Infostealers Weekly Report: 2021-09-20 – 2021-09-26
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Unknown Region 1,320
- #2 Russia 719
- #3 Brazil 619
- #4 India 590
- #5 Pakistan 281
- #6 United States of America 234
- #7 Philippines 191
- #8 Poland 153
- #9 Thailand 152
- #10 Indonesia 147
- #11 Mexico 133
- #12 Vietnam 126
- #13 Turkey 125
- #14 Germany 113
- #15 Bangladesh 102
- #16 Peru 96
- #17 Sweden 94
- #18 Malaysia 91
- #19 Colombia 88
- #20 Egypt 87
- #21 Nigeria 78
- #22 Romania 76
- #23 Italy 73
- #24 Netherlands 72
- #25 Spain 71
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,697 users
-
#2
5,466 users
-
#3
facebook.com 4,390 users
-
#4
live.com 4,112 users
-
#5
discord.com 2,347 users
-
#6
2,173 users
-
#7
___| 2,050 users
-
#8
\ 2,050 users
-
#9
|_) 2,050 users
-
#10
_ 2,050 users
-
#11
instagram.com 2,041 users
-
#12
netflix.com 2,029 users
-
#13
twitter.com 1,998 users
-
#14
twitch.tv 1,817 users
-
#15
amazon.com 1,727 users
-
#16
roblox.com 1,701 users
-
#17
steampowered.com 1,687 users
-
#18
paypal.com 1,648 users
-
#19
riotgames.com 1,586 users
-
#20
com.facebook.katana 1,553 users
-
#21
epicgames.com 1,506 users
-
#22
steamcommunity.com 1,410 users
-
#23
mega.nz 1,366 users
-
#24
apple.com 1,102 users
-
#25
microsoftonline.com 1,079 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
34 employees
-
#2
icicibank.com 32 employees
-
#3
rediff.com 26 employees
-
#4
accenture.com 18 employees
-
#5
aiou.edu.pk 17 employees
-
#6
zsthost.com 16 employees
-
#7
14 employees
-
#8
digimail.in 13 employees
-
#9
163.com 13 employees
-
#10
telecom.pt 13 employees
-
#11
moe.gov.ae 11 employees
-
#12
interia.pl 11 employees
-
#13
o2.pl 11 employees
-
#14
netpnb.com 10 employees
-
#15
freemail.hu 10 employees
-
#16
sp.gov.br 9 employees
-
#17
onet.pl 9 employees
-
#18
onlinesbi.com 9 employees
-
#19
one.com 8 employees
-
#20
pec.it 8 employees
-
#21
ukr.net 8 employees
-
#22
ig.com.br 8 employees
-
#23
naver.com 8 employees
-
#24
globo.com 8 employees
-
#25
freenet.de 7 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
netflix.com 6 employees
-
#2
cognizant.com 3 employees
-
#3
publix.com 3 employees
-
#4
ibm.com 2 employees
-
#5
amazon.com 2 employees
-
#6
jpmorganchase.com 2 employees
-
#7
microsoft.com 2 employees
-
#8
rockwellautomation.com 2 employees
-
#9
bakerhughes.com 1 employees
-
#10
cbrands.com 1 employees
-
#11
att.com 1 employees
-
#12
abbott.com 1 employees
-
#13
oracle.com 1 employees
-
#14
micron.com 1 employees
-
#15
cbre.com 1 employees
-
#16
gm.com 1 employees
-
#17
essendant.com 1 employees
-
#18
costco.com 1 employees
-
#19
apple.com 1 employees
-
#20
hp.com 1 employees
Compromised users
-
#1
google.com 5,697 users
-
#2
facebook.com 4,390 users
-
#3
netflix.com 2,029 users
-
#4
amazon.com 1,727 users
-
#5
paypal.com 1,648 users
-
#6
apple.com 1,102 users
-
#7
ebay.com 272 users
-
#8
oracle.com 198 users
-
#9
hp.com 124 users
-
#10
cisco.com 104 users
-
#11
nike.com 103 users
-
#12
microsoft.com 97 users
-
#13
walmart.com 78 users
-
#14
intel.com 76 users
-
#15
bestbuy.com 40 users
-
#16
ibm.com 40 users
-
#17
adp.com 39 users
-
#18
fedex.com 37 users
-
#19
ups.com 36 users
-
#20
target.com 30 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 20,330hits
- #2 sso 4,963hits
- #3 zoom 1,600hits
- #4 adfs 817hits
- #5 github 769hits
- #6 webmail 717hits
- #7 oracle 389hits
- #8 owa 282hits
- #9 zendesk 267hits
- #10 sap 225hits
- #11 sts 201hits
- #12 vpn 200hits
- #13 cpanel 189hits
- #14 ping 179hits
- #15 webex 169hits
- #16 st 165hits
- #17 ftp 155hits
- #18 extranet 152hits
- #19 kaspersky 114hits
- #20 salesforce 67hits
- #21 okta 55hits
- #22 gitlab 52hits
- #23 roundcube 49hits
- #24 zimbra 40hits
- #25 citrix 34hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains