Infostealers Weekly Report: 2023-04-10 – 2023-04-16
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 9,457
- #2 Mexico 5,492
- #3 Brazil 5,404
- #4 Philippines 3,888
- #5 Egypt 3,705
- #6 Turkey 3,178
- #7 Peru 2,917
- #8 Colombia 2,866
- #9 Thailand 2,700
- #10 Argentina 2,407
- #11 Spain 2,265
- #12 Morocco 2,263
- #13 Algeria 2,079
- #14 Poland 1,934
- #15 Romania 1,843
- #16 Iraq 1,702
- #17 United States of America 1,610
- #18 Bolivia 1,498
- #19 Bangladesh 1,376
- #20 Germany 1,350
- #21 Chile 1,296
- #22 Ecuador 1,219
- #23 Pakistan 1,189
- #24 Sri Lanka 1,185
- #25 South Korea 1,181
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 38,882 users
-
#2
facebook.com 37,585 users
-
#3
live.com 33,432 users
-
#4
discord.com 17,985 users
-
#5
roblox.com 17,404 users
-
#6
com.facebook.katana 15,957 users
-
#7
netflix.com 15,952 users
-
#8
instagram.com 15,494 users
-
#9
steampowered.com 13,163 users
-
#10
twitter.com 11,804 users
-
#11
amazon.com 11,691 users
-
#12
riotgames.com 11,051 users
-
#13
twitch.tv 10,582 users
-
#14
microsoftonline.com 10,438 users
-
#15
com.netflix.mediaclient 10,413 users
-
#16
paypal.com 9,953 users
-
#17
com.instagram.android 9,338 users
-
#18
epicgames.com 9,142 users
-
#19
mega.nz 9,067 users
-
#20
apple.com 8,317 users
-
#21
steamcommunity.com 8,264 users
-
#22
spotify.com 8,003 users
-
#23
com.roblox.client 7,763 users
-
#24
com.discord 7,642 users
-
#25
linkedin.com 6,983 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 216 employees
-
#2
freemail.hu 174 employees
-
#3
163.com 134 employees
-
#4
skole.hr 129 employees
-
#5
utp.edu.pe 111 employees
-
#6
hostinger.com 106 employees
-
#7
o2.pl 106 employees
-
#8
interia.pl 104 employees
-
#9
buenosaires.gob.ar 99 employees
-
#10
tim.it 94 employees
-
#11
aruba.it 86 employees
-
#12
onet.pl 83 employees
-
#13
qq.com 78 employees
-
#14
abv.bg 75 employees
-
#15
laureate.net 73 employees
-
#16
telecom.pt 71 employees
-
#17
isacombank.com.vn 64 employees
-
#18
secureserver.net 63 employees
-
#19
secop.gov.co 63 employees
-
#20
upc.edu.pe 60 employees
-
#21
hust.edu.vn 58 employees
-
#22
jwpub.org 58 employees
-
#23
naver.com 56 employees
-
#24
inacap.cl 56 employees
-
#25
correo.com.uy 55 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 36 employees
-
#2
microsoft.com 21 employees
-
#3
csc.com 14 employees
-
#4
apple.com 10 employees
-
#5
abm.com 8 employees
-
#6
nike.com 8 employees
-
#7
quintiles.com 7 employees
-
#8
manpowergroup.com 7 employees
-
#9
amazon.com 6 employees
-
#10
xerox.com 5 employees
-
#11
netflix.com 5 employees
-
#12
att.com 5 employees
-
#13
pepsico.com 4 employees
-
#14
ups.com 4 employees
-
#15
publix.com 3 employees
-
#16
facebook.com 3 employees
-
#17
hp.com 2 employees
-
#18
gm.com 2 employees
-
#19
oracle.com 1 employees
-
#20
intel.com 1 employees
Compromised users
-
#1
google.com 38,882 users
-
#2
facebook.com 37,585 users
-
#3
netflix.com 15,952 users
-
#4
amazon.com 11,691 users
-
#5
paypal.com 9,953 users
-
#6
apple.com 8,317 users
-
#7
ebay.com 1,609 users
-
#8
oracle.com 1,209 users
-
#9
microsoft.com 1,141 users
-
#10
hp.com 1,065 users
-
#11
nike.com 1,034 users
-
#12
cisco.com 932 users
-
#13
walmart.com 429 users
-
#14
intel.com 351 users
-
#15
ibm.com 313 users
-
#16
ups.com 289 users
-
#17
westernunion.com 228 users
-
#18
fedex.com 184 users
-
#19
adp.com 156 users
-
#20
bestbuy.com 139 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 131,967hits
- #2 sso 35,636hits
- #3 zoom 13,646hits
- #4 github 5,576hits
- #5 webmail 4,436hits
- #6 adfs 4,063hits
- #7 oracle 2,794hits
- #8 owa 2,262hits
- #9 zendesk 1,750hits
- #10 cpanel 1,462hits
- #11 sap 1,397hits
- #12 vpn 1,236hits
- #13 ping 1,146hits
- #14 sts 1,089hits
- #15 extranet 965hits
- #16 roundcube 920hits
- #17 webex 836hits
- #18 kaspersky 827hits
- #19 ftp 794hits
- #20 st 535hits
- #21 salesforce 410hits
- #22 okta 391hits
- #23 gitlab 249hits
- #24 twilio 200hits
- #25 sharepoint 156hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains