Infostealers Weekly Report: 2023-08-28 – 2023-09-03
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 8,362
- #2 Brazil 7,518
- #3 Pakistan 4,026
- #4 Philippines 3,496
- #5 Egypt 2,869
- #6 Thailand 2,772
- #7 Peru 2,692
- #8 Mexico 2,453
- #9 Bangladesh 2,393
- #10 Colombia 2,334
- #11 Algeria 2,270
- #12 Vietnam 2,227
- #13 Poland 2,069
- #14 Spain 1,806
- #15 Argentina 1,633
- #16 Sri Lanka 1,362
- #17 Morocco 1,358
- #18 Venezuela 1,335
- #19 United States of America 1,245
- #20 Germany 1,164
- #21 India 1,111
- #22 Chile 1,074
- #23 Nigeria 1,051
- #24 Ukraine 1,016
- #25 Indonesia 996
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 34,910 users
-
#2
facebook.com 31,802 users
-
#3
live.com 29,021 users
-
#4
instagram.com 14,300 users
-
#5
discord.com 13,537 users
-
#6
com.facebook.katana 13,498 users
-
#7
netflix.com 13,346 users
-
#8
roblox.com 11,849 users
-
#9
steampowered.com 10,234 users
-
#10
amazon.com 9,857 users
-
#11
twitter.com 9,346 users
-
#12
com.instagram.android 9,084 users
-
#13
com.netflix.mediaclient 8,424 users
-
#14
paypal.com 8,342 users
-
#15
mega.nz 7,977 users
-
#16
microsoftonline.com 7,483 users
-
#17
twitch.tv 7,259 users
-
#18
riotgames.com 7,218 users
-
#19
apple.com 7,115 users
-
#20
spotify.com 6,883 users
-
#21
linkedin.com 6,854 users
-
#22
epicgames.com 6,615 users
-
#23
steamcommunity.com 5,982 users
-
#24
com.roblox.client 5,561 users
-
#25
com.discord 5,545 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 274 employees
-
#2
163.com 143 employees
-
#3
yandex.com.tr 128 employees
-
#4
qq.com 125 employees
-
#5
freemail.hu 121 employees
-
#6
o2.pl 117 employees
-
#7
ukr.net 101 employees
-
#8
aruba.it 96 employees
-
#9
interia.pl 92 employees
-
#10
tim.it 90 employees
-
#11
login.sp.gov.br 75 employees
-
#12
onet.pl 74 employees
-
#13
deped.gov.ph 70 employees
-
#14
ig.com.br 68 employees
-
#15
rockwellautomation.com 66 employees
-
#16
secop.gov.co 65 employees
-
#17
sempreser.com.br 61 employees
-
#18
pec.it 59 employees
-
#19
utp.edu.pe 59 employees
-
#20
hostinger.com 55 employees
-
#21
bcb.gov.br 53 employees
-
#22
aiou.edu.pk 53 employees
-
#23
abv.bg 52 employees
-
#24
buenosaires.gob.ar 48 employees
-
#25
fmod.dev 47 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 66 employees
-
#2
microsoft.com 14 employees
-
#3
netflix.com 10 employees
-
#4
cisco.com 9 employees
-
#5
ecolab.com 6 employees
-
#6
cbre.com 5 employees
-
#7
publix.com 3 employees
-
#8
pepsico.com 3 employees
-
#9
techdata.com 2 employees
-
#10
johnsoncontrols.com 2 employees
-
#11
ibm.com 2 employees
-
#12
facebook.com 1 employees
-
#13
abbott.com 1 employees
Compromised users
-
#1
google.com 34,910 users
-
#2
facebook.com 31,802 users
-
#3
netflix.com 13,346 users
-
#4
amazon.com 9,857 users
-
#5
paypal.com 8,342 users
-
#6
apple.com 7,115 users
-
#7
ebay.com 1,533 users
-
#8
microsoft.com 1,046 users
-
#9
hp.com 998 users
-
#10
oracle.com 980 users
-
#11
cisco.com 832 users
-
#12
nike.com 757 users
-
#13
ibm.com 343 users
-
#14
ups.com 307 users
-
#15
westernunion.com 252 users
-
#16
walmart.com 235 users
-
#17
intel.com 231 users
-
#18
americanexpress.com 110 users
-
#19
adp.com 96 users
-
#20
westerndigital.com 91 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 116,895hits
- #2 sso 27,636hits
- #3 zoom 10,863hits
- #4 github 5,165hits
- #5 webmail 4,396hits
- #6 oracle 4,275hits
- #7 adfs 2,941hits
- #8 sap 1,740hits
- #9 owa 1,521hits
- #10 zendesk 1,519hits
- #11 vpn 1,370hits
- #12 sts 1,066hits
- #13 ping 957hits
- #14 kaspersky 943hits
- #15 cpanel 801hits
- #16 webex 752hits
- #17 ftp 701hits
- #18 extranet 663hits
- #19 roundcube 570hits
- #20 st 415hits
- #21 okta 297hits
- #22 gitlab 261hits
- #23 twilio 171hits
- #24 salesforce 164hits
- #25 zimbra 142hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains