Infostealers Weekly Report: 2025-11-24 – 2025-12-01
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,505
- #2 Egypt 2,291
- #3 Brazil 1,740
- #4 Indonesia 1,608
- #5 Bangladesh 1,558
- #6 United States of America 945
- #7 Algeria 932
- #8 France 642
- #9 Spain 520
- #10 Germany 490
- #11 Colombia 480
- #12 Argentina 455
- #13 Canada 407
- #14 United Kingdom 362
- #15 Philippines 327
- #16 China 285
- #17 Pakistan 268
- #18 Chile 258
- #19 Vietnam 195
- #20 Hungary 187
- #21 Unknown Region 186
- #22 Ecuador 176
- #23 Australia 174
- #24 United Arab Emirates 172
- #25 Mexico 160
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
facebook.com 29,822 users
-
#2
google.com 29,097 users
-
#3
live.com 21,133 users
-
#4
instagram.com 15,841 users
-
#5
com.facebook.katana 15,760 users
-
#6
netflix.com 11,938 users
-
#7
com.instagram.android 10,847 users
-
#8
amazon.com 10,424 users
-
#9
discord.com 10,323 users
-
#10
com.netflix.mediaclient 8,550 users
-
#11
paypal.com 8,372 users
-
#12
twitter.com 8,343 users
-
#13
steampowered.com 7,518 users
-
#14
linkedin.com 7,465 users
-
#15
apple.com 7,355 users
-
#16
roblox.com 6,915 users
-
#17
openai.com 6,320 users
-
#18
192.168.1.1 6,243 users
-
#19
com.pinterest 6,198 users
-
#20
com.discord 5,958 users
-
#21
twitch.tv 5,910 users
-
#22
github.com 5,714 users
-
#23
yahoo.com 5,553 users
-
#24
microsoftonline.com 5,461 users
-
#25
com.roblox.client 5,317 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 213 employees
-
#2
hostinger.com 178 employees
-
#3
watchit.com 130 employees
-
#4
163.com 114 employees
-
#5
buenosaires.gob.ar 95 employees
-
#6
freemail.hu 90 employees
-
#7
rediff.com 89 employees
-
#8
santander.com.br 83 employees
-
#9
qq.com 81 employees
-
#10
firstmail.ltd 79 employees
-
#11
secop.gov.co 76 employees
-
#12
banquemisr.com 76 employees
-
#13
abv.bg 69 employees
-
#14
seznam.cz 63 employees
-
#15
atlassian.com 60 employees
-
#16
unionbankonline.co.in 58 employees
-
#17
netpnb.com 56 employees
-
#18
bni.co.id 55 employees
-
#19
icai.org 54 employees
-
#20
skole.hr 53 employees
-
#21
aruba.it 52 employees
-
#22
bobibanking.com 49 employees
-
#23
wp.pl 47 employees
-
#24
login.sp.gov.br 47 employees
-
#25
payoneer.com 46 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 22 employees
-
#2
rockwellautomation.com 16 employees
-
#3
ibm.com 12 employees
-
#4
cognizant.com 6 employees
-
#5
salesforce.com 6 employees
-
#6
amazon.com 5 employees
-
#7
ups.com 5 employees
-
#8
hp.com 5 employees
-
#9
netflix.com 4 employees
-
#10
honeywell.com 4 employees
-
#11
adp.com 3 employees
-
#12
publix.com 3 employees
-
#13
csc.com 3 employees
-
#14
facebook.com 3 employees
-
#15
cisco.com 3 employees
-
#16
google.com 2 employees
-
#17
twc.com 2 employees
-
#18
johndeere.com 2 employees
-
#19
oracle.com 2 employees
-
#20
staples.com 2 employees
Compromised users
-
#1
facebook.com 29,822 users
-
#2
google.com 29,097 users
-
#3
netflix.com 11,938 users
-
#4
amazon.com 10,424 users
-
#5
paypal.com 8,372 users
-
#6
apple.com 7,355 users
-
#7
ebay.com 1,416 users
-
#8
hp.com 1,346 users
-
#9
oracle.com 1,338 users
-
#10
microsoft.com 1,056 users
-
#11
nike.com 856 users
-
#12
cisco.com 755 users
-
#13
ibm.com 519 users
-
#14
ups.com 488 users
-
#15
walmart.com 401 users
-
#16
westernunion.com 311 users
-
#17
broadcom.com 244 users
-
#18
adp.com 238 users
-
#19
fedex.com 221 users
-
#20
intel.com 212 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
15,760 users
10,847 users
Netflix
8,550 users
6,198 users
Discord
5,958 users
Roblox
5,317 users
Snapchat
4,632 users
4,381 users
Spotify
4,355 users
Twitch
3,955 users
Wish
2,867 users
Zoom
2,615 users
PayPal
2,429 users
2,247 users
Mega
2,048 users
Xiaomi
2,033 users
Disney
2,020 users
Mercadolibre
1,471 users
Waze
1,293 users
Alibaba
1,244 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 1,597,575 users
-
#2
hotmail.com 164,486 users
-
#3
yahoo.com 62,451 users
-
#4
outlook.com 37,692 users
-
#5
hotmail.fr 11,221 users
-
#6
icloud.com 11,147 users
-
#7
live.com 6,426 users
-
#8
yahoo.fr 6,377 users
-
#9
yahoo.com.br 6,257 users
-
#10
free.fr 4,961 users
-
#11
orange.fr 4,760 users
-
#12
web.de 4,728 users
-
#13
gmx.de 3,928 users
-
#14
msn.com 3,798 users
-
#15
aol.com 3,698 users
-
#16
yahoo.co.id 3,604 users
-
#17
hotmail.es 3,522 users
-
#18
ymail.com 3,453 users
-
#19
live.fr 3,319 users
-
#20
googlemail.com 2,957 users
-
#21
hotmail.co.uk 2,806 users
-
#22
mail.com 2,612 users
-
#23
mail.ru 2,141 users
-
#24
laposte.net 1,947 users
-
#25
yahoo.com.ar 1,744 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 25,137machines
- #2 Acreed 16,389machines
- #3 Lumma 1,146machines
- #4 Vidar 128machines
Anti-virus Coverage
- #1 Windows Defender 5,298machines
- #2 No anti-virus installed 1,529machines
- #3 Windows Defender. 9machines
- #4 None 2machines
- #5 Norton Security Ultra 2machines
- #6 Reason Cybersecurity, Windows Defender 2machines
- #7 Windows Defender, Avast Antivirus. 2machines
- #8 Windows Defender, Norton Security Ultra 1machines
- #9 Windows Defender, Quick Heal Total Security 1machines
- #10 Windows Defender, McAfee. 1machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 180,514hits
- #2 sso 47,925hits
- #3 zoom 12,906hits
- #4 github 10,490hits
- #5 webmail 3,602hits
- #6 oracle 3,122hits
- #7 adfs 2,772hits
- #8 sap 2,389hits
- #9 zendesk 2,290hits
- #10 ping 1,994hits
- #11 vpn 1,870hits
- #12 cpanel 1,647hits
- #13 sts 1,327hits
- #14 owa 1,207hits
- #15 st 976hits
- #16 kaspersky 955hits
- #17 salesforce 892hits
- #18 imap 876hits
- #19 webex 874hits
- #20 extranet 832hits
- #21 ftp 663hits
- #22 webvpn 651hits
- #23 okta 534hits
- #24 twilio 518hits
- #25 roundcube 496hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.