Skip to content
Weekly intelligence Apr 24 – Apr 30, 2023 13 min read

Infostealers Weekly Report: 2023-04-24 – 2023-04-30

InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…

#1 0 Compromised Machines
#2 0 Compromised Employees
#3 0 Compromised Users
#4 0 Compromised Androids
#5 0 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 206
Infections by country

Top 25 countries

  1. #1 Brazil 11,749
  2. #2 India 11,231
  3. #3 Vietnam 10,900
  4. #4 Egypt 8,183
  5. #5 Mexico 5,642
  6. #6 Peru 4,466
  7. #7 Pakistan 4,408
  8. #8 Philippines 4,375
  9. #9 Colombia 4,131
  10. #10 Indonesia 3,937
  11. #11 Spain 3,917
  12. #12 Turkey 3,847
  13. #13 Argentina 3,311
  14. #14 Algeria 3,118
  15. #15 United States of America 2,986
  16. #16 Thailand 2,920
  17. #17 Morocco 2,694
  18. #18 Bangladesh 2,407
  19. #19 Italy 2,160
  20. #20 Venezuela 1,909
  21. #21 France 1,861
  22. #22 Chile 1,856
  23. #23 Germany 1,855
  24. #24 Dominican Republic 1,801
  25. #25 Malaysia 1,772

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 65,503 users
  2. #2 facebook.com 60,676 users
  3. #3 live.com 55,068 users
  4. #4 instagram.com 27,173 users
  5. #5 com.facebook.katana 26,075 users
  6. #6 discord.com 25,592 users
  7. #7 netflix.com 25,359 users
  8. #8 amazon.com 21,421 users
  9. #9 roblox.com 20,800 users
  10. #10 twitter.com 20,603 users
  11. #11 steampowered.com 18,401 users
  12. #12 microsoftonline.com 17,865 users
  13. #13 paypal.com 17,729 users
  14. #14 com.instagram.android 17,186 users
  15. #15 com.netflix.mediaclient 17,031 users
  16. #16 mega.nz 15,736 users
  17. #17 linkedin.com 15,228 users
  18. #18 twitch.tv 14,300 users
  19. #19 riotgames.com 14,293 users
  20. #20 apple.com 14,250 users
  21. #21 spotify.com 12,628 users
  22. #22 epicgames.com 12,509 users
  23. #23 zoom.us 11,591 users
  24. #24 com.discord 11,536 users
  25. #25 com.spotify.music 10,982 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 icicibank.com 282 employees
  2. #2 wp.pl 267 employees
  3. #3 hostinger.com 253 employees
  4. #4 aruba.it 249 employees
  5. #5 tim.it 194 employees
  6. #6 rediff.com 191 employees
  7. #7 163.com 180 employees
  8. #8 qq.com 160 employees
  9. #9 secop.gov.co 156 employees
  10. #10 laureate.net 146 employees
  11. #11 pec.it 146 employees
  12. #12 bcb.gov.br 136 employees
  13. #13 login.sp.gov.br 117 employees
  14. #14 telecom.pt 117 employees
  15. #15 freemail.hu 114 employees
  16. #16 netpnb.com 109 employees
  17. #17 banquemisr.com 109 employees
  18. #18 abv.bg 107 employees
  19. #19 interia.pl 105 employees
  20. #20 secureserver.net 102 employees
  21. #21 jwpub.org 100 employees
  22. #22 sempreser.com.br 98 employees
  23. #23 atlassian.com 96 employees
  24. #24 ovh.net 95 employees
  25. #25 o2.pl 94 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 rockwellautomation.com 64 employees
  2. #2 microsoft.com 50 employees
  3. #3 ibm.com 25 employees
  4. #4 cognizant.com 16 employees
  5. #5 google.com 15 employees
  6. #6 netflix.com 13 employees
  7. #7 facebook.com 12 employees
  8. #8 publix.com 10 employees
  9. #9 ups.com 10 employees
  10. #10 csc.com 9 employees
  11. #11 hp.com 7 employees
  12. #12 cbre.com 7 employees
  13. #13 amazon.com 6 employees
  14. #14 manpowergroup.com 6 employees
  15. #15 citigroup.com 5 employees
  16. #16 fedex.com 5 employees
  17. #17 twc.com 4 employees
  18. #18 pfizer.com 4 employees
  19. #19 oracle.com 4 employees
  20. #20 cisco.com 3 employees

Compromised users

  1. #1 google.com 65,503 users
  2. #2 facebook.com 60,676 users
  3. #3 netflix.com 25,359 users
  4. #4 amazon.com 21,421 users
  5. #5 paypal.com 17,729 users
  6. #6 apple.com 14,250 users
  7. #7 ebay.com 3,451 users
  8. #8 oracle.com 2,459 users
  9. #9 microsoft.com 2,218 users
  10. #10 hp.com 2,061 users
  11. #11 cisco.com 1,947 users
  12. #12 nike.com 1,617 users
  13. #13 walmart.com 824 users
  14. #14 ibm.com 800 users
  15. #15 ups.com 767 users
  16. #16 westernunion.com 617 users
  17. #17 intel.com 490 users
  18. #18 adp.com 393 users
  19. #19 fedex.com 387 users
  20. #20 bestbuy.com 381 users

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 235,011hits
  2. #2 sso 65,602hits
  3. #3 zoom 25,270hits
  4. #4 github 10,945hits
  5. #5 webmail 10,852hits
  6. #6 adfs 8,444hits
  7. #7 oracle 4,915hits
  8. #8 sap 3,720hits
  9. #9 owa 3,420hits
  10. #10 zendesk 3,394hits
  11. #11 vpn 2,666hits
  12. #12 ping 2,639hits
  13. #13 cpanel 2,492hits
  14. #14 sts 2,271hits
  15. #15 webex 2,021hits
  16. #16 kaspersky 1,706hits
  17. #17 extranet 1,637hits
  18. #18 imap 1,346hits
  19. #19 ftp 1,325hits
  20. #20 salesforce 1,253hits
  21. #21 roundcube 1,203hits
  22. #22 st 1,121hits
  23. #23 okta 870hits
  24. #24 gitlab 709hits
  25. #25 twilio 578hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure