Infostealers Weekly Report: 2023-07-24 – 2023-07-30
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 26,426
- #2 India 11,278
- #3 Colombia 10,655
- #4 Mexico 9,473
- #5 Indonesia 9,107
- #6 Argentina 8,809
- #7 Peru 7,602
- #8 Philippines 7,545
- #9 Pakistan 7,416
- #10 Vietnam 7,037
- #11 Egypt 6,446
- #12 United States of America 5,986
- #13 Turkey 5,751
- #14 Thailand 5,436
- #15 Chile 4,983
- #16 Spain 4,818
- #17 Bangladesh 4,673
- #18 Ecuador 4,360
- #19 Germany 3,619
- #20 France 3,433
- #21 Algeria 3,415
- #22 Morocco 2,997
- #23 Bolivia 2,255
- #24 Sri Lanka 1,968
- #25 Venezuela 1,898
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 111,484 users
-
#2
facebook.com 105,765 users
-
#3
live.com 90,782 users
-
#4
discord.com 16,901 users
-
#5
roblox.com 15,608 users
-
#6
yahoo.com 15,544 users
-
#7
com.facebook.katana 15,362 users
-
#8
instagram.com 15,170 users
-
#9
netflix.com 14,341 users
-
#10
steampowered.com 11,823 users
-
#11
twitter.com 11,164 users
-
#12
amazon.com 10,994 users
-
#13
microsoftonline.com 9,685 users
-
#14
com.instagram.android 9,665 users
-
#15
com.netflix.mediaclient 9,292 users
-
#16
riotgames.com 9,291 users
-
#17
paypal.com 9,035 users
-
#18
twitch.tv 8,807 users
-
#19
mega.nz 8,606 users
-
#20
epicgames.com 7,939 users
-
#21
apple.com 7,455 users
-
#22
spotify.com 7,269 users
-
#23
com.roblox.client 7,115 users
-
#24
linkedin.com 6,944 users
-
#25
com.discord 6,672 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 141 employees
-
#2
163.com 110 employees
-
#3
hostinger.com 107 employees
-
#4
utp.edu.pe 101 employees
-
#5
laureate.net 99 employees
-
#6
bcb.gov.br 97 employees
-
#7
secop.gov.co 81 employees
-
#8
aruba.it 71 employees
-
#9
qq.com 68 employees
-
#10
sts.net.pk 67 employees
-
#11
login.sp.gov.br 66 employees
-
#12
rockwellautomation.com 64 employees
-
#13
fmod.dev 64 employees
-
#14
inacap.cl 61 employees
-
#15
utpl.edu.ec 59 employees
-
#16
bluehost.com 59 employees
-
#17
deped.gov.ph 58 employees
-
#18
sempreser.com.br 57 employees
-
#19
isacombank.com.vn 50 employees
-
#20
000webhostapp.com 50 employees
-
#21
jwpub.org 49 employees
-
#22
interia.pl 48 employees
-
#23
tim.it 46 employees
-
#24
hust.edu.vn 45 employees
-
#25
pec.it 45 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 64 employees
-
#2
microsoft.com 31 employees
-
#3
att.com 10 employees
-
#4
manpowergroup.com 9 employees
-
#5
publix.com 8 employees
-
#6
goodyear.com 7 employees
-
#7
essendant.com 4 employees
-
#8
netflix.com 3 employees
-
#9
bestbuy.com 3 employees
-
#10
statestreet.com 2 employees
-
#11
cbre.com 2 employees
-
#12
ups.com 2 employees
-
#13
amazon.com 2 employees
-
#14
pepsico.com 2 employees
-
#15
vfc.com 2 employees
-
#16
gm.com 2 employees
-
#17
abbott.com 2 employees
-
#18
cognizant.com 2 employees
-
#19
paypal.com 1 employees
-
#20
twc.com 1 employees
Compromised users
-
#1
google.com 111,484 users
-
#2
facebook.com 105,765 users
-
#3
netflix.com 14,341 users
-
#4
amazon.com 10,994 users
-
#5
paypal.com 9,035 users
-
#6
apple.com 7,455 users
-
#7
ebay.com 1,542 users
-
#8
microsoft.com 1,195 users
-
#9
oracle.com 1,166 users
-
#10
hp.com 950 users
-
#11
cisco.com 948 users
-
#12
nike.com 797 users
-
#13
walmart.com 382 users
-
#14
ibm.com 320 users
-
#15
westernunion.com 285 users
-
#16
ups.com 258 users
-
#17
fedex.com 221 users
-
#18
intel.com 218 users
-
#19
bestbuy.com 160 users
-
#20
adp.com 134 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 125,949hits
- #2 sso 33,618hits
- #3 zoom 12,632hits
- #4 github 5,421hits
- #5 adfs 4,229hits
- #6 webmail 4,107hits
- #7 sap 2,199hits
- #8 oracle 2,195hits
- #9 owa 1,983hits
- #10 zendesk 1,458hits
- #11 vpn 1,265hits
- #12 cpanel 1,177hits
- #13 ping 1,115hits
- #14 sts 1,063hits
- #15 webex 1,056hits
- #16 kaspersky 883hits
- #17 extranet 792hits
- #18 ftp 599hits
- #19 st 583hits
- #20 roundcube 464hits
- #21 okta 397hits
- #22 salesforce 339hits
- #23 gitlab 337hits
- #24 twilio 183hits
- #25 jira 151hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains