Infostealers Weekly Report: 2023-05-01 – 2023-05-07
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 9,948
- #2 Vietnam 7,662
- #3 Egypt 6,693
- #4 India 5,645
- #5 Mexico 4,597
- #6 Philippines 4,276
- #7 Peru 3,644
- #8 Pakistan 3,302
- #9 Colombia 3,236
- #10 Argentina 3,014
- #11 United States of America 2,922
- #12 Indonesia 2,871
- #13 Turkey 2,579
- #14 Bangladesh 2,421
- #15 Algeria 2,298
- #16 Spain 2,162
- #17 Morocco 2,075
- #18 Malaysia 1,652
- #19 Thailand 1,530
- #20 Germany 1,468
- #21 Venezuela 1,463
- #22 France 1,461
- #23 Poland 1,415
- #24 Italy 1,307
- #25 Chile 1,201
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 52,301 users
-
#2
facebook.com 47,684 users
-
#3
live.com 44,652 users
-
#4
discord.com 23,527 users
-
#5
instagram.com 22,108 users
-
#6
com.facebook.katana 21,238 users
-
#7
netflix.com 21,025 users
-
#8
roblox.com 20,729 users
-
#9
amazon.com 17,771 users
-
#10
twitter.com 16,804 users
-
#11
steampowered.com 16,574 users
-
#12
paypal.com 14,507 users
-
#13
com.instagram.android 14,092 users
-
#14
microsoftonline.com 14,066 users
-
#15
com.netflix.mediaclient 13,709 users
-
#16
twitch.tv 13,604 users
-
#17
riotgames.com 13,267 users
-
#18
mega.nz 12,598 users
-
#19
epicgames.com 11,738 users
-
#20
linkedin.com 11,598 users
-
#21
apple.com 11,256 users
-
#22
spotify.com 11,139 users
-
#23
steamcommunity.com 10,186 users
-
#24
com.discord 9,986 users
-
#25
com.roblox.client 9,488 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 199 employees
-
#2
icicibank.com 187 employees
-
#3
hostinger.com 164 employees
-
#4
163.com 163 employees
-
#5
qq.com 146 employees
-
#6
aruba.it 143 employees
-
#7
rediff.com 117 employees
-
#8
sempreser.com.br 113 employees
-
#9
utp.edu.pe 103 employees
-
#10
laureate.net 102 employees
-
#11
secureserver.net 100 employees
-
#12
o2.pl 99 employees
-
#13
pec.it 99 employees
-
#14
tim.it 98 employees
-
#15
banquemisr.com 90 employees
-
#16
secop.gov.co 88 employees
-
#17
naver.com 84 employees
-
#18
buenosaires.gob.ar 81 employees
-
#19
bcb.gov.br 80 employees
-
#20
web-hosting.com 80 employees
-
#21
interia.pl 76 employees
-
#22
freemail.hu 75 employees
-
#23
telecom.pt 67 employees
-
#24
hostgator.com 66 employees
-
#25
atlassian.com 66 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 47 employees
-
#2
microsoft.com 33 employees
-
#3
publix.com 13 employees
-
#4
netflix.com 11 employees
-
#5
cognizant.com 11 employees
-
#6
sandisk.com 8 employees
-
#7
apple.com 7 employees
-
#8
oracle.com 6 employees
-
#9
salesforce.com 6 employees
-
#10
csc.com 6 employees
-
#11
amazon.com 4 employees
-
#12
pg.com 4 employees
-
#13
ibm.com 4 employees
-
#14
marathonoil.com 3 employees
-
#15
wrberkley.com 3 employees
-
#16
ford.com 3 employees
-
#17
google.com 3 employees
-
#18
paypal.com 3 employees
-
#19
johnsoncontrols.com 2 employees
-
#20
metlife.com 2 employees
Compromised users
-
#1
google.com 52,301 users
-
#2
facebook.com 47,684 users
-
#3
netflix.com 21,025 users
-
#4
amazon.com 17,771 users
-
#5
paypal.com 14,507 users
-
#6
apple.com 11,256 users
-
#7
ebay.com 2,607 users
-
#8
oracle.com 1,978 users
-
#9
microsoft.com 1,813 users
-
#10
hp.com 1,544 users
-
#11
cisco.com 1,513 users
-
#12
nike.com 1,405 users
-
#13
ibm.com 575 users
-
#14
walmart.com 543 users
-
#15
ups.com 531 users
-
#16
intel.com 409 users
-
#17
westernunion.com 391 users
-
#18
fedex.com 288 users
-
#19
bestbuy.com 256 users
-
#20
adp.com 223 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 194,228hits
- #2 sso 49,554hits
- #3 zoom 19,842hits
- #4 github 8,959hits
- #5 webmail 7,066hits
- #6 adfs 6,764hits
- #7 oracle 3,685hits
- #8 zendesk 2,811hits
- #9 sap 2,784hits
- #10 owa 2,382hits
- #11 ping 2,061hits
- #12 sts 2,055hits
- #13 vpn 2,047hits
- #14 cpanel 1,827hits
- #15 kaspersky 1,447hits
- #16 webex 1,428hits
- #17 ftp 1,157hits
- #18 extranet 1,142hits
- #19 roundcube 1,021hits
- #20 st 901hits
- #21 okta 647hits
- #22 salesforce 641hits
- #23 imap 588hits
- #24 gitlab 542hits
- #25 twilio 462hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains