Infostealers Weekly Report: 2023-03-13 – 2023-03-19
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 6,140
- #2 Brazil 6,112
- #3 Egypt 4,163
- #4 Mexico 4,148
- #5 Philippines 3,312
- #6 Pakistan 2,941
- #7 Colombia 2,864
- #8 Thailand 2,843
- #9 Argentina 2,671
- #10 Turkey 2,335
- #11 Bangladesh 2,286
- #12 Peru 2,157
- #13 Morocco 1,973
- #14 United States of America 1,756
- #15 Algeria 1,694
- #16 Spain 1,361
- #17 Iraq 1,330
- #18 Chile 1,282
- #19 India 1,242
- #20 Bolivia 1,179
- #21 Venezuela 1,055
- #22 Sri Lanka 1,050
- #23 Indonesia 984
- #24 Malaysia 980
- #25 Poland 965
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 34,428 users
-
#2
facebook.com 32,356 users
-
#3
live.com 28,689 users
-
#4
roblox.com 15,348 users
-
#5
discord.com 15,242 users
-
#6
com.facebook.katana 13,857 users
-
#7
instagram.com 13,408 users
-
#8
netflix.com 13,190 users
-
#9
steampowered.com 10,306 users
-
#10
twitter.com 10,018 users
-
#11
amazon.com 9,916 users
-
#12
riotgames.com 8,723 users
-
#13
microsoftonline.com 8,670 users
-
#14
twitch.tv 8,661 users
-
#15
com.netflix.mediaclient 8,531 users
-
#16
com.instagram.android 8,207 users
-
#17
paypal.com 8,092 users
-
#18
mega.nz 7,980 users
-
#19
epicgames.com 7,143 users
-
#20
apple.com 6,469 users
-
#21
com.roblox.client 6,422 users
-
#22
steamcommunity.com 6,391 users
-
#23
com.discord 6,357 users
-
#24
spotify.com 6,138 users
-
#25
linkedin.com 6,119 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
abv.bg 142 employees
-
#2
wp.pl 101 employees
-
#3
hostinger.com 77 employees
-
#4
qq.com 76 employees
-
#5
secop.gov.co 76 employees
-
#6
freemail.hu 75 employees
-
#7
163.com 66 employees
-
#8
buenosaires.gob.ar 64 employees
-
#9
secureserver.net 57 employees
-
#10
inacap.cl 56 employees
-
#11
hust.edu.vn 54 employees
-
#12
bncr.fi.cr 53 employees
-
#13
o2.pl 52 employees
-
#14
skole.hr 51 employees
-
#15
login.sp.gov.br 50 employees
-
#16
banquemisr.com 48 employees
-
#17
interia.pl 47 employees
-
#18
mail.bg 47 employees
-
#19
laureate.net 46 employees
-
#20
telecom.pt 45 employees
-
#21
rockwellautomation.com 44 employees
-
#22
syrahost.com 43 employees
-
#23
dreamhost.com 42 employees
-
#24
aiou.edu.pk 42 employees
-
#25
deped.gov.ph 40 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 44 employees
-
#2
microsoft.com 13 employees
-
#3
vfc.com 12 employees
-
#4
facebook.com 10 employees
-
#5
oracle.com 9 employees
-
#6
fisglobal.com 8 employees
-
#7
goodyear.com 7 employees
-
#8
hp.com 6 employees
-
#9
ups.com 6 employees
-
#10
ford.com 5 employees
-
#11
xerox.com 5 employees
-
#12
paypal.com 4 employees
-
#13
pepsico.com 4 employees
-
#14
ibm.com 4 employees
-
#15
publix.com 4 employees
-
#16
yum.com 3 employees
-
#17
google.com 2 employees
-
#18
statefarm.com 2 employees
-
#19
cognizant.com 2 employees
-
#20
starwoodhotels.com 1 employees
Compromised users
-
#1
google.com 34,428 users
-
#2
facebook.com 32,356 users
-
#3
netflix.com 13,190 users
-
#4
amazon.com 9,916 users
-
#5
paypal.com 8,092 users
-
#6
apple.com 6,469 users
-
#7
ebay.com 1,426 users
-
#8
microsoft.com 1,085 users
-
#9
oracle.com 988 users
-
#10
cisco.com 952 users
-
#11
hp.com 798 users
-
#12
nike.com 714 users
-
#13
ups.com 264 users
-
#14
walmart.com 256 users
-
#15
ibm.com 248 users
-
#16
intel.com 226 users
-
#17
westernunion.com 210 users
-
#18
fedex.com 130 users
-
#19
americanexpress.com 113 users
-
#20
bestbuy.com 112 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 109,305hits
- #2 sso 30,128hits
- #3 zoom 11,953hits
- #4 github 4,764hits
- #5 adfs 3,651hits
- #6 webmail 3,036hits
- #7 oracle 1,780hits
- #8 sap 1,634hits
- #9 zendesk 1,398hits
- #10 owa 1,258hits
- #11 vpn 993hits
- #12 cpanel 961hits
- #13 ping 846hits
- #14 sts 777hits
- #15 kaspersky 645hits
- #16 webex 586hits
- #17 ftp 559hits
- #18 extranet 559hits
- #19 roundcube 546hits
- #20 st 358hits
- #21 salesforce 349hits
- #22 okta 348hits
- #23 gitlab 226hits
- #24 twilio 167hits
- #25 jira 155hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains