Infostealers Weekly Report: 2023-07-17 – 2023-07-23
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 12,632
- #2 Mexico 6,192
- #3 Pakistan 5,775
- #4 Vietnam 5,451
- #5 Peru 5,122
- #6 Egypt 5,069
- #7 Thailand 4,922
- #8 India 4,793
- #9 Turkey 4,762
- #10 Colombia 4,427
- #11 Philippines 4,410
- #12 Argentina 4,186
- #13 United States of America 4,098
- #14 Bangladesh 2,807
- #15 Spain 2,432
- #16 Chile 2,358
- #17 Algeria 2,232
- #18 Indonesia 2,186
- #19 Morocco 2,062
- #20 Germany 1,722
- #21 Ecuador 1,697
- #22 France 1,518
- #23 Saudi Arabia 1,360
- #24 Sri Lanka 1,347
- #25 Bolivia 1,318
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 55,288 users
-
#2
facebook.com 52,458 users
-
#3
live.com 45,719 users
-
#4
discord.com 15,446 users
-
#5
instagram.com 14,976 users
-
#6
com.facebook.katana 14,281 users
-
#7
netflix.com 13,800 users
-
#8
roblox.com 13,313 users
-
#9
steampowered.com 10,890 users
-
#10
twitter.com 10,728 users
-
#11
amazon.com 10,691 users
-
#12
com.instagram.android 9,356 users
-
#13
com.netflix.mediaclient 9,034 users
-
#14
microsoftonline.com 8,907 users
-
#15
paypal.com 8,871 users
-
#16
twitch.tv 8,384 users
-
#17
riotgames.com 8,352 users
-
#18
mega.nz 8,041 users
-
#19
epicgames.com 7,512 users
-
#20
spotify.com 7,457 users
-
#21
apple.com 7,287 users
-
#22
yahoo.com 7,279 users
-
#23
linkedin.com 6,971 users
-
#24
com.discord 6,349 users
-
#25
steamcommunity.com 6,301 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 135 employees
-
#2
utp.edu.pe 97 employees
-
#3
163.com 96 employees
-
#4
laureate.net 84 employees
-
#5
hostinger.com 79 employees
-
#6
aruba.it 68 employees
-
#7
taqat.sa 66 employees
-
#8
secop.gov.co 66 employees
-
#9
bluehost.com 66 employees
-
#10
bcb.gov.br 66 employees
-
#11
upc.edu.pe 63 employees
-
#12
ig.com.br 61 employees
-
#13
interia.pl 61 employees
-
#14
fmod.dev 59 employees
-
#15
tim.it 56 employees
-
#16
qq.com 55 employees
-
#17
o2.pl 52 employees
-
#18
hust.edu.vn 49 employees
-
#19
sempreser.com.br 49 employees
-
#20
buenosaires.gob.ar 48 employees
-
#21
cibertec.edu.pe 46 employees
-
#22
concentrix.com 43 employees
-
#23
dla.go.th 42 employees
-
#24
icicibank.com 42 employees
-
#25
freemail.hu 41 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 21 employees
-
#2
rockwellautomation.com 18 employees
-
#3
ibm.com 15 employees
-
#4
netflix.com 10 employees
-
#5
cognizant.com 9 employees
-
#6
jll.com 5 employees
-
#7
hp.com 4 employees
-
#8
publix.com 4 employees
-
#9
oracle.com 3 employees
-
#10
ups.com 2 employees
-
#11
att.com 2 employees
-
#12
manpowergroup.com 2 employees
-
#13
oxy.com 2 employees
-
#14
quantaservices.com 1 employees
-
#15
westrock.com 1 employees
-
#16
cbre.com 1 employees
-
#17
statestreet.com 1 employees
-
#18
cisco.com 1 employees
-
#19
harman.com 1 employees
-
#20
aa.com 1 employees
Compromised users
-
#1
google.com 55,288 users
-
#2
facebook.com 52,458 users
-
#3
netflix.com 13,800 users
-
#4
amazon.com 10,691 users
-
#5
paypal.com 8,871 users
-
#6
apple.com 7,287 users
-
#7
ebay.com 1,489 users
-
#8
oracle.com 1,076 users
-
#9
microsoft.com 1,069 users
-
#10
hp.com 919 users
-
#11
nike.com 873 users
-
#12
cisco.com 836 users
-
#13
walmart.com 336 users
-
#14
ups.com 269 users
-
#15
westernunion.com 255 users
-
#16
ibm.com 240 users
-
#17
intel.com 238 users
-
#18
fedex.com 219 users
-
#19
adp.com 144 users
-
#20
salesforce.com 133 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 125,881hits
- #2 sso 39,671hits
- #3 zoom 12,543hits
- #4 github 5,225hits
- #5 adfs 3,921hits
- #6 webmail 3,531hits
- #7 oracle 1,998hits
- #8 sap 1,872hits
- #9 owa 1,729hits
- #10 zendesk 1,620hits
- #11 vpn 1,138hits
- #12 ping 1,110hits
- #13 cpanel 1,012hits
- #14 sts 1,003hits
- #15 extranet 893hits
- #16 webex 873hits
- #17 kaspersky 688hits
- #18 ftp 648hits
- #19 roundcube 572hits
- #20 salesforce 442hits
- #21 st 406hits
- #22 okta 354hits
- #23 gitlab 271hits
- #24 twilio 205hits
- #25 jira 167hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains