Skip to content
Weekly intelligence Apr 3 – Apr 9, 2023 12 min read

Infostealers Weekly Report: 2023-04-03 – 2023-04-09

InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…

#1 0 Compromised Machines
#2 0 Compromised Employees
#3 0 Compromised Users
#4 0 Compromised Androids
#5 0 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 193
Infections by country

Top 25 countries

  1. #1 Vietnam 8,554
  2. #2 Brazil 6,728
  3. #3 Egypt 5,470
  4. #4 Mexico 4,455
  5. #5 Thailand 3,517
  6. #6 Philippines 3,469
  7. #7 United States of America 3,036
  8. #8 Turkey 2,916
  9. #9 Colombia 2,766
  10. #10 Peru 2,483
  11. #11 Argentina 2,439
  12. #12 Algeria 2,413
  13. #13 Bangladesh 2,202
  14. #14 Morocco 2,168
  15. #15 Poland 2,116
  16. #16 Spain 2,060
  17. #17 Iraq 1,666
  18. #18 Pakistan 1,535
  19. #19 Romania 1,405
  20. #20 South Korea 1,401
  21. #21 Malaysia 1,360
  22. #22 Germany 1,347
  23. #23 Bolivia 1,344
  24. #24 France 1,318
  25. #25 Dominican Republic 1,274

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 44,589 users
  2. #2 facebook.com 41,502 users
  3. #3 live.com 37,913 users
  4. #4 discord.com 22,262 users
  5. #5 roblox.com 20,685 users
  6. #6 netflix.com 18,435 users
  7. #7 instagram.com 17,946 users
  8. #8 com.facebook.katana 17,892 users
  9. #9 steampowered.com 15,520 users
  10. #10 twitter.com 14,014 users
  11. #11 twitch.tv 13,511 users
  12. #12 amazon.com 13,396 users
  13. #13 riotgames.com 13,061 users
  14. #14 paypal.com 12,235 users
  15. #15 microsoftonline.com 12,037 users
  16. #16 com.netflix.mediaclient 11,459 users
  17. #17 epicgames.com 11,380 users
  18. #18 com.instagram.android 10,970 users
  19. #19 mega.nz 10,357 users
  20. #20 steamcommunity.com 9,928 users
  21. #21 spotify.com 9,564 users
  22. #22 apple.com 9,564 users
  23. #23 com.discord 8,932 users
  24. #24 com.roblox.client 8,676 users
  25. #25 com.spotify.music 7,941 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 wp.pl 262 employees
  2. #2 163.com 156 employees
  3. #3 freemail.hu 142 employees
  4. #4 interia.pl 140 employees
  5. #5 o2.pl 117 employees
  6. #6 secop.gov.co 108 employees
  7. #7 onet.pl 93 employees
  8. #8 qq.com 92 employees
  9. #9 skole.hr 89 employees
  10. #10 hostinger.com 76 employees
  11. #11 banquemisr.com 76 employees
  12. #12 aruba.it 75 employees
  13. #13 naver.com 72 employees
  14. #14 pec.it 70 employees
  15. #15 tim.it 68 employees
  16. #16 buenosaires.gob.ar 66 employees
  17. #17 laureate.net 65 employees
  18. #18 hust.edu.vn 61 employees
  19. #19 moe.gov.ae 60 employees
  20. #20 bcb.gov.br 60 employees
  21. #21 cibertec.edu.pe 57 employees
  22. #22 secureserver.net 55 employees
  23. #23 atlassian.com 53 employees
  24. #24 tigo.com.co 52 employees
  25. #25 globo.com 52 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 microsoft.com 39 employees
  2. #2 rockwellautomation.com 34 employees
  3. #3 pg.com 8 employees
  4. #4 publix.com 7 employees
  5. #5 google.com 7 employees
  6. #6 netflix.com 7 employees
  7. #7 borgwarner.com 5 employees
  8. #8 cablevision.com 5 employees
  9. #9 cummins.com 5 employees
  10. #10 ups.com 5 employees
  11. #11 facebook.com 4 employees
  12. #12 aig.com 3 employees
  13. #13 apple.com 2 employees
  14. #14 honeywell.com 2 employees
  15. #15 jetblue.com 2 employees
  16. #16 cognizant.com 2 employees
  17. #17 aramark.com 2 employees
  18. #18 nrgenergy.com 2 employees
  19. #19 statefarm.com 1 employees
  20. #20 kindredhealthcare.com 1 employees

Compromised users

  1. #1 google.com 44,589 users
  2. #2 facebook.com 41,502 users
  3. #3 netflix.com 18,435 users
  4. #4 amazon.com 13,396 users
  5. #5 paypal.com 12,235 users
  6. #6 apple.com 9,564 users
  7. #7 ebay.com 2,060 users
  8. #8 microsoft.com 1,291 users
  9. #9 oracle.com 1,275 users
  10. #10 nike.com 1,243 users
  11. #11 hp.com 1,177 users
  12. #12 cisco.com 1,082 users
  13. #13 walmart.com 497 users
  14. #14 ups.com 481 users
  15. #15 ibm.com 371 users
  16. #16 intel.com 369 users
  17. #17 westernunion.com 329 users
  18. #18 fedex.com 236 users
  19. #19 bestbuy.com 233 users
  20. #20 target.com 206 users

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 156,395hits
  2. #2 sso 39,717hits
  3. #3 zoom 14,979hits
  4. #4 github 6,398hits
  5. #5 adfs 5,148hits
  6. #6 webmail 4,697hits
  7. #7 oracle 2,549hits
  8. #8 sap 2,076hits
  9. #9 owa 1,760hits
  10. #10 zendesk 1,734hits
  11. #11 vpn 1,422hits
  12. #12 ping 1,337hits
  13. #13 sts 1,334hits
  14. #14 cpanel 1,071hits
  15. #15 webex 1,029hits
  16. #16 kaspersky 857hits
  17. #17 st 827hits
  18. #18 ftp 763hits
  19. #19 extranet 757hits
  20. #20 roundcube 571hits
  21. #21 okta 553hits
  22. #22 gitlab 362hits
  23. #23 salesforce 332hits
  24. #24 twilio 224hits
  25. #25 jira 211hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure