Infostealers Weekly Report: 2023-08-14 – 2023-08-20
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 5,460
- #2 Turkey 3,314
- #3 Pakistan 2,755
- #4 Philippines 2,593
- #5 Peru 2,389
- #6 Mexico 2,229
- #7 Egypt 1,900
- #8 United States of America 1,894
- #9 Vietnam 1,794
- #10 Colombia 1,585
- #11 Thailand 1,527
- #12 Spain 1,449
- #13 Bangladesh 1,425
- #14 Germany 1,209
- #15 Argentina 1,184
- #16 Morocco 1,171
- #17 Poland 1,139
- #18 India 1,107
- #19 Sri Lanka 1,103
- #20 Algeria 1,097
- #21 Nigeria 887
- #22 Indonesia 823
- #23 Chile 778
- #24 France 715
- #25 Bolivia 702
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 23,562 users
-
#2
facebook.com 21,595 users
-
#3
live.com 20,091 users
-
#4
discord.com 9,857 users
-
#5
instagram.com 9,703 users
-
#6
com.facebook.katana 9,303 users
-
#7
netflix.com 9,059 users
-
#8
roblox.com 8,904 users
-
#9
steampowered.com 7,477 users
-
#10
amazon.com 7,209 users
-
#11
twitter.com 6,912 users
-
#12
paypal.com 6,258 users
-
#13
com.netflix.mediaclient 5,993 users
-
#14
microsoftonline.com 5,939 users
-
#15
com.instagram.android 5,830 users
-
#16
mega.nz 5,805 users
-
#17
twitch.tv 5,639 users
-
#18
riotgames.com 5,313 users
-
#19
epicgames.com 5,222 users
-
#20
apple.com 5,010 users
-
#21
spotify.com 4,932 users
-
#22
linkedin.com 4,849 users
-
#23
steamcommunity.com 4,552 users
-
#24
com.roblox.client 4,156 users
-
#25
zoom.us 3,873 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 173 employees
-
#2
163.com 126 employees
-
#3
qq.com 100 employees
-
#4
freemail.hu 84 employees
-
#5
interia.pl 72 employees
-
#6
utp.edu.pe 60 employees
-
#7
hostinger.com 56 employees
-
#8
ukr.net 54 employees
-
#9
abv.bg 52 employees
-
#10
laureate.net 50 employees
-
#11
login.sp.gov.br 49 employees
-
#12
fmod.dev 47 employees
-
#13
o2.pl 44 employees
-
#14
sempreser.com.br 42 employees
-
#15
banquemisr.com 42 employees
-
#16
rockwellautomation.com 41 employees
-
#17
secureserver.net 40 employees
-
#18
jwpub.org 39 employees
-
#19
secop.gov.co 37 employees
-
#20
telecom.pt 35 employees
-
#21
onet.pl 33 employees
-
#22
bcb.gov.br 32 employees
-
#23
pec.it 31 employees
-
#24
tim.it 31 employees
-
#25
aruba.it 31 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 41 employees
-
#2
microsoft.com 23 employees
-
#3
pepsico.com 8 employees
-
#4
ibm.com 7 employees
-
#5
netflix.com 6 employees
-
#6
ncr.com 5 employees
-
#7
honeywell.com 4 employees
-
#8
publix.com 3 employees
-
#9
cbre.com 3 employees
-
#10
essendant.com 1 employees
-
#11
marriott.com 1 employees
-
#12
assurant.com 1 employees
-
#13
disney.com 1 employees
-
#14
cognizant.com 1 employees
-
#15
abbott.com 1 employees
-
#16
morganstanley.com 1 employees
-
#17
google.com 1 employees
-
#18
ups.com 1 employees
-
#19
stryker.com 1 employees
-
#20
anixter.com 1 employees
Compromised users
-
#1
google.com 23,562 users
-
#2
facebook.com 21,595 users
-
#3
netflix.com 9,059 users
-
#4
amazon.com 7,209 users
-
#5
paypal.com 6,258 users
-
#6
apple.com 5,010 users
-
#7
ebay.com 1,276 users
-
#8
oracle.com 799 users
-
#9
cisco.com 640 users
-
#10
hp.com 617 users
-
#11
microsoft.com 592 users
-
#12
nike.com 460 users
-
#13
walmart.com 269 users
-
#14
ibm.com 264 users
-
#15
ups.com 206 users
-
#16
intel.com 203 users
-
#17
westernunion.com 164 users
-
#18
fedex.com 109 users
-
#19
bestbuy.com 105 users
-
#20
adp.com 102 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 85,326hits
- #2 sso 22,559hits
- #3 zoom 8,440hits
- #4 github 3,668hits
- #5 webmail 3,191hits
- #6 adfs 2,777hits
- #7 sap 1,721hits
- #8 oracle 1,619hits
- #9 zendesk 1,396hits
- #10 owa 1,114hits
- #11 sts 930hits
- #12 vpn 846hits
- #13 cpanel 755hits
- #14 extranet 752hits
- #15 ping 643hits
- #16 webex 614hits
- #17 kaspersky 535hits
- #18 ftp 494hits
- #19 roundcube 464hits
- #20 st 424hits
- #21 okta 323hits
- #22 salesforce 171hits
- #23 twilio 136hits
- #24 dana-na 132hits
- #25 gitlab 115hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains