Infostealers Weekly Report: 2026-05-11 – 2026-05-18
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,319
- #2 France 463
- #3 Indonesia 334
- #4 Italy 305
- #5 United States of America 271
- #6 Philippines 178
- #7 Pakistan 174
- #8 Vietnam 162
- #9 United Kingdom 129
- #10 Brazil 125
- #11 Unknown Region 124
- #12 Bangladesh 116
- #13 South Africa 79
- #14 Canada 77
- #15 China 73
- #16 Mexico 68
- #17 Morocco 66
- #18 Egypt 65
- #19 Kenya 52
- #20 Algeria 51
- #21 Germany 50
- #22 Sri Lanka 44
- #23 Spain 38
- #24 Ghana 37
- #25 Malaysia 37
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 18,300 users
-
#2
facebook.com 14,154 users
-
#3
live.com 12,733 users
-
#4
instagram.com 9,545 users
-
#5
com.facebook.katana 8,746 users
-
#6
com.instagram.android 7,574 users
-
#7
netflix.com 7,509 users
-
#8
amazon.com 7,040 users
-
#9
discord.com 6,604 users
-
#10
com.netflix.mediaclient 5,717 users
-
#11
microsoftonline.com 5,258 users
-
#12
steampowered.com 5,195 users
-
#13
paypal.com 5,162 users
-
#14
roblox.com 5,094 users
-
#15
apple.com 4,751 users
-
#16
twitter.com 4,540 users
-
#17
com.spotify.music 4,412 users
-
#18
com.pinterest 4,287 users
-
#19
linkedin.com 4,188 users
-
#20
spotify.com 4,165 users
-
#21
com.roblox.client 3,964 users
-
#22
com.discord 3,941 users
-
#23
mega.nz 3,767 users
-
#24
openai.com 3,696 users
-
#25
twitch.tv 3,652 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 167 employees
-
#2
hostinger.com 154 employees
-
#3
aruba.it 103 employees
-
#4
rediff.com 87 employees
-
#5
buenosaires.gob.ar 79 employees
-
#6
firstmail.ltd 75 employees
-
#7
tim.it 64 employees
-
#8
bobibanking.com 59 employees
-
#9
netpnb.com 54 employees
-
#10
icai.org 52 employees
-
#11
pec.it 51 employees
-
#12
wp.pl 50 employees
-
#13
unionbankonline.co.in 45 employees
-
#14
163.com 37 employees
-
#15
secop.gov.co 37 employees
-
#16
indusind.com 35 employees
-
#17
mail.tm 34 employees
-
#18
fednetbank.com 34 employees
-
#19
santander.com.br 34 employees
-
#20
payoneer.com 33 employees
-
#21
android 32 employees
-
#22
ovh.net 29 employees
-
#23
unibo.it 29 employees
-
#24
accenture.com 28 employees
-
#25
inacap.cl 27 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
salesforce.com 17 employees
-
#2
rockwellautomation.com 13 employees
-
#3
microsoft.com 12 employees
-
#4
ibm.com 9 employees
-
#5
google.com 6 employees
-
#6
netflix.com 6 employees
-
#7
cognizant.com 6 employees
-
#8
ford.com 5 employees
-
#9
ups.com 5 employees
-
#10
publix.com 5 employees
-
#11
apple.com 5 employees
-
#12
abbott.com 3 employees
-
#13
jbhunt.com 3 employees
-
#14
stryker.com 3 employees
-
#15
ge.com 3 employees
-
#16
tenneco.com 2 employees
-
#17
amazon.com 2 employees
-
#18
aramark.com 2 employees
-
#19
paypal.com 2 employees
-
#20
bestbuy.com 2 employees
Compromised users
-
#1
google.com 18,300 users
-
#2
facebook.com 14,154 users
-
#3
netflix.com 7,509 users
-
#4
amazon.com 7,040 users
-
#5
paypal.com 5,162 users
-
#6
apple.com 4,751 users
-
#7
hp.com 995 users
-
#8
oracle.com 878 users
-
#9
ebay.com 822 users
-
#10
nike.com 711 users
-
#11
microsoft.com 668 users
-
#12
cisco.com 465 users
-
#13
ups.com 358 users
-
#14
ibm.com 339 users
-
#15
walmart.com 332 users
-
#16
westernunion.com 234 users
-
#17
broadcom.com 205 users
-
#18
salesforce.com 179 users
-
#19
fedex.com 169 users
-
#20
intel.com 156 users
Compromised Mobile Apps
Top Android apps found in infected caches
The Android applications most frequently found in infected device caches this week.
8,746 users
7,574 users
Netflix
5,717 users
Spotify
4,412 users
4,287 users
Roblox
3,964 users
Discord
3,941 users
Snapchat
3,174 users
Twitch
2,633 users
2,605 users
Wish
1,955 users
PayPal
1,654 users
Disney
1,516 users
Zoom
1,462 users
Mega
1,357 users
1,313 users
Xiaomi
1,233 users
Mercadolibre
922 users
Alibaba
767 users
Waze
716 users
Top Compromised Email Providers
Email domains tied to compromised credentials
Gmail, hotmail, and beyond — providers seen across this week's stealer logs.
-
#1
gmail.com 930,044 users
-
#2
hotmail.com 98,712 users
-
#3
yahoo.com 26,157 users
-
#4
outlook.com 19,658 users
-
#5
icloud.com 7,312 users
-
#6
hotmail.fr 6,723 users
-
#7
live.com 3,574 users
-
#8
yahoo.fr 3,043 users
-
#9
msn.com 2,801 users
-
#10
hotmail.it 2,504 users
-
#11
libero.it 2,345 users
-
#12
orange.fr 2,236 users
-
#13
free.fr 2,026 users
-
#14
live.fr 2,015 users
-
#15
yahoo.com.br 1,957 users
-
#16
hotmail.es 1,835 users
-
#17
yahoo.it 1,813 users
-
#18
mail.com 1,662 users
-
#19
aol.com 1,583 users
-
#20
ymail.com 1,526 users
-
#21
gmx.com 1,446 users
-
#22
web.de 1,378 users
-
#23
hotmail.co.uk 1,366 users
-
#24
gmx.de 1,310 users
-
#25
yahoo.com.ar 1,124 users
Malware Landscape
Stealer families & anti-virus coverage
Malware families responsible for this week's infections, and the anti-virus solutions reported by infected hosts.
Stealer Families
- #1 Generic Stealer 23,437machines
- #2 Acreed 878machines
- #3 Lumma 457machines
Anti-virus Coverage
- #1 No anti-virus installed 358machines
- #2 Windows Defender 44machines
- #3 Windows Defender, AVG Antivirus 2machines
- #4 Kaspersky [OFF] 1machines
- #5 Avira Security, Windows Defender 1machines
- #6 Windows Defender, McAfee 1machines
- #7 Windows Defender [ON] 1machines
- #8 ESET Security, Spybot - Search and Destroy, ESET Security, Windows Defender, ESET Security 1machines
- #9 ESET Security 1machines
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 109,857hits
- #2 sso 29,721hits
- #3 zoom 6,880hits
- #4 github 5,651hits
- #5 webmail 2,906hits
- #6 adfs 2,395hits
- #7 oracle 1,883hits
- #8 sap 1,481hits
- #9 zendesk 1,370hits
- #10 salesforce 1,299hits
- #11 ping 1,071hits
- #12 owa 1,058hits
- #13 sts 1,003hits
- #14 vpn 910hits
- #15 extranet 716hits
- #16 cpanel 710hits
- #17 imap 668hits
- #18 kaspersky 543hits
- #19 webex 505hits
- #20 okta 454hits
- #21 ftp 387hits
- #22 st 379hits
- #23 roundcube 365hits
- #24 twilio 205hits
- #25 zimbra 188hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Top Compromised Social Platforms
Where saved sessions and logins lived
Social media services where compromised accounts had stored sessions or saved logins.