Infostealers Weekly Report: 2023-06-26 – 2023-07-02
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 5,140
- #2 Vietnam 3,880
- #3 Egypt 3,646
- #4 Philippines 3,152
- #5 India 3,020
- #6 Pakistan 2,551
- #7 United States of America 2,510
- #8 Thailand 1,831
- #9 Mexico 1,811
- #10 Germany 1,646
- #11 Peru 1,585
- #12 Turkey 1,511
- #13 Colombia 1,418
- #14 Spain 1,170
- #15 Indonesia 1,128
- #16 Bangladesh 1,060
- #17 Argentina 1,035
- #18 Algeria 1,002
- #19 Poland 973
- #20 Malaysia 909
- #21 Italy 874
- #22 Sri Lanka 867
- #23 France 865
- #24 Netherlands 764
- #25 China 646
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 24,665 users
-
#2
facebook.com 22,728 users
-
#3
live.com 20,786 users
-
#4
discord.com 10,619 users
-
#5
instagram.com 10,562 users
-
#6
com.facebook.katana 9,959 users
-
#7
netflix.com 9,641 users
-
#8
roblox.com 8,719 users
-
#9
amazon.com 8,230 users
-
#10
twitter.com 7,686 users
-
#11
steampowered.com 7,635 users
-
#12
paypal.com 6,818 users
-
#13
com.instagram.android 6,535 users
-
#14
com.netflix.mediaclient 6,341 users
-
#15
microsoftonline.com 6,298 users
-
#16
mega.nz 6,028 users
-
#17
riotgames.com 5,674 users
-
#18
twitch.tv 5,583 users
-
#19
apple.com 5,426 users
-
#20
linkedin.com 5,363 users
-
#21
spotify.com 5,143 users
-
#22
epicgames.com 5,039 users
-
#23
com.discord 4,651 users
-
#24
steamcommunity.com 4,505 users
-
#25
zoom.us 4,413 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 121 employees
-
#2
freemail.hu 109 employees
-
#3
163.com 100 employees
-
#4
aruba.it 95 employees
-
#5
hostinger.com 85 employees
-
#6
qq.com 79 employees
-
#7
secop.gov.co 73 employees
-
#8
icicibank.com 71 employees
-
#9
interia.pl 70 employees
-
#10
pec.it 69 employees
-
#11
tim.it 63 employees
-
#12
laureate.net 56 employees
-
#13
login.sp.gov.br 56 employees
-
#14
rediff.com 53 employees
-
#15
bcb.gov.br 53 employees
-
#16
sempreser.com.br 50 employees
-
#17
o2.pl 42 employees
-
#18
hostmonster.com 39 employees
-
#19
hust.edu.vn 38 employees
-
#20
ueb.edu.ec 38 employees
-
#21
abv.bg 37 employees
-
#22
banquemisr.com 37 employees
-
#23
menoklapja.hu 36 employees
-
#24
ig.com.br 36 employees
-
#25
arrabonaprint.hu 36 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 22 employees
-
#2
rockwellautomation.com 19 employees
-
#3
boeing.com 6 employees
-
#4
emc.com 4 employees
-
#5
publix.com 4 employees
-
#6
chrobinson.com 4 employees
-
#7
netflix.com 3 employees
-
#8
hp.com 3 employees
-
#9
apple.com 3 employees
-
#10
ups.com 3 employees
-
#11
ball.com 3 employees
-
#12
paypal.com 3 employees
-
#13
ibm.com 2 employees
-
#14
twc.com 2 employees
-
#15
ford.com 2 employees
-
#16
jpmorganchase.com 2 employees
-
#17
oracle.com 2 employees
-
#18
salesforce.com 2 employees
-
#19
amazon.com 2 employees
-
#20
adm.com 1 employees
Compromised users
-
#1
google.com 24,665 users
-
#2
facebook.com 22,728 users
-
#3
netflix.com 9,641 users
-
#4
amazon.com 8,230 users
-
#5
paypal.com 6,818 users
-
#6
apple.com 5,426 users
-
#7
ebay.com 1,253 users
-
#8
oracle.com 917 users
-
#9
microsoft.com 865 users
-
#10
hp.com 751 users
-
#11
cisco.com 721 users
-
#12
nike.com 643 users
-
#13
ibm.com 304 users
-
#14
walmart.com 281 users
-
#15
ups.com 225 users
-
#16
westernunion.com 209 users
-
#17
intel.com 205 users
-
#18
fedex.com 170 users
-
#19
bestbuy.com 130 users
-
#20
target.com 106 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 92,476hits
- #2 sso 25,325hits
- #3 zoom 9,377hits
- #4 github 4,586hits
- #5 webmail 3,879hits
- #6 adfs 3,236hits
- #7 oracle 1,729hits
- #8 sap 1,587hits
- #9 zendesk 1,192hits
- #10 owa 1,176hits
- #11 vpn 1,043hits
- #12 cpanel 1,032hits
- #13 salesforce 922hits
- #14 sts 880hits
- #15 ping 785hits
- #16 webex 704hits
- #17 ftp 669hits
- #18 kaspersky 562hits
- #19 st 538hits
- #20 extranet 493hits
- #21 roundcube 431hits
- #22 okta 349hits
- #23 twilio 285hits
- #24 gitlab 166hits
- #25 jira 157hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains