Skip to content
Weekly intelligence Nov 24 – Dec 1, 2025 14 min read

Infostealers Weekly Report: 2025-11-24 – 2025-12-01

InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.

#1 42,800 Compromised Machines
#2 9,331 Compromised Employees
#3 6,447 Compromised Users
#4 27,022 Compromised Androids
#5 513,120 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 186
Infections by country

Top 25 countries

  1. #1 India 2,505
  2. #2 Egypt 2,291
  3. #3 Brazil 1,740
  4. #4 Indonesia 1,608
  5. #5 Bangladesh 1,558
  6. #6 United States of America 945
  7. #7 Algeria 932
  8. #8 France 642
  9. #9 Spain 520
  10. #10 Germany 490
  11. #11 Colombia 480
  12. #12 Argentina 455
  13. #13 Canada 407
  14. #14 United Kingdom 362
  15. #15 Philippines 327
  16. #16 China 285
  17. #17 Pakistan 268
  18. #18 Chile 258
  19. #19 Vietnam 195
  20. #20 Hungary 187
  21. #21 Unknown Region 186
  22. #22 Ecuador 176
  23. #23 Australia 174
  24. #24 United Arab Emirates 172
  25. #25 Mexico 160

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 facebook.com 29,822 users
  2. #2 google.com 29,097 users
  3. #3 live.com 21,133 users
  4. #4 instagram.com 15,841 users
  5. #5 com.facebook.katana 15,760 users
  6. #6 netflix.com 11,938 users
  7. #7 com.instagram.android 10,847 users
  8. #8 amazon.com 10,424 users
  9. #9 discord.com 10,323 users
  10. #10 com.netflix.mediaclient 8,550 users
  11. #11 paypal.com 8,372 users
  12. #12 twitter.com 8,343 users
  13. #13 steampowered.com 7,518 users
  14. #14 linkedin.com 7,465 users
  15. #15 apple.com 7,355 users
  16. #16 roblox.com 6,915 users
  17. #17 openai.com 6,320 users
  18. #18 192.168.1.1 6,243 users
  19. #19 com.pinterest 6,198 users
  20. #20 com.discord 5,958 users
  21. #21 twitch.tv 5,910 users
  22. #22 github.com 5,714 users
  23. #23 yahoo.com 5,553 users
  24. #24 microsoftonline.com 5,461 users
  25. #25 com.roblox.client 5,317 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 icicibank.com 213 employees
  2. #2 hostinger.com 178 employees
  3. #3 watchit.com 130 employees
  4. #4 163.com 114 employees
  5. #5 buenosaires.gob.ar 95 employees
  6. #6 freemail.hu 90 employees
  7. #7 rediff.com 89 employees
  8. #8 santander.com.br 83 employees
  9. #9 qq.com 81 employees
  10. #10 firstmail.ltd 79 employees
  11. #11 secop.gov.co 76 employees
  12. #12 banquemisr.com 76 employees
  13. #13 abv.bg 69 employees
  14. #14 seznam.cz 63 employees
  15. #15 atlassian.com 60 employees
  16. #16 unionbankonline.co.in 58 employees
  17. #17 netpnb.com 56 employees
  18. #18 bni.co.id 55 employees
  19. #19 icai.org 54 employees
  20. #20 skole.hr 53 employees
  21. #21 aruba.it 52 employees
  22. #22 bobibanking.com 49 employees
  23. #23 wp.pl 47 employees
  24. #24 login.sp.gov.br 47 employees
  25. #25 payoneer.com 46 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 microsoft.com 22 employees
  2. #2 rockwellautomation.com 16 employees
  3. #3 ibm.com 12 employees
  4. #4 cognizant.com 6 employees
  5. #5 salesforce.com 6 employees
  6. #6 amazon.com 5 employees
  7. #7 ups.com 5 employees
  8. #8 hp.com 5 employees
  9. #9 netflix.com 4 employees
  10. #10 honeywell.com 4 employees
  11. #11 adp.com 3 employees
  12. #12 publix.com 3 employees
  13. #13 csc.com 3 employees
  14. #14 facebook.com 3 employees
  15. #15 cisco.com 3 employees
  16. #16 google.com 2 employees
  17. #17 twc.com 2 employees
  18. #18 johndeere.com 2 employees
  19. #19 oracle.com 2 employees
  20. #20 staples.com 2 employees

Compromised users

  1. #1 facebook.com 29,822 users
  2. #2 google.com 29,097 users
  3. #3 netflix.com 11,938 users
  4. #4 amazon.com 10,424 users
  5. #5 paypal.com 8,372 users
  6. #6 apple.com 7,355 users
  7. #7 ebay.com 1,416 users
  8. #8 hp.com 1,346 users
  9. #9 oracle.com 1,338 users
  10. #10 microsoft.com 1,056 users
  11. #11 nike.com 856 users
  12. #12 cisco.com 755 users
  13. #13 ibm.com 519 users
  14. #14 ups.com 488 users
  15. #15 walmart.com 401 users
  16. #16 westernunion.com 311 users
  17. #17 broadcom.com 244 users
  18. #18 adp.com 238 users
  19. #19 fedex.com 221 users
  20. #20 intel.com 212 users

Compromised Mobile Apps

Top Android apps found in infected caches

The Android applications most frequently found in infected device caches this week.

Top 20
#1

Facebook

facebook.com · com.facebook.katana

15,760 users

#2

Instagram

instagram.com · com.instagram.android

10,847 users

#3

Netflix

netflix.com · com.netflix.mediaclient

8,550 users

#4

Pinterest

pinterest.com · com.pinterest

6,198 users

#5

Discord

discord.com · com.discord

5,958 users

#6

Roblox

roblox.com · com.roblox.client

5,317 users

#7

Snapchat

snapchat.com · com.snapchat.android

4,632 users

#8

Twitter

twitter.com · com.twitter.android

4,381 users

#9

Spotify

spotify.com · com.spotify.music

4,355 users

#10

Twitch

app.com · tv.twitch.android.app

3,955 users

#11

Wish

contextlogic.com · com.contextlogic.wish

2,867 users

#12

Zoom

videomeetings.com · us.zoom.videomeetings

2,615 users

#13

PayPal

paypal.com · com.paypal.android.p2pmobile

2,429 users

#14

LinkedIn

linkedin.com · com.linkedin.android

2,247 users

#15

Mega

app.com · mega.privacy.android.app

2,048 users

#16

Xiaomi

xiaomi.com · com.xiaomi.account

2,033 users

#17

Disney

disney.com · com.disney.disneyplus

2,020 users

#18

Mercadolibre

mercadolibre.com · com.mercadolibre

1,471 users

#19

Waze

waze.com · com.waze

1,293 users

#20

Alibaba

alibaba.com · com.alibaba.aliexpresshd

1,244 users

Top Compromised Email Providers

Email domains tied to compromised credentials

Gmail, hotmail, and beyond — providers seen across this week's stealer logs.

Top 25
  1. #1 gmail.com 1,597,575 users
  2. #2 hotmail.com 164,486 users
  3. #3 yahoo.com 62,451 users
  4. #4 outlook.com 37,692 users
  5. #5 hotmail.fr 11,221 users
  6. #6 icloud.com 11,147 users
  7. #7 live.com 6,426 users
  8. #8 yahoo.fr 6,377 users
  9. #9 yahoo.com.br 6,257 users
  10. #10 free.fr 4,961 users
  11. #11 orange.fr 4,760 users
  12. #12 web.de 4,728 users
  13. #13 gmx.de 3,928 users
  14. #14 msn.com 3,798 users
  15. #15 aol.com 3,698 users
  16. #16 yahoo.co.id 3,604 users
  17. #17 hotmail.es 3,522 users
  18. #18 ymail.com 3,453 users
  19. #19 live.fr 3,319 users
  20. #20 googlemail.com 2,957 users
  21. #21 hotmail.co.uk 2,806 users
  22. #22 mail.com 2,612 users
  23. #23 mail.ru 2,141 users
  24. #24 laposte.net 1,947 users
  25. #25 yahoo.com.ar 1,744 users

Top Compromised Social Platforms

Where saved sessions and logins lived

Social media services where compromised accounts had stored sessions or saved logins.

Top 19
  1. #1 facebook.com 29,822 accounts
  2. #2 twitter.com 8,343 accounts
  3. #3 instagram.com 15,841 accounts
  4. #4 linkedin.com 7,465 accounts
  5. #5 pinterest.com 2,062 accounts
  6. #6 tiktok.com 3,234 accounts
  7. #7 snapchat.com 2,605 accounts
  8. #8 reddit.com 1,522 accounts
  9. #9 youtube.com 189 accounts
  10. #10 weibo.com 121 accounts
  11. #11 vk.com 1,361 accounts
  12. #12 telegram.org 187 accounts
  13. #13 tumblr.com 923 accounts
  14. #14 discord.com 10,323 accounts
  15. #15 flickr.com 502 accounts
  16. #16 myspace.com 102 accounts
  17. #17 badoo.com 285 accounts
  18. #18 meetup.com 78 accounts
  19. #19 quora.com 245 accounts

Malware Landscape

Stealer families & anti-virus coverage

Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.

Stealer Families

  1. #1 Generic Stealer 25,137machines
  2. #2 Acreed 16,389machines
  3. #3 Lumma 1,146machines
  4. #4 Vidar 128machines

Anti-virus Coverage

  1. #1 Windows Defender 5,298machines
  2. #2 No anti-virus installed 1,529machines
  3. #3 Windows Defender. 9machines
  4. #4 None 2machines
  5. #5 Norton Security Ultra 2machines
  6. #6 Reason Cybersecurity, Windows Defender 2machines
  7. #7 Windows Defender, Avast Antivirus. 2machines
  8. #8 Windows Defender, Norton Security Ultra 1machines
  9. #9 Windows Defender, Quick Heal Total Security 1machines
  10. #10 Windows Defender, McAfee. 1machines

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 180,514hits
  2. #2 sso 47,925hits
  3. #3 zoom 12,906hits
  4. #4 github 10,490hits
  5. #5 webmail 3,602hits
  6. #6 oracle 3,122hits
  7. #7 adfs 2,772hits
  8. #8 sap 2,389hits
  9. #9 zendesk 2,290hits
  10. #10 ping 1,994hits
  11. #11 vpn 1,870hits
  12. #12 cpanel 1,647hits
  13. #13 sts 1,327hits
  14. #14 owa 1,207hits
  15. #15 st 976hits
  16. #16 kaspersky 955hits
  17. #17 salesforce 892hits
  18. #18 imap 876hits
  19. #19 webex 874hits
  20. #20 extranet 832hits
  21. #21 ftp 663hits
  22. #22 webvpn 651hits
  23. #23 okta 534hits
  24. #24 twilio 518hits
  25. #25 roundcube 496hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure