Infostealers Weekly Report: 2023-03-27 – 2023-04-02
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 8,057
- #2 Brazil 7,070
- #3 Egypt 6,855
- #4 Mexico 6,249
- #5 Colombia 4,547
- #6 Peru 4,113
- #7 Argentina 4,000
- #8 Thailand 3,985
- #9 Bangladesh 3,981
- #10 Turkey 3,869
- #11 Spain 3,862
- #12 Philippines 3,751
- #13 Algeria 2,843
- #14 Morocco 2,557
- #15 Ecuador 2,121
- #16 Chile 2,035
- #17 Bolivia 1,813
- #18 Iraq 1,718
- #19 Dominican Republic 1,669
- #20 Venezuela 1,603
- #21 Italy 1,597
- #22 Germany 1,562
- #23 France 1,550
- #24 Romania 1,486
- #25 United States of America 1,438
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 51,797 users
-
#2
facebook.com 49,573 users
-
#3
live.com 44,003 users
-
#4
com.facebook.katana 21,360 users
-
#5
discord.com 21,195 users
-
#6
netflix.com 20,531 users
-
#7
instagram.com 20,025 users
-
#8
roblox.com 19,077 users
-
#9
steampowered.com 16,216 users
-
#10
twitter.com 15,944 users
-
#11
amazon.com 15,719 users
-
#12
com.netflix.mediaclient 13,830 users
-
#13
paypal.com 13,776 users
-
#14
microsoftonline.com 13,435 users
-
#15
twitch.tv 13,009 users
-
#16
com.instagram.android 12,608 users
-
#17
riotgames.com 12,538 users
-
#18
mega.nz 12,499 users
-
#19
epicgames.com 11,120 users
-
#20
apple.com 10,648 users
-
#21
linkedin.com 10,415 users
-
#22
steamcommunity.com 9,662 users
-
#23
spotify.com 9,649 users
-
#24
com.discord 9,317 users
-
#25
com.spotify.music 9,203 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 248 employees
-
#2
aruba.it 220 employees
-
#3
wp.pl 179 employees
-
#4
pec.it 160 employees
-
#5
hostinger.com 154 employees
-
#6
secop.gov.co 152 employees
-
#7
qq.com 131 employees
-
#8
163.com 124 employees
-
#9
tim.it 122 employees
-
#10
laureate.net 115 employees
-
#11
banquemisr.com 100 employees
-
#12
inacap.cl 95 employees
-
#13
abv.bg 95 employees
-
#14
rockwellautomation.com 91 employees
-
#15
buenosaires.gob.ar 85 employees
-
#16
interia.pl 85 employees
-
#17
utp.edu.pe 82 employees
-
#18
onet.pl 80 employees
-
#19
jwpub.org 78 employees
-
#20
ovh.net 77 employees
-
#21
skole.hr 76 employees
-
#22
upc.edu.pe 71 employees
-
#23
cibertec.edu.pe 71 employees
-
#24
telecom.pt 68 employees
-
#25
tigo.com.co 68 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 91 employees
-
#2
microsoft.com 29 employees
-
#3
netflix.com 18 employees
-
#4
publix.com 13 employees
-
#5
mosaicco.com 10 employees
-
#6
abbott.com 8 employees
-
#7
firstam.com 7 employees
-
#8
paypal.com 6 employees
-
#9
twc.com 6 employees
-
#10
dupont.com 6 employees
-
#11
facebook.com 6 employees
-
#12
pg.com 6 employees
-
#13
amazon.com 5 employees
-
#14
salesforce.com 4 employees
-
#15
ryder.com 4 employees
-
#16
cognizant.com 2 employees
-
#17
att.com 2 employees
-
#18
ibm.com 2 employees
-
#19
frontier.com 2 employees
-
#20
hp.com 2 employees
Compromised users
-
#1
google.com 51,797 users
-
#2
facebook.com 49,573 users
-
#3
netflix.com 20,531 users
-
#4
amazon.com 15,719 users
-
#5
paypal.com 13,776 users
-
#6
apple.com 10,648 users
-
#7
ebay.com 2,676 users
-
#8
microsoft.com 1,660 users
-
#9
oracle.com 1,650 users
-
#10
cisco.com 1,517 users
-
#11
hp.com 1,471 users
-
#12
nike.com 1,220 users
-
#13
walmart.com 518 users
-
#14
ups.com 463 users
-
#15
intel.com 426 users
-
#16
ibm.com 421 users
-
#17
westernunion.com 412 users
-
#18
adp.com 185 users
-
#19
americanexpress.com 172 users
-
#20
salesforce.com 158 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 185,545hits
- #2 sso 42,074hits
- #3 zoom 18,781hits
- #4 webmail 7,244hits
- #5 github 6,634hits
- #6 adfs 5,640hits
- #7 oracle 3,221hits
- #8 zendesk 2,323hits
- #9 owa 2,319hits
- #10 sap 1,818hits
- #11 ping 1,699hits
- #12 vpn 1,663hits
- #13 cpanel 1,536hits
- #14 sts 1,525hits
- #15 webex 1,415hits
- #16 kaspersky 1,299hits
- #17 extranet 1,246hits
- #18 ftp 1,144hits
- #19 roundcube 760hits
- #20 st 743hits
- #21 okta 600hits
- #22 salesforce 454hits
- #23 gitlab 432hits
- #24 zimbra 285hits
- #25 twilio 285hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains