Infostealers Weekly Report: 2025-10-06 – 2025-10-13
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 958
- #2 Brazil 322
- #3 Indonesia 299
- #4 United States of America 299
- #5 Vietnam 275
- #6 Mexico 239
- #7 Egypt 219
- #8 Philippines 215
- #9 Bangladesh 213
- #10 Argentina 205
- #11 Colombia 160
- #12 Peru 157
- #13 Turkey 135
- #14 Pakistan 135
- #15 Thailand 109
- #16 Germany 102
- #17 France 93
- #18 Poland 79
- #19 Chile 77
- #20 Italy 72
- #21 Algeria 67
- #22 United Kingdom 67
- #23 Spain 66
- #24 United Arab Emirates 54
- #25 Ecuador 48
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,051 users
-
#2
facebook.com 4,751 users
-
#3
live.com 4,367 users
-
#4
instagram.com 3,172 users
-
#5
discord.com 2,746 users
-
#6
netflix.com 2,514 users
-
#7
com.facebook.katana 2,400 users
-
#8
roblox.com 2,321 users
-
#9
amazon.com 2,139 users
-
#10
com.instagram.android 1,979 users
-
#11
steampowered.com 1,881 users
-
#12
microsoftonline.com 1,663 users
-
#13
paypal.com 1,647 users
-
#14
com.netflix.mediaclient 1,617 users
-
#15
twitter.com 1,524 users
-
#16
twitch.tv 1,452 users
-
#17
spotify.com 1,452 users
-
#18
apple.com 1,384 users
-
#19
linkedin.com 1,372 users
-
#20
epicgames.com 1,338 users
-
#21
com.roblox.client 1,312 users
-
#22
riotgames.com 1,279 users
-
#23
openai.com 1,239 users
-
#24
com.discord 1,212 users
-
#25
github.com 1,127 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 67 employees
-
#2
icicibank.com 59 employees
-
#3
rediff.com 41 employees
-
#4
firstmail.ltd 38 employees
-
#5
buenosaires.gob.ar 20 employees
-
#6
bobibanking.com 18 employees
-
#7
watchit.com 16 employees
-
#8
secop.gov.co 15 employees
-
#9
secureserver.net 15 employees
-
#10
icai.org 14 employees
-
#11
concentrix.com 14 employees
-
#12
onlinesbi.com 14 employees
-
#13
sat.gob.mx 12 employees
-
#14
njoyn.com 12 employees
-
#15
wp.pl 12 employees
-
#16
fednetbank.com 11 employees
-
#17
pec.it 11 employees
-
#18
mail.tm 11 employees
-
#19
abv.bg 11 employees
-
#20
atlassian.com 10 employees
-
#21
pnbibanking.in 10 employees
-
#22
163.com 10 employees
-
#23
onlinesbi.sbi 10 employees
-
#24
vk.com 10 employees
-
#25
netpnb.com 10 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 5 employees
-
#2
microsoft.com 4 employees
-
#3
csc.com 2 employees
-
#4
apple.com 2 employees
-
#5
hp.com 2 employees
-
#6
xerox.com 1 employees
-
#7
publix.com 1 employees
-
#8
ford.com 1 employees
-
#9
newyorklife.com 1 employees
-
#10
motorolasolutions.com 1 employees
-
#11
oracle.com 1 employees
-
#12
ups.com 1 employees
-
#13
ibm.com 1 employees
-
#14
wrberkley.com 1 employees
-
#15
pg.com 1 employees
Compromised users
-
#1
google.com 6,055 users
-
#2
facebook.com 4,752 users
-
#3
netflix.com 2,514 users
-
#4
amazon.com 2,141 users
-
#5
paypal.com 1,647 users
-
#6
apple.com 1,385 users
-
#7
ebay.com 294 users
-
#8
oracle.com 283 users
-
#9
hp.com 273 users
-
#10
nike.com 221 users
-
#11
microsoft.com 212 users
-
#12
cisco.com 156 users
-
#13
walmart.com 132 users
-
#14
ibm.com 115 users
-
#15
ups.com 76 users
-
#16
westernunion.com 68 users
-
#17
fedex.com 68 users
-
#18
bestbuy.com 62 users
-
#19
adp.com 49 users
-
#20
intel.com 48 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
2,400 users
1,979 users
Netflix
1,617 users
Roblox
1,312 users
Discord
1,212 users
Spotify
941 users
Snapchat
856 users
Twitch
762 users
737 users
551 users
Zoom
431 users
PayPal
395 users
359 users
Xiaomi
332 users
Disney
323 users
Wish
322 users
Mega
321 users
Mercadolibre
195 users
Alibaba
176 users
Waze
154 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 273,181 users
-
#2
hotmail.com 23,992 users
-
#3
yahoo.com 10,097 users
-
#4
outlook.com 7,678 users
-
#5
icloud.com 1,833 users
-
#6
live.com 1,106 users
-
#7
mail.ru 1,015 users
-
#8
libero.it 731 users
-
#9
me.com 699 users
-
#10
yahoo.com.br 689 users
-
#11
yahoo.co.uk 619 users
-
#12
mail.com 602 users
-
#13
aol.com 566 users
-
#14
hotmail.co.uk 525 users
-
#15
hotmail.fr 512 users
-
#16
web.de 447 users
-
#17
orange.fr 445 users
-
#18
free.fr 437 users
-
#19
msn.com 393 users
-
#20
protonmail.com 386 users
-
#21
gmx.de 380 users
-
#22
yahoo.fr 379 users
-
#23
yahoo.com.ar 342 users
-
#24
proton.me 309 users
-
#25
hotmail.es 284 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 7,542machines
- #2 Lumma 1,097machines
- #3 Acreed 292machines
Anti-virus Coverage
- #1 Windows Defender 1,656machines
- #2 Windows Defender. 378machines
- #3 Disabled 285machines
- #4 Windows Defender, McAfee. 27machines
- #5 N/A 24machines
- #6 Windows Defender, Avast Antivirus. 17machines
- #7 Kaspersky, Windows Defender, Kaspersky. 10machines
- #8 Windows Defender, AVG Antivirus. 9machines
- #9 Windows Defender, 360 Total Security. 8machines
- #10 Windows Defender, ESET Security. 4machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 36,469hits
- #2 sso 8,154hits
- #3 zoom 2,286hits
- #4 github 1,914hits
- #5 webmail 1,113hits
- #6 adfs 862hits
- #7 oracle 550hits
- #8 zendesk 392hits
- #9 sap 383hits
- #10 ping 355hits
- #11 cpanel 305hits
- #12 sts 303hits
- #13 owa 273hits
- #14 vpn 261hits
- #15 okta 194hits
- #16 salesforce 190hits
- #17 kaspersky 182hits
- #18 webex 166hits
- #19 extranet 165hits
- #20 citrix 141hits
- #21 st 140hits
- #22 twilio 97hits
- #23 ftp 88hits
- #24 roundcube 76hits
- #25 gitlab 63hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.