Infostealers Weekly Report: 2025-10-27 – 2025-11-03
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,469
- #2 United States of America 912
- #3 Brazil 544
- #4 Philippines 456
- #5 Indonesia 340
- #6 Mexico 326
- #7 Vietnam 314
- #8 Egypt 291
- #9 France 238
- #10 Colombia 232
- #11 Bangladesh 213
- #12 Turkey 206
- #13 Argentina 198
- #14 Thailand 196
- #15 Peru 188
- #16 Pakistan 178
- #17 Germany 175
- #18 Spain 168
- #19 Poland 157
- #20 Italy 140
- #21 Algeria 138
- #22 United Kingdom 132
- #23 Unknown Region 128
- #24 South Korea 115
- #25 Morocco 110
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 8,829 users
-
#2
facebook.com 6,721 users
-
#3
live.com 6,231 users
-
#4
instagram.com 4,718 users
-
#5
netflix.com 3,701 users
-
#6
discord.com 3,599 users
-
#7
com.facebook.katana 3,566 users
-
#8
amazon.com 3,026 users
-
#9
com.instagram.android 3,003 users
-
#10
roblox.com 2,928 users
-
#11
microsoftonline.com 2,531 users
-
#12
steampowered.com 2,519 users
-
#13
com.netflix.mediaclient 2,407 users
-
#14
paypal.com 2,186 users
-
#15
apple.com 1,975 users
-
#16
spotify.com 1,951 users
-
#17
twitter.com 1,926 users
-
#18
linkedin.com 1,917 users
-
#19
openai.com 1,890 users
-
#20
twitch.tv 1,821 users
-
#21
com.roblox.client 1,795 users
-
#22
epicgames.com 1,771 users
-
#23
riotgames.com 1,686 users
-
#24
com.discord 1,668 users
-
#25
github.com 1,630 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 79 employees
-
#2
icicibank.com 68 employees
-
#3
firstmail.ltd 68 employees
-
#4
rediff.com 40 employees
-
#5
bobibanking.com 38 employees
-
#6
netpnb.com 31 employees
-
#7
aruba.it 30 employees
-
#8
icai.org 30 employees
-
#9
unionbankonline.co.in 29 employees
-
#10
wp.pl 21 employees
-
#11
naver.com 20 employees
-
#12
secureserver.net 19 employees
-
#13
qq.com 18 employees
-
#14
pec.it 16 employees
-
#15
watchit.com 16 employees
-
#16
njoyn.com 16 employees
-
#17
163.com 15 employees
-
#18
laureate.net 15 employees
-
#19
zsthost.com 15 employees
-
#20
pnbibanking.in 15 employees
-
#21
mail.tm 15 employees
-
#22
accenture.com 15 employees
-
#23
buenosaires.gob.ar 14 employees
-
#24
onet.pl 13 employees
-
#25
alxswe.com 13 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 11 employees
-
#2
microsoft.com 10 employees
-
#3
cbre.com 4 employees
-
#4
cognizant.com 4 employees
-
#5
ibm.com 4 employees
-
#6
publix.com 4 employees
-
#7
twc.com 3 employees
-
#8
jpmorganchase.com 3 employees
-
#9
facebook.com 2 employees
-
#10
oracle.com 2 employees
-
#11
ups.com 2 employees
-
#12
disney.com 2 employees
-
#13
pepsico.com 1 employees
-
#14
charter.com 1 employees
-
#15
cisco.com 1 employees
-
#16
essendant.com 1 employees
-
#17
lear.com 1 employees
-
#18
fedex.com 1 employees
-
#19
emerson.com 1 employees
-
#20
ge.com 1 employees
Compromised users
-
#1
google.com 8,829 users
-
#2
facebook.com 6,721 users
-
#3
netflix.com 3,701 users
-
#4
amazon.com 3,026 users
-
#5
paypal.com 2,186 users
-
#6
apple.com 1,975 users
-
#7
ebay.com 445 users
-
#8
hp.com 425 users
-
#9
oracle.com 378 users
-
#10
nike.com 303 users
-
#11
microsoft.com 298 users
-
#12
walmart.com 253 users
-
#13
cisco.com 231 users
-
#14
ups.com 185 users
-
#15
adp.com 144 users
-
#16
ibm.com 138 users
-
#17
target.com 133 users
-
#18
fedex.com 132 users
-
#19
capitalone.com 132 users
-
#20
att.com 126 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
3,566 users
3,003 users
Netflix
2,407 users
Roblox
1,795 users
Discord
1,668 users
Spotify
1,326 users
Snapchat
1,325 users
Twitch
1,065 users
992 users
Zoom
637 users
PayPal
634 users
589 users
544 users
Xiaomi
477 users
Disney
459 users
Mega
407 users
Wish
370 users
Alibaba
219 users
Waze
214 users
Mercadolibre
177 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 392,337 users
-
#2
hotmail.com 32,746 users
-
#3
yahoo.com 19,660 users
-
#4
outlook.com 10,834 users
-
#5
icloud.com 3,538 users
-
#6
sky.com 1,575 users
-
#7
live.com 1,543 users
-
#8
hotmail.fr 1,357 users
-
#9
aol.com 1,095 users
-
#10
mail.ru 1,012 users
-
#11
yahoo.fr 914 users
-
#12
orange.fr 775 users
-
#13
protonmail.com 740 users
-
#14
msn.com 731 users
-
#15
mail.com 706 users
-
#16
hotmail.it 672 users
-
#17
free.fr 623 users
-
#18
libero.it 534 users
-
#19
hotmail.es 528 users
-
#20
comcast.net 517 users
-
#21
t-online.de 439 users
-
#22
hotmail.co.uk 408 users
-
#23
live.fr 405 users
-
#24
yahoo.co.id 377 users
-
#25
proton.me 373 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 10,988machines
- #2 Lumma 3,762machines
- #3 Vidar 877machines
- #4 Acreed 86machines
- #5 RedLine 3machines
Anti-virus Coverage
- #1 Windows Defender 5,078machines
- #2 Windows Defender. 324machines
- #3 Windows Defender, McAfee. 33machines
- #4 Windows Defender, Avast Antivirus. 28machines
- #5 McAfee, Windows Defender 16machines
- #6 N/A 16machines
- #7 McAfee Firewall 15machines
- #8 Windows Defender, McAfee 15machines
- #9 McAfee VirusScan 15machines
- #10 Windows Defender, ESET Security 13machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 47,788hits
- #2 sso 12,370hits
- #3 zoom 3,591hits
- #4 github 2,824hits
- #5 webmail 1,552hits
- #6 adfs 1,406hits
- #7 oracle 783hits
- #8 zendesk 607hits
- #9 sap 534hits
- #10 owa 529hits
- #11 ping 520hits
- #12 sts 377hits
- #13 okta 354hits
- #14 vpn 345hits
- #15 cpanel 301hits
- #16 webex 295hits
- #17 salesforce 293hits
- #18 ftp 215hits
- #19 kaspersky 214hits
- #20 extranet 207hits
- #21 st 201hits
- #22 roundcube 174hits
- #23 twilio 129hits
- #24 gitlab 108hits
- #25 imap 93hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.