Infostealers Weekly Report: 2023-06-12 – 2023-06-18
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 6,409
- #2 Thailand 5,074
- #3 Egypt 4,765
- #4 Philippines 3,835
- #5 Vietnam 3,594
- #6 Pakistan 3,047
- #7 Peru 3,007
- #8 Turkey 2,744
- #9 United States of America 2,605
- #10 Mexico 2,548
- #11 India 2,460
- #12 Colombia 1,770
- #13 Spain 1,698
- #14 Germany 1,670
- #15 Algeria 1,550
- #16 Argentina 1,550
- #17 Bangladesh 1,437
- #18 Indonesia 1,227
- #19 Morocco 1,127
- #20 France 1,018
- #21 Netherlands 1,015
- #22 Sri Lanka 1,011
- #23 Saudi Arabia 962
- #24 Italy 931
- #25 Poland 917
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 32,675 users
-
#2
facebook.com 30,399 users
-
#3
live.com 27,534 users
-
#4
discord.com 14,167 users
-
#5
com.facebook.katana 14,097 users
-
#6
instagram.com 13,798 users
-
#7
roblox.com 13,251 users
-
#8
netflix.com 12,604 users
-
#9
steampowered.com 9,972 users
-
#10
twitter.com 9,703 users
-
#11
amazon.com 9,566 users
-
#12
com.instagram.android 9,016 users
-
#13
com.netflix.mediaclient 8,704 users
-
#14
microsoftonline.com 8,483 users
-
#15
riotgames.com 8,173 users
-
#16
paypal.com 7,868 users
-
#17
twitch.tv 7,712 users
-
#18
mega.nz 7,241 users
-
#19
epicgames.com 6,930 users
-
#20
linkedin.com 6,701 users
-
#21
apple.com 6,641 users
-
#22
com.roblox.client 6,544 users
-
#23
spotify.com 6,290 users
-
#24
com.discord 6,179 users
-
#25
steamcommunity.com 5,774 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 124 employees
-
#2
163.com 103 employees
-
#3
laureate.net 99 employees
-
#4
hostinger.com 89 employees
-
#5
utp.edu.pe 80 employees
-
#6
qq.com 71 employees
-
#7
deped.gov.ph 71 employees
-
#8
aruba.it 65 employees
-
#9
login.sp.gov.br 62 employees
-
#10
icicibank.com 59 employees
-
#11
freemail.hu 59 employees
-
#12
tim.it 59 employees
-
#13
banquemisr.com 55 employees
-
#14
sempreser.com.br 54 employees
-
#15
fmod.dev 53 employees
-
#16
secureserver.net 51 employees
-
#17
secop.gov.co 51 employees
-
#18
telecom.pt 51 employees
-
#19
jwpub.org 50 employees
-
#20
bcb.gov.br 48 employees
-
#21
rediff.com 46 employees
-
#22
sapo.pt 46 employees
-
#23
upc.edu.pe 45 employees
-
#24
pec.it 44 employees
-
#25
buenosaires.gob.ar 43 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 40 employees
-
#2
microsoft.com 20 employees
-
#3
netflix.com 8 employees
-
#4
henryschein.com 7 employees
-
#5
mattel.com 6 employees
-
#6
ibm.com 6 employees
-
#7
quantaservices.com 5 employees
-
#8
emc.com 4 employees
-
#9
google.com 4 employees
-
#10
hp.com 4 employees
-
#11
gm.com 3 employees
-
#12
amazon.com 3 employees
-
#13
newmont.com 2 employees
-
#14
honeywell.com 2 employees
-
#15
stryker.com 2 employees
-
#16
paypal.com 2 employees
-
#17
manpowergroup.com 2 employees
-
#18
jetblue.com 1 employees
-
#19
pg.com 1 employees
-
#20
wm.com 1 employees
Compromised users
-
#1
google.com 32,675 users
-
#2
facebook.com 30,399 users
-
#3
netflix.com 12,604 users
-
#4
amazon.com 9,566 users
-
#5
paypal.com 7,868 users
-
#6
apple.com 6,641 users
-
#7
ebay.com 1,305 users
-
#8
microsoft.com 952 users
-
#9
oracle.com 907 users
-
#10
nike.com 906 users
-
#11
cisco.com 828 users
-
#12
hp.com 810 users
-
#13
ibm.com 260 users
-
#14
walmart.com 248 users
-
#15
ups.com 236 users
-
#16
westernunion.com 205 users
-
#17
intel.com 202 users
-
#18
adp.com 126 users
-
#19
fedex.com 122 users
-
#20
att.com 103 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 118,142hits
- #2 sso 34,280hits
- #3 zoom 12,882hits
- #4 github 5,048hits
- #5 webmail 4,241hits
- #6 adfs 3,926hits
- #7 sap 2,418hits
- #8 oracle 1,884hits
- #9 zendesk 1,646hits
- #10 owa 1,534hits
- #11 vpn 1,282hits
- #12 ping 1,170hits
- #13 cpanel 1,130hits
- #14 sts 1,040hits
- #15 extranet 903hits
- #16 webex 827hits
- #17 kaspersky 683hits
- #18 st 633hits
- #19 ftp 626hits
- #20 roundcube 553hits
- #21 salesforce 414hits
- #22 okta 348hits
- #23 gitlab 234hits
- #24 twilio 224hits
- #25 sharepoint 179hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains