Infostealers Weekly Report: 2023-07-31 – 2023-08-06
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 7,378
- #2 Philippines 4,431
- #3 Vietnam 4,175
- #4 Pakistan 3,905
- #5 Peru 3,307
- #6 United States of America 3,067
- #7 Thailand 2,891
- #8 Mexico 2,569
- #9 Colombia 2,502
- #10 Turkey 2,455
- #11 India 2,369
- #12 Egypt 2,168
- #13 Bangladesh 2,156
- #14 Algeria 1,954
- #15 Morocco 1,807
- #16 Indonesia 1,785
- #17 Germany 1,783
- #18 Argentina 1,574
- #19 Sri Lanka 1,306
- #20 Malaysia 1,223
- #21 Poland 1,106
- #22 Netherlands 943
- #23 Spain 941
- #24 Ecuador 941
- #25 Chile 930
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 28,872 users
-
#2
facebook.com 27,060 users
-
#3
live.com 24,607 users
-
#4
discord.com 12,509 users
-
#5
roblox.com 12,270 users
-
#6
com.facebook.katana 12,052 users
-
#7
instagram.com 11,897 users
-
#8
netflix.com 11,291 users
-
#9
steampowered.com 8,800 users
-
#10
twitter.com 8,437 users
-
#11
amazon.com 8,352 users
-
#12
com.instagram.android 7,717 users
-
#13
com.netflix.mediaclient 7,603 users
-
#14
paypal.com 6,929 users
-
#15
riotgames.com 6,795 users
-
#16
mega.nz 6,694 users
-
#17
microsoftonline.com 6,616 users
-
#18
twitch.tv 6,468 users
-
#19
spotify.com 5,870 users
-
#20
epicgames.com 5,853 users
-
#21
com.roblox.client 5,706 users
-
#22
apple.com 5,620 users
-
#23
linkedin.com 5,505 users
-
#24
steamcommunity.com 4,811 users
-
#25
zoom.us 4,795 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 105 employees
-
#2
freemail.hu 85 employees
-
#3
utp.edu.pe 81 employees
-
#4
login.sp.gov.br 78 employees
-
#5
qq.com 75 employees
-
#6
icicibank.com 66 employees
-
#7
hostinger.com 64 employees
-
#8
163.com 61 employees
-
#9
inacap.cl 60 employees
-
#10
sempreser.com.br 55 employees
-
#11
bcb.gov.br 53 employees
-
#12
deped.gov.ph 52 employees
-
#13
britanico.edu.pe 51 employees
-
#14
o2.pl 51 employees
-
#15
onet.pl 45 employees
-
#16
laureate.net 44 employees
-
#17
secop.gov.co 42 employees
-
#18
hust.edu.vn 42 employees
-
#19
aruba.it 41 employees
-
#20
upc.edu.pe 41 employees
-
#21
fmod.dev 40 employees
-
#22
turbify.com 40 employees
-
#23
cibertec.edu.pe 39 employees
-
#24
yandex.com.tr 38 employees
-
#25
ukr.net 38 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 33 employees
-
#2
rockwellautomation.com 22 employees
-
#3
stryker.com 10 employees
-
#4
publix.com 5 employees
-
#5
pepsico.com 4 employees
-
#6
honeywell.com 4 employees
-
#7
twc.com 4 employees
-
#8
gm.com 4 employees
-
#9
jacobs.com 3 employees
-
#10
cbre.com 2 employees
-
#11
centene.com 2 employees
-
#12
johnsoncontrols.com 2 employees
-
#13
halliburton.com 2 employees
-
#14
citigroup.com 1 employees
-
#15
boeing.com 1 employees
-
#16
facebook.com 1 employees
-
#17
csc.com 1 employees
-
#18
hp.com 1 employees
-
#19
cognizant.com 1 employees
-
#20
aa.com 1 employees
Compromised users
-
#1
google.com 28,872 users
-
#2
facebook.com 27,060 users
-
#3
netflix.com 11,291 users
-
#4
amazon.com 8,352 users
-
#5
paypal.com 6,929 users
-
#6
apple.com 5,620 users
-
#7
ebay.com 1,179 users
-
#8
microsoft.com 861 users
-
#9
oracle.com 727 users
-
#10
cisco.com 697 users
-
#11
hp.com 679 users
-
#12
nike.com 626 users
-
#13
walmart.com 284 users
-
#14
ibm.com 248 users
-
#15
ups.com 228 users
-
#16
westernunion.com 215 users
-
#17
intel.com 193 users
-
#18
adp.com 132 users
-
#19
fedex.com 103 users
-
#20
bestbuy.com 95 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 94,909hits
- #2 sso 25,326hits
- #3 zoom 9,797hits
- #4 github 4,347hits
- #5 webmail 2,958hits
- #6 adfs 2,949hits
- #7 oracle 1,336hits
- #8 owa 1,264hits
- #9 vpn 1,217hits
- #10 zendesk 1,149hits
- #11 sap 1,140hits
- #12 ping 983hits
- #13 sts 907hits
- #14 cpanel 836hits
- #15 kaspersky 608hits
- #16 extranet 590hits
- #17 webex 568hits
- #18 okta 501hits
- #19 ftp 426hits
- #20 roundcube 407hits
- #21 salesforce 374hits
- #22 st 360hits
- #23 gitlab 294hits
- #24 twilio 227hits
- #25 git 152hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains