Infostealers Weekly Report: 2023-03-20 – 2023-03-26
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 5,967
- #2 Egypt 5,435
- #3 Mexico 4,521
- #4 Brazil 4,408
- #5 Argentina 2,727
- #6 Colombia 2,713
- #7 Thailand 2,611
- #8 Spain 2,375
- #9 Philippines 2,329
- #10 Peru 2,254
- #11 United States of America 2,220
- #12 Algeria 2,173
- #13 Turkey 1,841
- #14 Bangladesh 1,661
- #15 Morocco 1,542
- #16 Pakistan 1,368
- #17 Germany 1,208
- #18 Iraq 1,194
- #19 India 1,118
- #20 Bolivia 1,095
- #21 Chile 940
- #22 Venezuela 937
- #23 France 924
- #24 Ecuador 911
- #25 Dominican Republic 860
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 33,396 users
-
#2
facebook.com 31,964 users
-
#3
live.com 28,455 users
-
#4
discord.com 14,730 users
-
#5
com.facebook.katana 13,702 users
-
#6
netflix.com 13,596 users
-
#7
roblox.com 13,502 users
-
#8
instagram.com 13,287 users
-
#9
twitter.com 10,468 users
-
#10
amazon.com 10,370 users
-
#11
steampowered.com 10,257 users
-
#12
paypal.com 8,844 users
-
#13
com.netflix.mediaclient 8,640 users
-
#14
twitch.tv 8,605 users
-
#15
microsoftonline.com 8,538 users
-
#16
riotgames.com 8,278 users
-
#17
mega.nz 8,209 users
-
#18
com.instagram.android 8,170 users
-
#19
epicgames.com 7,428 users
-
#20
apple.com 6,892 users
-
#21
linkedin.com 6,875 users
-
#22
spotify.com 6,415 users
-
#23
steamcommunity.com 6,337 users
-
#24
com.discord 5,929 users
-
#25
com.roblox.client 5,835 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 138 employees
-
#2
hostinger.com 111 employees
-
#3
qq.com 97 employees
-
#4
163.com 95 employees
-
#5
freemail.hu 93 employees
-
#6
jwpub.org 87 employees
-
#7
rockwellautomation.com 84 employees
-
#8
laureate.net 82 employees
-
#9
secureserver.net 77 employees
-
#10
abv.bg 77 employees
-
#11
milwaukee.k12.wi.us 76 employees
-
#12
secop.gov.co 74 employees
-
#13
buenosaires.gob.ar 73 employees
-
#14
aruba.it 65 employees
-
#15
tim.it 64 employees
-
#16
reacheducationfund.com 57 employees
-
#17
foxytech.net 57 employees
-
#18
ovh.net 53 employees
-
#19
ddec.pf 51 employees
-
#20
onet.pl 49 employees
-
#21
upc.edu.pe 49 employees
-
#22
pec.it 48 employees
-
#23
interia.pl 46 employees
-
#24
uaslp.mx 45 employees
-
#25
isacombank.com.vn 44 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 84 employees
-
#2
microsoft.com 20 employees
-
#3
facebook.com 11 employees
-
#4
amazon.com 7 employees
-
#5
parker.com 4 employees
-
#6
firstam.com 4 employees
-
#7
halliburton.com 3 employees
-
#8
att.com 3 employees
-
#9
hp.com 3 employees
-
#10
publix.com 3 employees
-
#11
netflix.com 2 employees
-
#12
abbott.com 2 employees
-
#13
paypal.com 2 employees
-
#14
deanfoods.com 1 employees
-
#15
fisglobal.com 1 employees
-
#16
apple.com 1 employees
-
#17
cablevision.com 1 employees
-
#18
disney.com 1 employees
-
#19
ncr.com 1 employees
-
#20
ford.com 1 employees
Compromised users
-
#1
google.com 33,396 users
-
#2
facebook.com 31,964 users
-
#3
netflix.com 13,596 users
-
#4
amazon.com 10,370 users
-
#5
paypal.com 8,844 users
-
#6
apple.com 6,892 users
-
#7
ebay.com 1,766 users
-
#8
oracle.com 1,109 users
-
#9
microsoft.com 1,057 users
-
#10
hp.com 1,038 users
-
#11
cisco.com 983 users
-
#12
nike.com 833 users
-
#13
walmart.com 523 users
-
#14
ups.com 359 users
-
#15
ibm.com 323 users
-
#16
fedex.com 234 users
-
#17
westernunion.com 229 users
-
#18
bestbuy.com 224 users
-
#19
target.com 214 users
-
#20
intel.com 201 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 107,721hits
- #2 sso 28,223hits
- #3 zoom 11,832hits
- #4 github 4,782hits
- #5 webmail 4,009hits
- #6 adfs 3,923hits
- #7 sap 2,409hits
- #8 oracle 1,998hits
- #9 owa 1,586hits
- #10 cpanel 1,511hits
- #11 zendesk 1,452hits
- #12 vpn 1,137hits
- #13 sts 996hits
- #14 ping 968hits
- #15 extranet 771hits
- #16 kaspersky 718hits
- #17 webex 700hits
- #18 ftp 663hits
- #19 st 634hits
- #20 okta 544hits
- #21 roundcube 423hits
- #22 gitlab 278hits
- #23 twilio 251hits
- #24 salesforce 212hits
- #25 sharepoint 138hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains