Infostealers Weekly Report: 2019-12-30 – 2020-01-05
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 1,747
- #2 Turkey 1,579
- #3 India 1,159
- #4 United States of America 1,158
- #5 Pakistan 1,125
- #6 Brazil 922
- #7 Indonesia 894
- #8 Philippines 671
- #9 Thailand 659
- #10 Romania 593
- #11 Egypt 590
- #12 Iran 511
- #13 Italy 391
- #14 Morocco 390
- #15 Poland 322
- #16 Serbia 317
- #17 Malaysia 286
- #18 Russia 266
- #19 Bangladesh 262
- #20 Argentina 250
- #21 Spain 241
- #22 Hungary 234
- #23 Mexico 231
- #24 Portugal 230
- #25 South Africa 219
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 14,169 users
-
#2
facebook.com 10,477 users
-
#3
live.com 7,102 users
-
#4
twitter.com 3,608 users
-
#5
roblox.com 2,977 users
-
#6
netflix.com 2,952 users
-
#7
instagram.com 2,812 users
-
#8
discordapp.com 2,787 users
-
#9
mega.nz 2,741 users
-
#10
yahoo.com 2,541 users
-
#11
paypal.com 2,441 users
-
#12
amazon.com 2,387 users
-
#13
2,236 users
-
#14
com.facebook.katana 2,193 users
-
#15
steampowered.com 2,181 users
-
#16
epicgames.com 2,172 users
-
#17
linkedin.com 2,080 users
-
#18
twitch.tv 1,924 users
-
#19
steamcommunity.com 1,890 users
-
#20
minecraft.net 1,747 users
-
#21
apple.com 1,739 users
-
#22
192.168.1.1 1,674 users
-
#23
dropbox.com 1,423 users
-
#24
ea.com 1,222 users
-
#25
spotify.com 1,203 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 50 employees
-
#2
rediff.com 43 employees
-
#3
POP3://pop.gmail.com:995 42 employees
-
#4
40 employees
-
#5
telecom.pt 33 employees
-
#6
o2.pl 32 employees
-
#7
abv.bg 30 employees
-
#8
icicibank.com 29 employees
-
#9
tim.it 29 employees
-
#10
interia.pl 27 employees
-
#11
onet.pl 25 employees
-
#12
secureserver.net 24 employees
-
#13
yandex.com.tr 22 employees
-
#14
sapo.pt 22 employees
-
#15
aruba.it 21 employees
-
#16
citromail.hu 21 employees
-
#17
pec.it 20 employees
-
#18
http://localhost/wordpress/wp-admin/install.php 18 employees
-
#19
ftp://hoanh.biz/ 16 employees
-
#20
inbox.lv 15 employees
-
#21
accenture.com 14 employees
-
#22
telkomsa.net 14 employees
-
#23
digimail.in 12 employees
-
#24
163.com 12 employees
-
#25
netpnb.com 11 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 6 employees
-
#2
twc.com 5 employees
-
#3
cognizant.com 4 employees
-
#4
amazon.com 4 employees
-
#5
frontier.com 3 employees
-
#6
apple.com 2 employees
-
#7
netflix.com 2 employees
-
#8
microsoft.com 2 employees
-
#9
ge.com 2 employees
-
#10
cbre.com 2 employees
-
#11
oracle.com 1 employees
-
#12
jll.com 1 employees
-
#13
ibm.com 1 employees
-
#14
bms.com 1 employees
-
#15
borgwarner.com 1 employees
-
#16
humana.com 1 employees
-
#17
entergy.com 1 employees
-
#18
gapinc.com 1 employees
-
#19
csc.com 1 employees
-
#20
lear.com 1 employees
Compromised users
-
#1
google.com 14,161 users
-
#2
facebook.com 10,472 users
-
#3
netflix.com 2,952 users
-
#4
paypal.com 2,441 users
-
#5
amazon.com 2,387 users
-
#6
apple.com 1,739 users
-
#7
ebay.com 943 users
-
#8
oracle.com 223 users
-
#9
walmart.com 181 users
-
#10
hp.com 125 users
-
#11
ups.com 118 users
-
#12
microsoft.com 99 users
-
#13
adp.com 94 users
-
#14
bestbuy.com 94 users
-
#15
capitalone.com 93 users
-
#16
att.com 91 users
-
#17
target.com 87 users
-
#18
nike.com 79 users
-
#19
westernunion.com 79 users
-
#20
cisco.com 68 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 18,604hits
- #2 sso 8,406hits
- #3 webmail 1,681hits
- #4 adfs 1,125hits
- #5 imap 1,030hits
- #6 github 697hits
- #7 sap 596hits
- #8 cpanel 586hits
- #9 ftp 579hits
- #10 owa 517hits
- #11 oracle 471hits
- #12 zendesk 336hits
- #13 sts 316hits
- #14 ping 249hits
- #15 zoom 247hits
- #16 st 244hits
- #17 kaspersky 235hits
- #18 vpn 181hits
- #19 extranet 148hits
- #20 roundcube 111hits
- #21 salesforce 98hits
- #22 webex 63hits
- #23 citrix 61hits
- #24 gitlab 57hits
- #25 okta 51hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains