Infostealers Weekly Report: 2023-04-03 – 2023-04-09
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 8,554
- #2 Brazil 6,728
- #3 Egypt 5,470
- #4 Mexico 4,455
- #5 Thailand 3,517
- #6 Philippines 3,469
- #7 United States of America 3,036
- #8 Turkey 2,916
- #9 Colombia 2,766
- #10 Peru 2,483
- #11 Argentina 2,439
- #12 Algeria 2,413
- #13 Bangladesh 2,202
- #14 Morocco 2,168
- #15 Poland 2,116
- #16 Spain 2,060
- #17 Iraq 1,666
- #18 Pakistan 1,535
- #19 Romania 1,405
- #20 South Korea 1,401
- #21 Malaysia 1,360
- #22 Germany 1,347
- #23 Bolivia 1,344
- #24 France 1,318
- #25 Dominican Republic 1,274
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 44,589 users
-
#2
facebook.com 41,502 users
-
#3
live.com 37,913 users
-
#4
discord.com 22,262 users
-
#5
roblox.com 20,685 users
-
#6
netflix.com 18,435 users
-
#7
instagram.com 17,946 users
-
#8
com.facebook.katana 17,892 users
-
#9
steampowered.com 15,520 users
-
#10
twitter.com 14,014 users
-
#11
twitch.tv 13,511 users
-
#12
amazon.com 13,396 users
-
#13
riotgames.com 13,061 users
-
#14
paypal.com 12,235 users
-
#15
microsoftonline.com 12,037 users
-
#16
com.netflix.mediaclient 11,459 users
-
#17
epicgames.com 11,380 users
-
#18
com.instagram.android 10,970 users
-
#19
mega.nz 10,357 users
-
#20
steamcommunity.com 9,928 users
-
#21
spotify.com 9,564 users
-
#22
apple.com 9,564 users
-
#23
com.discord 8,932 users
-
#24
com.roblox.client 8,676 users
-
#25
com.spotify.music 7,941 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 262 employees
-
#2
163.com 156 employees
-
#3
freemail.hu 142 employees
-
#4
interia.pl 140 employees
-
#5
o2.pl 117 employees
-
#6
secop.gov.co 108 employees
-
#7
onet.pl 93 employees
-
#8
qq.com 92 employees
-
#9
skole.hr 89 employees
-
#10
hostinger.com 76 employees
-
#11
banquemisr.com 76 employees
-
#12
aruba.it 75 employees
-
#13
naver.com 72 employees
-
#14
pec.it 70 employees
-
#15
tim.it 68 employees
-
#16
buenosaires.gob.ar 66 employees
-
#17
laureate.net 65 employees
-
#18
hust.edu.vn 61 employees
-
#19
moe.gov.ae 60 employees
-
#20
bcb.gov.br 60 employees
-
#21
cibertec.edu.pe 57 employees
-
#22
secureserver.net 55 employees
-
#23
atlassian.com 53 employees
-
#24
tigo.com.co 52 employees
-
#25
globo.com 52 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 39 employees
-
#2
rockwellautomation.com 34 employees
-
#3
pg.com 8 employees
-
#4
publix.com 7 employees
-
#5
google.com 7 employees
-
#6
netflix.com 7 employees
-
#7
borgwarner.com 5 employees
-
#8
cablevision.com 5 employees
-
#9
cummins.com 5 employees
-
#10
ups.com 5 employees
-
#11
facebook.com 4 employees
-
#12
aig.com 3 employees
-
#13
apple.com 2 employees
-
#14
honeywell.com 2 employees
-
#15
jetblue.com 2 employees
-
#16
cognizant.com 2 employees
-
#17
aramark.com 2 employees
-
#18
nrgenergy.com 2 employees
-
#19
statefarm.com 1 employees
-
#20
kindredhealthcare.com 1 employees
Compromised users
-
#1
google.com 44,589 users
-
#2
facebook.com 41,502 users
-
#3
netflix.com 18,435 users
-
#4
amazon.com 13,396 users
-
#5
paypal.com 12,235 users
-
#6
apple.com 9,564 users
-
#7
ebay.com 2,060 users
-
#8
microsoft.com 1,291 users
-
#9
oracle.com 1,275 users
-
#10
nike.com 1,243 users
-
#11
hp.com 1,177 users
-
#12
cisco.com 1,082 users
-
#13
walmart.com 497 users
-
#14
ups.com 481 users
-
#15
ibm.com 371 users
-
#16
intel.com 369 users
-
#17
westernunion.com 329 users
-
#18
fedex.com 236 users
-
#19
bestbuy.com 233 users
-
#20
target.com 206 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 156,395hits
- #2 sso 39,717hits
- #3 zoom 14,979hits
- #4 github 6,398hits
- #5 adfs 5,148hits
- #6 webmail 4,697hits
- #7 oracle 2,549hits
- #8 sap 2,076hits
- #9 owa 1,760hits
- #10 zendesk 1,734hits
- #11 vpn 1,422hits
- #12 ping 1,337hits
- #13 sts 1,334hits
- #14 cpanel 1,071hits
- #15 webex 1,029hits
- #16 kaspersky 857hits
- #17 st 827hits
- #18 ftp 763hits
- #19 extranet 757hits
- #20 roundcube 571hits
- #21 okta 553hits
- #22 gitlab 362hits
- #23 salesforce 332hits
- #24 twilio 224hits
- #25 jira 211hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains