Infostealers Weekly Report: 2026-06-22 – 2026-06-29
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 7,124
- #2 Indonesia 1,208
- #3 Philippines 1,100
- #4 Egypt 896
- #5 Vietnam 795
- #6 France 758
- #7 Thailand 734
- #8 United States of America 610
- #9 Brazil 580
- #10 Mexico 528
- #11 United Kingdom 466
- #12 Spain 434
- #13 Pakistan 404
- #14 Colombia 364
- #15 Peru 357
- #16 Algeria 350
- #17 Poland 266
- #18 Bangladesh 238
- #19 Malaysia 224
- #20 Chile 220
- #21 South Africa 211
- #22 Germany 183
- #23 Morocco 163
- #24 Sri Lanka 160
- #25 Taiwan 159
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 21,294 users
-
#2
facebook.com 16,551 users
-
#3
live.com 13,061 users
-
#4
instagram.com 11,305 users
-
#5
com.facebook.katana 9,477 users
-
#6
com.instagram.android 8,316 users
-
#7
netflix.com 7,851 users
-
#8
amazon.com 7,332 users
-
#9
discord.com 7,191 users
-
#10
microsoftonline.com 5,762 users
-
#11
steampowered.com 5,758 users
-
#12
com.netflix.mediaclient 5,626 users
-
#13
roblox.com 5,100 users
-
#14
paypal.com 5,097 users
-
#15
apple.com 4,921 users
-
#16
twitter.com 4,749 users
-
#17
linkedin.com 4,412 users
-
#18
amazon.in 4,306 users
-
#19
openai.com 4,265 users
-
#20
com.spotify.music 4,251 users
-
#21
twitch.tv 4,141 users
-
#22
com.discord 4,035 users
-
#23
riotgames.com 4,005 users
-
#24
spotify.com 4,001 users
-
#25
com.snapchat.android 3,843 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
hostinger.com 208 employees
-
#2
icicibank.com 199 employees
-
#3
rediff.com 163 employees
-
#4
icai.org 102 employees
-
#5
netpnb.com 87 employees
-
#6
wp.pl 71 employees
-
#7
njoyn.com 56 employees
-
#8
bobibanking.com 56 employees
-
#9
unionbankonline.co.in 50 employees
-
#10
pnbibanking.in 49 employees
-
#11
firstmail.ltd 45 employees
-
#12
mail.gov.in 42 employees
-
#13
onlinesbi.sbi 36 employees
-
#14
aruba.it 35 employees
-
#15
thaimooc.ac.th 35 employees
-
#16
karnataka.gov.in 35 employees
-
#17
o2.pl 34 employees
-
#18
secureserver.net 34 employees
-
#19
fednetbank.com 34 employees
-
#20
rediffmailpro.com 33 employees
-
#21
confused.com 32 employees
-
#22
atlassian.com 32 employees
-
#23
pnb.bank.in 32 employees
-
#24
deped.gov.ph 31 employees
-
#25
ovh.net 31 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 21 employees
-
#2
salesforce.com 20 employees
-
#3
rockwellautomation.com 9 employees
-
#4
cognizant.com 8 employees
-
#5
ibm.com 7 employees
-
#6
netflix.com 6 employees
-
#7
hp.com 6 employees
-
#8
ups.com 5 employees
-
#9
bestbuy.com 4 employees
-
#10
oracle.com 3 employees
-
#11
honeywell.com 3 employees
-
#12
twc.com 2 employees
-
#13
gm.com 2 employees
-
#14
verizon.com 2 employees
-
#15
pepsico.com 2 employees
-
#16
borgwarner.com 2 employees
-
#17
cisco.com 2 employees
-
#18
publix.com 2 employees
-
#19
ajg.com 1 employees
-
#20
csx.com 1 employees
Compromised users
-
#1
google.com 21,294 users
-
#2
facebook.com 16,551 users
-
#3
netflix.com 7,851 users
-
#4
amazon.com 7,332 users
-
#5
paypal.com 5,097 users
-
#6
apple.com 4,921 users
-
#7
oracle.com 1,046 users
-
#8
hp.com 893 users
-
#9
ebay.com 878 users
-
#10
microsoft.com 694 users
-
#11
nike.com 655 users
-
#12
cisco.com 550 users
-
#13
ibm.com 437 users
-
#14
ups.com 392 users
-
#15
walmart.com 357 users
-
#16
broadcom.com 216 users
-
#17
salesforce.com 216 users
-
#18
fedex.com 214 users
-
#19
adp.com 208 users
-
#20
westernunion.com 174 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
9,477 users
8,316 users
Netflix
5,626 users
Spotify
4,251 users
Discord
4,035 users
Snapchat
3,843 users
3,737 users
Roblox
3,514 users
2,643 users
Twitch
2,469 users
Zoom
1,576 users
Wish
1,553 users
PayPal
1,541 users
Xiaomi
1,345 users
1,344 users
Mega
1,226 users
Disney
987 users
Alibaba
594 users
Waze
549 users
Mercadolibre
436 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 993,523 users
-
#2
hotmail.com 75,624 users
-
#3
yahoo.com 32,152 users
-
#4
outlook.com 17,731 users
-
#5
hotmail.fr 7,669 users
-
#6
icloud.com 5,772 users
-
#7
live.com 3,767 users
-
#8
hotmail.co.uk 3,379 users
-
#9
free.fr 3,024 users
-
#10
aol.com 2,319 users
-
#11
yahoo.fr 2,284 users
-
#12
orange.fr 2,133 users
-
#13
googlemail.com 2,116 users
-
#14
hotmail.es 2,116 users
-
#15
msn.com 2,029 users
-
#16
ymail.com 1,775 users
-
#17
yahoo.co.id 1,655 users
-
#18
live.fr 1,635 users
-
#19
gmx.de 1,566 users
-
#20
web.de 1,413 users
-
#21
yahoo.com.br 1,087 users
-
#22
libero.it 1,082 users
-
#23
protonmail.com 849 users
-
#24
mail.com 783 users
-
#25
laposte.net 780 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 15,416machines
- #2 Acreed 12,961machines
- #3 Lumma 1,042machines
Anti-virus Coverage
- #1 Windows Defender 11,692machines
- #2 None 1,450machines
- #3 Avast 99machines
- #4 Kaspersky 57machines
- #5 Malwarebytes 51machines
- #6 Avast, Norton 33machines
- #7 Avast, AVG 21machines
- #8 Avast, Malwarebytes 5machines
- #9 AVG 5machines
- #10 ESET 4machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 112,662hits
- #2 sso 29,991hits
- #3 zoom 7,071hits
- #4 github 6,725hits
- #5 adfs 2,820hits
- #6 webmail 2,676hits
- #7 oracle 2,233hits
- #8 sts 1,880hits
- #9 ftp 1,620hits
- #10 sap 1,548hits
- #11 zendesk 1,255hits
- #12 salesforce 1,180hits
- #13 ping 1,099hits
- #14 vpn 1,028hits
- #15 owa 967hits
- #16 cpanel 881hits
- #17 st 600hits
- #18 webex 561hits
- #19 okta 514hits
- #20 kaspersky 449hits
- #21 roundcube 434hits
- #22 extranet 429hits
- #23 imap 360hits
- #24 gitlab 319hits
- #25 twilio 290hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-15 – 2026-06-22
- 16K machines
- 3K users
- 216K domains
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.