Infostealers Weekly Report: 2026-02-16 – 2026-02-23
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,077
- #2 United States of America 352
- #3 Indonesia 201
- #4 Italy 178
- #5 Brazil 177
- #6 Pakistan 176
- #7 Bangladesh 150
- #8 Mexico 138
- #9 Philippines 136
- #10 Spain 128
- #11 United Kingdom 113
- #12 Egypt 100
- #13 France 97
- #14 Nepal 95
- #15 Germany 83
- #16 Vietnam 79
- #17 Turkey 69
- #18 Canada 68
- #19 Morocco 65
- #20 South Africa 64
- #21 Sri Lanka 61
- #22 United Arab Emirates 61
- #23 Thailand 60
- #24 Argentina 55
- #25 Colombia 55
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,718 users
-
#2
facebook.com 4,349 users
-
#3
live.com 3,392 users
-
#4
instagram.com 3,032 users
-
#5
apple.com 2,861 users
-
#6
netflix.com 2,508 users
-
#7
amazon.com 2,359 users
-
#8
com.facebook.katana 2,283 users
-
#9
com.instagram.android 2,004 users
-
#10
discord.com 1,801 users
-
#11
paypal.com 1,798 users
-
#12
microsoftonline.com 1,791 users
-
#13
linkedin.com 1,699 users
-
#14
twitter.com 1,542 users
-
#15
com.netflix.mediaclient 1,538 users
-
#16
spotify.com 1,401 users
-
#17
github.com 1,334 users
-
#18
openai.com 1,329 users
-
#19
adobe.com 1,312 users
-
#20
mega.nz 1,196 users
-
#21
192.168.1.1 1,181 users
-
#22
zoom.us 1,052 users
-
#23
steampowered.com 1,006 users
-
#24
com.snapchat.android 969 users
-
#25
roblox.com 927 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 149 employees
-
#2
icicibank.com 56 employees
-
#3
aruba.it 46 employees
-
#4
secureserver.net 27 employees
-
#5
rediff.com 26 employees
-
#6
qq.com 26 employees
-
#7
163.com 25 employees
-
#8
bobibanking.com 24 employees
-
#9
atlassian.com 22 employees
-
#10
pec.it 21 employees
-
#11
unibo.it 20 employees
-
#12
njoyn.com 19 employees
-
#13
payoneer.com 18 employees
-
#14
bluehost.com 18 employees
-
#15
netpnb.com 15 employees
-
#16
ovh.net 15 employees
-
#17
ionos.com 15 employees
-
#18
buenosaires.gob.ar 15 employees
-
#19
tim.it 14 employees
-
#20
unionbankonline.co.in 14 employees
-
#21
web-hosting.com 14 employees
-
#22
pnbibanking.in 13 employees
-
#23
fednetbank.com 13 employees
-
#24
mail.tm 12 employees
-
#25
one.com 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 11 employees
-
#2
ups.com 4 employees
-
#3
apple.com 4 employees
-
#4
oracle.com 3 employees
-
#5
salesforce.com 3 employees
-
#6
csc.com 3 employees
-
#7
halliburton.com 2 employees
-
#8
intel.com 2 employees
-
#9
paypal.com 2 employees
-
#10
google.com 2 employees
-
#11
ibm.com 2 employees
-
#12
publix.com 2 employees
-
#13
bestbuy.com 2 employees
-
#14
hp.com 1 employees
-
#15
lamresearch.com 1 employees
-
#16
baxter.com 1 employees
-
#17
interpublic.com 1 employees
-
#18
omnicomgroup.com 1 employees
-
#19
synnex.com 1 employees
-
#20
sonicautomotive.com 1 employees
Compromised users
-
#1
google.com 4,718 users
-
#2
facebook.com 4,349 users
-
#3
apple.com 2,861 users
-
#4
netflix.com 2,508 users
-
#5
amazon.com 2,359 users
-
#6
paypal.com 1,798 users
-
#7
ebay.com 429 users
-
#8
oracle.com 331 users
-
#9
nike.com 308 users
-
#10
microsoft.com 253 users
-
#11
hp.com 238 users
-
#12
walmart.com 177 users
-
#13
ups.com 176 users
-
#14
cisco.com 157 users
-
#15
broadcom.com 135 users
-
#16
ibm.com 133 users
-
#17
fedex.com 115 users
-
#18
target.com 94 users
-
#19
westernunion.com 94 users
-
#20
adp.com 91 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
2,283 users
2,004 users
Netflix
1,538 users
Snapchat
969 users
Spotify
898 users
Discord
781 users
742 users
Roblox
614 users
PayPal
458 users
452 users
Twitch
446 users
430 users
Zoom
384 users
Xiaomi
340 users
Mega
335 users
Wish
285 users
Disney
275 users
Alibaba
211 users
Waze
166 users
Mercadolibre
129 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 322,020 users
-
#2
hotmail.com 21,512 users
-
#3
outlook.com 10,698 users
-
#4
yahoo.com 9,300 users
-
#5
icloud.com 4,685 users
-
#6
hotmail.co.uk 1,282 users
-
#7
live.com 1,084 users
-
#8
libero.it 849 users
-
#9
me.com 801 users
-
#10
yahoo.fr 727 users
-
#11
mail.ru 717 users
-
#12
gmx.de 629 users
-
#13
aol.com 607 users
-
#14
msn.com 594 users
-
#15
web.de 585 users
-
#16
mac.com 519 users
-
#17
mail.com 516 users
-
#18
telenet.be 508 users
-
#19
hotmail.fr 504 users
-
#20
live.co.uk 474 users
-
#21
hotmail.it 457 users
-
#22
yahoo.co.uk 456 users
-
#23
ymail.com 451 users
-
#24
yandex.ru 405 users
-
#25
protonmail.com 329 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 6,420machines
- #2 Vidar 1,706machines
- #3 Lumma 389machines
- #4 Acreed 106machines
Anti-virus Coverage
- #1 Windows Defender 2,720machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 37,546hits
- #2 sso 9,158hits
- #3 github 2,530hits
- #4 zoom 2,470hits
- #5 webmail 1,365hits
- #6 adfs 1,141hits
- #7 oracle 758hits
- #8 ftp 545hits
- #9 cpanel 512hits
- #10 zendesk 475hits
- #11 sap 458hits
- #12 vpn 346hits
- #13 ping 332hits
- #14 sts 324hits
- #15 salesforce 297hits
- #16 gitlab 296hits
- #17 owa 294hits
- #18 okta 253hits
- #19 roundcube 215hits
- #20 twilio 201hits
- #21 extranet 173hits
- #22 webex 168hits
- #23 st 161hits
- #24 kaspersky 129hits
- #25 jira 95hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.