Infostealers Weekly Report: 2025-12-01 – 2025-12-08
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 3,824
- #2 Vietnam 738
- #3 Philippines 722
- #4 Indonesia 655
- #5 Brazil 599
- #6 Egypt 596
- #7 United States of America 590
- #8 Bangladesh 458
- #9 Mexico 371
- #10 Colombia 338
- #11 Peru 304
- #12 Pakistan 298
- #13 Algeria 257
- #14 Morocco 250
- #15 China 237
- #16 Argentina 210
- #17 Thailand 208
- #18 Spain 197
- #19 France 192
- #20 South Korea 165
- #21 Unknown Region 151
- #22 Italy 148
- #23 Poland 142
- #24 South Africa 141
- #25 Ghana 134
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 21,139 users
-
#2
facebook.com 18,423 users
-
#3
live.com 16,047 users
-
#4
instagram.com 12,864 users
-
#5
com.facebook.katana 11,751 users
-
#6
netflix.com 10,702 users
-
#7
com.instagram.android 10,022 users
-
#8
discord.com 9,734 users
-
#9
amazon.com 9,519 users
-
#10
com.netflix.mediaclient 8,486 users
-
#11
microsoftonline.com 8,406 users
-
#12
roblox.com 7,973 users
-
#13
paypal.com 7,787 users
-
#14
linkedin.com 7,585 users
-
#15
twitter.com 7,533 users
-
#16
apple.com 7,416 users
-
#17
steampowered.com 7,369 users
-
#18
openai.com 7,215 users
-
#19
spotify.com 6,693 users
-
#20
zoom.us 6,445 users
-
#21
twitch.tv 6,253 users
-
#22
com.discord 6,052 users
-
#23
com.roblox.client 6,018 users
-
#24
github.com 5,995 users
-
#25
yahoo.com 5,753 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
aruba.it 1,125 employees
-
#2
hostinger.com 952 employees
-
#3
icicibank.com 603 employees
-
#4
pec.it 419 employees
-
#5
rediff.com 393 employees
-
#6
naver.com 386 employees
-
#7
163.com 331 employees
-
#8
infocert.it 310 employees
-
#9
upc.edu.pe 289 employees
-
#10
firstmail.ltd 280 employees
-
#11
falabella.tech 272 employees
-
#12
markinfo.co.kr 267 employees
-
#13
bobibanking.com 256 employees
-
#14
maccabi4u.co.il 253 employees
-
#15
tls.edu.pe 250 employees
-
#16
atlassian.com 249 employees
-
#17
buenosaires.gob.ar 245 employees
-
#18
kakao.com 235 employees
-
#19
lolipop.jp 223 employees
-
#20
nate.com 217 employees
-
#21
tim.it 210 employees
-
#22
hinet.net 199 employees
-
#23
secop.gov.co 199 employees
-
#24
web-hosting.com 199 employees
-
#25
treknp.com 189 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
hp.com 168 employees
-
#2
twc.com 99 employees
-
#3
ford.com 59 employees
-
#4
publix.com 53 employees
-
#5
microsoft.com 51 employees
-
#6
mutualofomaha.com 40 employees
-
#7
salesforce.com 26 employees
-
#8
ibm.com 15 employees
-
#9
paypal.com 11 employees
-
#10
rockwellautomation.com 11 employees
-
#11
viacom.com 10 employees
-
#12
netflix.com 7 employees
-
#13
cognizant.com 6 employees
-
#14
jpmorganchase.com 6 employees
-
#15
google.com 5 employees
-
#16
fedex.com 3 employees
-
#17
johnsoncontrols.com 3 employees
-
#18
facebook.com 3 employees
-
#19
firstam.com 3 employees
-
#20
ingredion.com 3 employees
Compromised users
-
#1
google.com 21,139 users
-
#2
facebook.com 18,423 users
-
#3
netflix.com 10,702 users
-
#4
amazon.com 9,519 users
-
#5
paypal.com 7,787 users
-
#6
apple.com 7,416 users
-
#7
ebay.com 3,108 users
-
#8
hp.com 2,885 users
-
#9
oracle.com 2,481 users
-
#10
microsoft.com 2,240 users
-
#11
nike.com 2,217 users
-
#12
walmart.com 1,634 users
-
#13
ups.com 1,484 users
-
#14
cisco.com 1,473 users
-
#15
ibm.com 1,468 users
-
#16
fedex.com 1,133 users
-
#17
salesforce.com 893 users
-
#18
att.com 740 users
-
#19
westernunion.com 728 users
-
#20
capitalone.com 582 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
11,751 users
10,022 users
Netflix
8,486 users
Discord
6,052 users
Roblox
6,018 users
Spotify
5,739 users
Snapchat
5,394 users
5,200 users
4,723 users
Twitch
4,219 users
Zoom
3,555 users
3,109 users
Wish
3,024 users
PayPal
2,939 users
Xiaomi
2,817 users
Disney
2,620 users
Mega
2,365 users
Waze
2,001 users
Alibaba
1,760 users
Mercadolibre
1,671 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 3,982,236 users
-
#2
hotmail.com 385,931 users
-
#3
yahoo.com 150,284 users
-
#4
outlook.com 92,372 users
-
#5
mail.ru 36,762 users
-
#6
sky.com 27,690 users
-
#7
live.com 21,288 users
-
#8
hotmail.fr 19,930 users
-
#9
icloud.com 18,537 users
-
#10
mail.com 12,638 users
-
#11
aol.com 10,947 users
-
#12
orange.fr 10,307 users
-
#13
libero.it 9,823 users
-
#14
hotmail.es 9,349 users
-
#15
verizon.net 9,263 users
-
#16
yahoo.fr 8,876 users
-
#17
msn.com 8,225 users
-
#18
wanadoo.fr 7,783 users
-
#19
live.com.mx 6,809 users
-
#20
yahoo.com.ar 5,960 users
-
#21
yahoo.com.br 5,597 users
-
#22
yahoo.co.jp 5,279 users
-
#23
hanmail.net 4,543 users
-
#24
yandex.ru 4,220 users
-
#25
gmx.de 3,616 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 22,326machines
- #2 Acreed 3,023machines
- #3 Vidar 2,085machines
- #4 Lumma 1,601machines
Anti-virus Coverage
- #1 Windows Defender 6,797machines
- #2 Windows Defender. 433machines
- #3 No anti-virus installed 318machines
- #4 Windows Defender, Avast Antivirus. 45machines
- #5 N/A 34machines
- #6 Windows Defender, McAfee. 32machines
- #7 McAfee, Windows Defender 15machines
- #8 Windows Defender, 360 Total Security. 15machines
- #9 Windows Defender, ESET Security 13machines
- #10 Windows Defender, 알약 8machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 508,253hits
- #2 sso 135,356hits
- #3 zoom 43,668hits
- #4 github 20,722hits
- #5 webmail 18,989hits
- #6 adfs 9,169hits
- #7 oracle 8,247hits
- #8 zendesk 8,073hits
- #9 ping 6,047hits
- #10 owa 5,549hits
- #11 salesforce 4,677hits
- #12 sap 4,452hits
- #13 cpanel 4,000hits
- #14 sts 3,620hits
- #15 imap 3,528hits
- #16 webex 3,327hits
- #17 extranet 3,294hits
- #18 vpn 2,907hits
- #19 kaspersky 2,647hits
- #20 roundcube 2,565hits
- #21 okta 1,781hits
- #22 gitlab 1,751hits
- #23 ftp 1,705hits
- #24 st 1,418hits
- #25 twilio 1,340hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.