Infostealers Weekly Report: 2021-09-13 – 2021-09-19
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Russia 1,730
- #2 India 784
- #3 Brazil 505
- #4 Indonesia 417
- #5 Pakistan 372
- #6 Unknown Region 306
- #7 Germany 262
- #8 Turkey 251
- #9 Thailand 230
- #10 Philippines 224
- #11 United States of America 178
- #12 Vietnam 161
- #13 Sri Lanka 111
- #14 Nigeria 111
- #15 Mexico 111
- #16 France 109
- #17 Spain 107
- #18 Poland 98
- #19 Colombia 96
- #20 Egypt 91
- #21 Myanmar (Burma) 89
- #22 Italy 88
- #23 Malaysia 86
- #24 South Africa 84
- #25 United Kingdom 78
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 7,626 users
-
#2
7,261 users
-
#3
facebook.com 5,978 users
-
#4
live.com 5,296 users
-
#5
|_) 4,192 users
-
#6
\ 4,192 users
-
#7
___| 4,192 users
-
#8
_ 4,192 users
-
#9
3,467 users
-
#10
instagram.com 2,585 users
-
#11
twitter.com 2,464 users
-
#12
netflix.com 2,382 users
-
#13
discord.com 2,271 users
-
#14
com.facebook.katana 2,165 users
-
#15
amazon.com 2,114 users
-
#16
paypal.com 1,944 users
-
#17
roblox.com 1,814 users
-
#18
mega.nz 1,800 users
-
#19
twitch.tv 1,692 users
-
#20
steampowered.com 1,685 users
-
#21
epicgames.com 1,465 users
-
#22
microsoftonline.com 1,451 users
-
#23
riotgames.com 1,446 users
-
#24
linkedin.com 1,442 users
-
#25
apple.com 1,391 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 51 employees
-
#2
43 employees
-
#3
icicibank.com 35 employees
-
#4
ukr.net 28 employees
-
#5
22 employees
-
#6
interia.pl 20 employees
-
#7
aruba.it 20 employees
-
#8
ig.com.br 18 employees
-
#9
telecom.pt 16 employees
-
#10
digimail.in 16 employees
-
#11
o2.pl 16 employees
-
#12
onlinesbi.com 16 employees
-
#13
globo.com 15 employees
-
#14
freemail.hu 15 employees
-
#15
netpnb.com 14 employees
-
#16
accenture.com 14 employees
-
#17
163.com 13 employees
-
#18
mail.gov.in 12 employees
-
#19
pec.it 12 employees
-
#20
i.ua 12 employees
-
#21
tim.it 12 employees
-
#22
onet.pl 11 employees
-
#23
yandex.com.tr 11 employees
-
#24
bcb.gov.br 11 employees
-
#25
aiou.edu.pk 11 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 4 employees
-
#2
rockwellautomation.com 3 employees
-
#3
techdata.com 2 employees
-
#4
ibm.com 2 employees
-
#5
cbre.com 1 employees
-
#6
apple.com 1 employees
-
#7
harman.com 1 employees
-
#8
generalmills.com 1 employees
-
#9
microsoft.com 1 employees
-
#10
hp.com 1 employees
-
#11
netflix.com 1 employees
-
#12
twc.com 1 employees
Compromised users
-
#1
google.com 7,626 users
-
#2
facebook.com 5,978 users
-
#3
netflix.com 2,382 users
-
#4
amazon.com 2,114 users
-
#5
paypal.com 1,944 users
-
#6
apple.com 1,391 users
-
#7
ebay.com 387 users
-
#8
oracle.com 212 users
-
#9
cisco.com 165 users
-
#10
hp.com 151 users
-
#11
nike.com 115 users
-
#12
microsoft.com 106 users
-
#13
intel.com 68 users
-
#14
walmart.com 64 users
-
#15
ups.com 49 users
-
#16
westernunion.com 49 users
-
#17
ibm.com 45 users
-
#18
fedex.com 36 users
-
#19
bestbuy.com 29 users
-
#20
salesforce.com 26 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 21,205hits
- #2 sso 6,503hits
- #3 zoom 2,401hits
- #4 webmail 1,577hits
- #5 github 979hits
- #6 adfs 884hits
- #7 owa 535hits
- #8 sap 470hits
- #9 oracle 434hits
- #10 zendesk 339hits
- #11 webex 332hits
- #12 sts 308hits
- #13 ftp 262hits
- #14 cpanel 255hits
- #15 ping 227hits
- #16 vpn 211hits
- #17 extranet 182hits
- #18 kaspersky 150hits
- #19 st 146hits
- #20 roundcube 119hits
- #21 gitlab 75hits
- #22 salesforce 72hits
- #23 dana-na 50hits
- #24 citrix 47hits
- #25 okta 42hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains