Infostealers Weekly Report: 2025-11-10 – 2025-11-17
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,306
- #2 Vietnam 270
- #3 Philippines 234
- #4 Egypt 231
- #5 Bangladesh 220
- #6 Pakistan 182
- #7 United States of America 175
- #8 Brazil 155
- #9 Mexico 126
- #10 Colombia 100
- #11 Indonesia 93
- #12 Peru 79
- #13 France 62
- #14 South Korea 59
- #15 Sri Lanka 57
- #16 Morocco 56
- #17 Tunisia 56
- #18 Argentina 55
- #19 Italy 54
- #20 Algeria 54
- #21 Nepal 50
- #22 Spain 49
- #23 Serbia 47
- #24 Iraq 45
- #25 Chile 42
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,003 users
-
#2
facebook.com 4,042 users
-
#3
live.com 3,363 users
-
#4
instagram.com 2,938 users
-
#5
com.facebook.katana 2,231 users
-
#6
netflix.com 2,043 users
-
#7
com.instagram.android 1,993 users
-
#8
amazon.com 1,794 users
-
#9
microsoftonline.com 1,626 users
-
#10
discord.com 1,533 users
-
#11
linkedin.com 1,404 users
-
#12
openai.com 1,396 users
-
#13
com.netflix.mediaclient 1,377 users
-
#14
paypal.com 1,259 users
-
#15
twitter.com 1,247 users
-
#16
apple.com 1,225 users
-
#17
amazon.in 1,079 users
-
#18
spotify.com 1,064 users
-
#19
roblox.com 1,032 users
-
#20
github.com 983 users
-
#21
zoom.us 941 users
-
#22
steampowered.com 937 users
-
#23
com.spotify.music 909 users
-
#24
yahoo.com 878 users
-
#25
com.snapchat.android 874 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 148 employees
-
#2
aruba.it 131 employees
-
#3
icicibank.com 107 employees
-
#4
pec.it 84 employees
-
#5
rediff.com 47 employees
-
#6
firstmail.ltd 46 employees
-
#7
maccabi4u.co.il 46 employees
-
#8
infocert.it 45 employees
-
#9
ovh.net 41 employees
-
#10
tim.it 38 employees
-
#11
icai.org 34 employees
-
#12
atlassian.com 29 employees
-
#13
eptv.com.br 27 employees
-
#14
locaweb.com.br 27 employees
-
#15
njoyn.com 26 employees
-
#16
ionos.it 26 employees
-
#17
unitn.it 26 employees
-
#18
lumosgaming.com 25 employees
-
#19
lerner.co.il 25 employees
-
#20
leadershipschool.com.pk 25 employees
-
#21
suretech.com 25 employees
-
#22
anchornyc.com 25 employees
-
#23
freeway.bet 25 employees
-
#24
covid19.cl 24 employees
-
#25
lacoipa.cl 24 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 12 employees
-
#2
netflix.com 11 employees
-
#3
cisco.com 5 employees
-
#4
salesforce.com 4 employees
-
#5
csc.com 2 employees
-
#6
adm.com 2 employees
-
#7
wm.com 2 employees
-
#8
verizon.com 2 employees
-
#9
amazon.com 2 employees
-
#10
hp.com 2 employees
-
#11
microsoft.com 2 employees
-
#12
jnj.com 1 employees
-
#13
walmart.com 1 employees
-
#14
mckesson.com 1 employees
-
#15
sempra.com 1 employees
-
#16
paypal.com 1 employees
-
#17
publix.com 1 employees
-
#18
frontier.com 1 employees
-
#19
lilly.com 1 employees
-
#20
jll.com 1 employees
Compromised users
-
#1
google.com 5,003 users
-
#2
facebook.com 4,042 users
-
#3
netflix.com 2,043 users
-
#4
amazon.com 1,794 users
-
#5
paypal.com 1,259 users
-
#6
apple.com 1,225 users
-
#7
hp.com 303 users
-
#8
oracle.com 285 users
-
#9
microsoft.com 277 users
-
#10
ebay.com 269 users
-
#11
nike.com 224 users
-
#12
ups.com 140 users
-
#13
cisco.com 137 users
-
#14
walmart.com 123 users
-
#15
ibm.com 121 users
-
#16
fedex.com 113 users
-
#17
westernunion.com 98 users
-
#18
salesforce.com 88 users
-
#19
marriott.com 67 users
-
#20
americanexpress.com 67 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
2,231 users
1,993 users
Netflix
1,377 users
Spotify
909 users
Snapchat
874 users
Discord
768 users
651 users
Roblox
620 users
573 users
499 users
Zoom
485 users
Twitch
451 users
PayPal
355 users
Wish
299 users
Mega
290 users
Xiaomi
268 users
Disney
257 users
Waze
207 users
Alibaba
190 users
Mercadolibre
161 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 406,203 users
-
#2
hotmail.com 33,411 users
-
#3
yahoo.com 13,223 users
-
#4
outlook.com 7,158 users
-
#5
hotmail.fr 6,595 users
-
#6
yahoo.co.jp 2,230 users
-
#7
icloud.com 2,227 users
-
#8
libero.it 2,097 users
-
#9
mail.ru 1,538 users
-
#10
mail.com 1,285 users
-
#11
aol.com 1,159 users
-
#12
orange.fr 1,112 users
-
#13
yahoo.fr 1,106 users
-
#14
sky.com 1,065 users
-
#15
wanadoo.fr 1,057 users
-
#16
yahoo.it 775 users
-
#17
msn.com 702 users
-
#18
yahoo.com.br 612 users
-
#19
live.com 575 users
-
#20
yandex.ru 468 users
-
#21
hotmail.es 409 users
-
#22
live.fr 398 users
-
#23
sfr.fr 397 users
-
#24
protonmail.com 391 users
-
#25
yahoo.ca 391 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 3,735machines
- #2 Vidar 2,208machines
- #3 Lumma 1,573machines
Anti-virus Coverage
- #1 Windows Defender 5,659machines
- #2 Windows Defender. 110machines
- #3 McAfee, Windows Defender 15machines
- #4 McAfee VirusScan, Windows Defender 14machines
- #5 N/A 13machines
- #6 Windows Defender, McAfee 10machines
- #7 Windows Defender, 360 Total Security. 9machines
- #8 Windows Defender, Avast Antivirus. 8machines
- #9 ESET Security, Windows Defender 6machines
- #10 Trend Micro Security Agent, Windows Defender 6machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 52,667hits
- #2 sso 12,861hits
- #3 zoom 4,830hits
- #4 github 2,493hits
- #5 webmail 2,261hits
- #6 adfs 1,117hits
- #7 imap 668hits
- #8 oracle 636hits
- #9 owa 572hits
- #10 zendesk 562hits
- #11 sap 529hits
- #12 ping 514hits
- #13 extranet 427hits
- #14 st 391hits
- #15 webex 329hits
- #16 cpanel 321hits
- #17 sts 321hits
- #18 kaspersky 316hits
- #19 roundcube 284hits
- #20 vpn 275hits
- #21 salesforce 262hits
- #22 git 197hits
- #23 okta 168hits
- #24 twilio 155hits
- #25 gitlab 139hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.