Infostealers Weekly Report: 2023-02-06 – 2023-02-12
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 5,136
- #2 Egypt 3,623
- #3 Mexico 2,579
- #4 Vietnam 2,451
- #5 Germany 2,006
- #6 Turkey 1,871
- #7 United States of America 1,777
- #8 Colombia 1,717
- #9 Thailand 1,695
- #10 Philippines 1,685
- #11 Spain 1,677
- #12 Algeria 1,631
- #13 Peru 1,514
- #14 Argentina 1,491
- #15 Russia 1,388
- #16 Pakistan 1,384
- #17 Poland 1,342
- #18 Morocco 1,152
- #19 France 1,024
- #20 Chile 967
- #21 Bangladesh 905
- #22 Romania 902
- #23 Ecuador 855
- #24 Italy 838
- #25 Venezuela 765
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 26,384 users
-
#2
facebook.com 23,362 users
-
#3
live.com 21,672 users
-
#4
discord.com 11,984 users
-
#5
roblox.com 11,127 users
-
#6
netflix.com 10,648 users
-
#7
instagram.com 10,612 users
-
#8
com.facebook.katana 10,389 users
-
#9
steampowered.com 8,738 users
-
#10
amazon.com 8,365 users
-
#11
twitter.com 8,330 users
-
#12
paypal.com 7,823 users
-
#13
twitch.tv 7,643 users
-
#14
com.netflix.mediaclient 6,963 users
-
#15
riotgames.com 6,821 users
-
#16
com.instagram.android 6,805 users
-
#17
epicgames.com 6,742 users
-
#18
mega.nz 6,517 users
-
#19
microsoftonline.com 6,509 users
-
#20
steamcommunity.com 6,157 users
-
#21
apple.com 5,540 users
-
#22
spotify.com 5,521 users
-
#23
com.discord 5,218 users
-
#24
linkedin.com 5,077 users
-
#25
com.spotify.music 5,037 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 204 employees
-
#2
freemail.hu 106 employees
-
#3
abv.bg 97 employees
-
#4
163.com 91 employees
-
#5
bcb.gov.br 81 employees
-
#6
hostinger.com 74 employees
-
#7
aruba.it 71 employees
-
#8
qq.com 61 employees
-
#9
o2.pl 61 employees
-
#10
secop.gov.co 57 employees
-
#11
pec.it 55 employees
-
#12
onet.pl 52 employees
-
#13
interia.pl 51 employees
-
#14
secureserver.net 50 employees
-
#15
ig.com.br 46 employees
-
#16
mail.bg 45 employees
-
#17
tim.it 42 employees
-
#18
utp.edu.pe 41 employees
-
#19
globo.com 40 employees
-
#20
skole.hr 40 employees
-
#21
login.sp.gov.br 39 employees
-
#22
inacap.cl 39 employees
-
#23
jwpub.org 36 employees
-
#24
laureate.net 36 employees
-
#25
banquemisr.com 35 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 21 employees
-
#2
rockwellautomation.com 18 employees
-
#3
ibm.com 8 employees
-
#4
apple.com 6 employees
-
#5
amazon.com 4 employees
-
#6
facebook.com 3 employees
-
#7
ups.com 3 employees
-
#8
fedex.com 3 employees
-
#9
frontier.com 3 employees
-
#10
emc.com 3 employees
-
#11
quintiles.com 3 employees
-
#12
chs.net 2 employees
-
#13
firstam.com 2 employees
-
#14
google.com 2 employees
-
#15
ford.com 2 employees
-
#16
cisco.com 2 employees
-
#17
publix.com 2 employees
-
#18
fisglobal.com 2 employees
-
#19
principal.com 1 employees
-
#20
stryker.com 1 employees
Compromised users
-
#1
google.com 26,384 users
-
#2
facebook.com 23,362 users
-
#3
netflix.com 10,648 users
-
#4
amazon.com 8,365 users
-
#5
paypal.com 7,823 users
-
#6
apple.com 5,540 users
-
#7
ebay.com 1,340 users
-
#8
oracle.com 864 users
-
#9
hp.com 738 users
-
#10
nike.com 726 users
-
#11
cisco.com 724 users
-
#12
microsoft.com 699 users
-
#13
walmart.com 279 users
-
#14
ups.com 271 users
-
#15
intel.com 251 users
-
#16
ibm.com 222 users
-
#17
westernunion.com 176 users
-
#18
bestbuy.com 151 users
-
#19
adp.com 114 users
-
#20
fedex.com 113 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 92,094hits
- #2 sso 24,994hits
- #3 zoom 9,270hits
- #4 adfs 4,145hits
- #5 webmail 3,712hits
- #6 github 3,467hits
- #7 oracle 1,649hits
- #8 sap 1,245hits
- #9 zendesk 1,225hits
- #10 owa 1,111hits
- #11 sts 913hits
- #12 vpn 898hits
- #13 cpanel 877hits
- #14 ping 792hits
- #15 kaspersky 727hits
- #16 ftp 698hits
- #17 webex 680hits
- #18 extranet 625hits
- #19 st 532hits
- #20 okta 349hits
- #21 rlogin 346hits
- #22 roundcube 339hits
- #23 salesforce 275hits
- #24 gitlab 206hits
- #25 jira 173hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains