Infostealers Weekly Report: 2023-05-29 – 2023-06-04
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 7,313
- #2 Vietnam 5,730
- #3 Egypt 5,191
- #4 Philippines 4,649
- #5 Peru 4,433
- #6 Thailand 3,701
- #7 Mexico 3,478
- #8 Pakistan 3,240
- #9 Colombia 3,108
- #10 United States of America 2,566
- #11 Algeria 2,334
- #12 Argentina 2,255
- #13 India 1,974
- #14 Turkey 1,896
- #15 Spain 1,536
- #16 Morocco 1,494
- #17 Germany 1,402
- #18 Bangladesh 1,237
- #19 Indonesia 1,216
- #20 Sri Lanka 1,169
- #21 Malaysia 1,155
- #22 Bolivia 1,139
- #23 Venezuela 1,119
- #24 Poland 987
- #25 Chile 875
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 32,321 users
-
#2
facebook.com 30,109 users
-
#3
live.com 27,981 users
-
#4
discord.com 14,107 users
-
#5
roblox.com 13,734 users
-
#6
instagram.com 13,451 users
-
#7
com.facebook.katana 13,395 users
-
#8
netflix.com 12,865 users
-
#9
steampowered.com 10,379 users
-
#10
twitter.com 9,866 users
-
#11
amazon.com 9,532 users
-
#12
com.netflix.mediaclient 8,819 users
-
#13
com.instagram.android 8,556 users
-
#14
microsoftonline.com 8,498 users
-
#15
riotgames.com 8,290 users
-
#16
paypal.com 8,224 users
-
#17
mega.nz 7,918 users
-
#18
twitch.tv 7,874 users
-
#19
epicgames.com 6,895 users
-
#20
com.roblox.client 6,540 users
-
#21
apple.com 6,400 users
-
#22
spotify.com 6,362 users
-
#23
linkedin.com 6,279 users
-
#24
com.discord 6,203 users
-
#25
steamcommunity.com 5,963 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
laureate.net 132 employees
-
#2
wp.pl 111 employees
-
#3
britanico.edu.pe 74 employees
-
#4
utp.edu.pe 73 employees
-
#5
163.com 69 employees
-
#6
upc.edu.pe 65 employees
-
#7
qq.com 64 employees
-
#8
secop.gov.co 63 employees
-
#9
rockwellautomation.com 57 employees
-
#10
cibertec.edu.pe 53 employees
-
#11
hostinger.com 52 employees
-
#12
login.sp.gov.br 46 employees
-
#13
freemail.hu 46 employees
-
#14
buenosaires.gob.ar 46 employees
-
#15
bcb.gov.br 45 employees
-
#16
telecom.pt 44 employees
-
#17
banquemisr.com 43 employees
-
#18
pronabec.edu.pe 41 employees
-
#19
bluehost.com 40 employees
-
#20
interia.pl 40 employees
-
#21
icicibank.com 39 employees
-
#22
inacap.cl 37 employees
-
#23
aruba.it 37 employees
-
#24
yes.my 36 employees
-
#25
ovh.net 35 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 57 employees
-
#2
microsoft.com 23 employees
-
#3
publix.com 12 employees
-
#4
amazon.com 7 employees
-
#5
ibm.com 7 employees
-
#6
micron.com 6 employees
-
#7
interpublic.com 5 employees
-
#8
facebook.com 5 employees
-
#9
principal.com 5 employees
-
#10
newmont.com 5 employees
-
#11
ups.com 4 employees
-
#12
quintiles.com 4 employees
-
#13
verizon.com 4 employees
-
#14
cognizant.com 3 employees
-
#15
netflix.com 3 employees
-
#16
bakerhughes.com 2 employees
-
#17
jll.com 2 employees
-
#18
bestbuy.com 2 employees
-
#19
hp.com 2 employees
-
#20
firstam.com 1 employees
Compromised users
-
#1
google.com 32,321 users
-
#2
facebook.com 30,109 users
-
#3
netflix.com 12,865 users
-
#4
amazon.com 9,532 users
-
#5
paypal.com 8,224 users
-
#6
apple.com 6,400 users
-
#7
ebay.com 1,161 users
-
#8
microsoft.com 1,059 users
-
#9
oracle.com 928 users
-
#10
cisco.com 925 users
-
#11
hp.com 853 users
-
#12
nike.com 806 users
-
#13
ibm.com 316 users
-
#14
walmart.com 239 users
-
#15
intel.com 224 users
-
#16
ups.com 221 users
-
#17
westernunion.com 203 users
-
#18
fedex.com 126 users
-
#19
bestbuy.com 116 users
-
#20
adp.com 109 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 105,309hits
- #2 sso 28,929hits
- #3 zoom 12,465hits
- #4 github 4,388hits
- #5 adfs 3,455hits
- #6 webmail 3,250hits
- #7 sap 1,939hits
- #8 oracle 1,871hits
- #9 owa 1,473hits
- #10 zendesk 1,216hits
- #11 vpn 1,064hits
- #12 ping 996hits
- #13 sts 930hits
- #14 extranet 898hits
- #15 cpanel 823hits
- #16 webex 766hits
- #17 kaspersky 734hits
- #18 ftp 623hits
- #19 st 553hits
- #20 okta 405hits
- #21 salesforce 374hits
- #22 roundcube 304hits
- #23 gitlab 181hits
- #24 twilio 154hits
- #25 sharepoint 154hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains