
#22
hotmail.be 217 users
-
#23
gmx.de 216 users
-
#24
yahoo.com.ar 214 users
-
#25
comcast.net 197 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 5,113machines
- #2 Lumma 1,074machines
- #3 Vidar 168machines
Anti-virus Coverage
- #1 Disabled 571machines
- #2 Windows Defender. 257machines
- #3 Windows Defender 206machines
- #4 Windows Defender, McAfee. 32machines
- #5 Windows Defender, Avast Antivirus. 23machines
- #6 N/A 19machines
- #7 Windows Defender, AVG Antivirus. 11machines
- #8 McAfee VirusScan 9machines
- #9 Windows Defender, McAfee 7machines
- #10 McAfee 7machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 28,940hits
- #2 sso 8,066hits
- #3 zoom 2,184hits
- #4 github 1,689hits
- #5 webmail 1,124hits
- #6 adfs 670hits
- #7 oracle 414hits
- #8 sap 382hits
- #9 sts 368hits
- #10 vpn 356hits
- #11 zendesk 356hits
- #12 ping 349hits
- #13 owa 342hits
- #14 cpanel 238hits
- #15 extranet 208hits
- #16 zimbra 171hits
- #17 salesforce 165hits
- #18 okta 146hits
- #19 kaspersky 132hits
- #20 st 118hits
- #21 webex 117hits
- #22 ftp 116hits
- #23 roundcube 111hits
- #24 jira 70hits
- #25 imap 68hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.