Infostealers Weekly Report: 2026-02-02 – 2026-02-09
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 950
- #2 Brazil 642
- #3 United States of America 438
- #4 Indonesia 370
- #5 Philippines 337
- #6 Vietnam 240
- #7 Bangladesh 223
- #8 Pakistan 210
- #9 Turkey 155
- #10 Argentina 154
- #11 Egypt 126
- #12 Mexico 126
- #13 France 118
- #14 Colombia 116
- #15 Germany 116
- #16 Poland 110
- #17 Morocco 105
- #18 United Kingdom 100
- #19 Thailand 94
- #20 Spain 90
- #21 Chile 89
- #22 Italy 77
- #23 South Africa 76
- #24 Peru 72
- #25 Algeria 72
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 17,456 users
-
#2
facebook.com 13,110 users
-
#3
live.com 12,195 users
-
#4
discord.com 10,128 users
-
#5
roblox.com 9,974 users
-
#6
instagram.com 8,717 users
-
#7
netflix.com 6,973 users
-
#8
steampowered.com 6,926 users
-
#9
com.facebook.katana 6,838 users
-
#10
twitch.tv 5,659 users
-
#11
amazon.com 5,518 users
-
#12
com.roblox.client 5,322 users
-
#13
com.instagram.android 5,202 users
-
#14
epicgames.com 5,143 users
-
#15
riotgames.com 4,904 users
-
#16
apple.com 4,790 users
-
#17
paypal.com 4,689 users
-
#18
spotify.com 4,641 users
-
#19
microsoftonline.com 4,586 users
-
#20
steamcommunity.com 4,419 users
-
#21
com.netflix.mediaclient 4,362 users
-
#22
com.discord 4,107 users
-
#23
twitter.com 3,864 users
-
#24
nexusmods.com 3,249 users
-
#25
rockstargames.com 3,197 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
firstmail.ltd 156 employees
-
#2
hostinger.com 105 employees
-
#3
wp.pl 83 employees
-
#4
icicibank.com 55 employees
-
#5
zsthost.com 49 employees
-
#6
163.com 48 employees
-
#7
rediff.com 46 employees
-
#8
qq.com 40 employees
-
#9
mail.tm 39 employees
-
#10
aruba.it 38 employees
-
#11
o2.pl 29 employees
-
#12
abv.bg 25 employees
-
#13
netpnb.com 25 employees
-
#14
santander.com.br 25 employees
-
#15
rmunify.com 25 employees
-
#16
interia.pl 24 employees
-
#17
sempreser.com.br 23 employees
-
#18
concentrix.com 22 employees
-
#19
pec.it 22 employees
-
#20
onet.pl 21 employees
-
#21
seznam.cz 21 employees
-
#22
deped.gov.ph 20 employees
-
#23
naver.com 20 employees
-
#24
indusind.com 19 employees
-
#25
det.nsw.edu.au 19 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 10 employees
-
#2
ups.com 8 employees
-
#3
publix.com 7 employees
-
#4
netflix.com 5 employees
-
#5
apple.com 5 employees
-
#6
rockwellautomation.com 4 employees
-
#7
amazon.com 3 employees
-
#8
jpmorganchase.com 3 employees
-
#9
twc.com 3 employees
-
#10
att.com 3 employees
-
#11
verizon.com 2 employees
-
#12
mutualofomaha.com 2 employees
-
#13
salesforce.com 2 employees
-
#14
intel.com 2 employees
-
#15
hp.com 2 employees
-
#16
allstate.com 2 employees
-
#17
cognizant.com 2 employees
-
#18
csc.com 1 employees
-
#19
centurylink.com 1 employees
-
#20
xerox.com 1 employees
Compromised users
-
#1
google.com 17,456 users
-
#2
facebook.com 13,110 users
-
#3
netflix.com 6,973 users
-
#4
amazon.com 5,518 users
-
#5
apple.com 4,790 users
-
#6
paypal.com 4,689 users
-
#7
ebay.com 726 users
-
#8
hp.com 661 users
-
#9
nike.com 605 users
-
#10
oracle.com 603 users
-
#11
walmart.com 488 users
-
#12
microsoft.com 453 users
-
#13
ups.com 279 users
-
#14
cisco.com 271 users
-
#15
bestbuy.com 245 users
-
#16
adp.com 233 users
-
#17
target.com 220 users
-
#18
capitalone.com 196 users
-
#19
disney.com 191 users
-
#20
ibm.com 182 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
6,838 users
Roblox
5,322 users
5,202 users
Netflix
4,362 users
Discord
4,107 users
Spotify
3,048 users
Twitch
2,978 users
2,277 users
Snapchat
2,237 users
1,752 users
PayPal
1,331 users
Disney
1,206 users
Wish
1,182 users
Mega
1,079 users
Xiaomi
891 users
Zoom
797 users
635 users
Mercadolibre
505 users
Waze
478 users
Alibaba
450 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 747,015 users
-
#2
hotmail.com 55,878 users
-
#3
yahoo.com 23,760 users
-
#4
outlook.com 18,229 users
-
#5
icloud.com 8,444 users
-
#6
live.com 3,484 users
-
#7
hotmail.fr 2,782 users
-
#8
yahoo.com.br 2,039 users
-
#9
msn.com 1,660 users
-
#10
gmx.de 1,431 users
-
#11
live.fr 1,335 users
-
#12
aol.com 1,257 users
-
#13
web.de 1,069 users
-
#14
hotmail.it 1,047 users
-
#15
libero.it 994 users
-
#16
yahoo.fr 908 users
-
#17
hotmail.co.uk 884 users
-
#18
yahoo.co.uk 799 users
-
#19
orange.fr 778 users
-
#20
hotmail.de 773 users
-
#21
proton.me 699 users
-
#22
protonmail.com 694 users
-
#23
yahoo.co.id 690 users
-
#24
mail.com 683 users
-
#25
free.fr 669 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 22,903machines
- #2 Acreed 3,389machines
- #3 Vidar 601machines
Anti-virus Coverage
- #1 Windows Defender 2,781machines
- #2 No anti-virus installed 1,177machines
- #3 McAfee VirusScan 5machines
- #4 McAfee 4machines
- #5 McAfee Firewall 4machines
- #6 Webroot SecureAnywhere 2machines
- #7 Avira Security 2machines
- #8 Norton Security Ultra 1machines
- #9 Avira Antivirus 1machines
- #10 Pare-feu McAfee 1machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 89,878hits
- #2 sso 21,766hits
- #3 github 4,876hits
- #4 zoom 4,468hits
- #5 adfs 2,876hits
- #6 webmail 1,887hits
- #7 zendesk 1,381hits
- #8 oracle 1,192hits
- #9 sap 848hits
- #10 ping 845hits
- #11 vpn 828hits
- #12 sts 719hits
- #13 okta 503hits
- #14 owa 499hits
- #15 cpanel 489hits
- #16 st 448hits
- #17 kaspersky 368hits
- #18 ftp 291hits
- #19 webex 254hits
- #20 salesforce 252hits
- #21 extranet 243hits
- #22 roundcube 230hits
- #23 twilio 212hits
- #24 gitlab 172hits
- #25 imap 138hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.