Infostealers Weekly Report: 2020-01-20 – 2020-01-26
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 805
- #2 Egypt 781
- #3 United States of America 701
- #4 Indonesia 670
- #5 Pakistan 661
- #6 Turkey 569
- #7 India 517
- #8 Vietnam 457
- #9 Philippines 371
- #10 Thailand 318
- #11 Algeria 316
- #12 Morocco 236
- #13 Romania 235
- #14 Serbia 184
- #15 Bangladesh 183
- #16 Hungary 159
- #17 Canada 155
- #18 Argentina 155
- #19 Malaysia 135
- #20 Colombia 130
- #21 Mexico 129
- #22 Portugal 121
- #23 Spain 119
- #24 Kenya 113
- #25 South Africa 108
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 8,591 users
-
#2
facebook.com 7,085 users
-
#3
live.com 4,371 users
-
#4
twitter.com 2,357 users
-
#5
paypal.com 1,898 users
-
#6
mega.nz 1,894 users
-
#7
netflix.com 1,845 users
-
#8
roblox.com 1,786 users
-
#9
discordapp.com 1,743 users
-
#10
yahoo.com 1,719 users
-
#11
instagram.com 1,680 users
-
#12
amazon.com 1,540 users
-
#13
com.facebook.katana 1,433 users
-
#14
steampowered.com 1,361 users
-
#15
epicgames.com 1,306 users
-
#16
linkedin.com 1,217 users
-
#17
apple.com 1,184 users
-
#18
twitch.tv 1,176 users
-
#19
minecraft.net 1,126 users
-
#20
192.168.1.1 1,126 users
-
#21
1,080 users
-
#22
steamcommunity.com 1,051 users
-
#23
dropbox.com 996 users
-
#24
com.netflix.mediaclient 832 users
-
#25
spotify.com 759 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 40 employees
-
#2
nbg.gr 19 employees
-
#3
bluehost.com 18 employees
-
#4
sapo.pt 17 employees
-
#5
telecom.pt 16 employees
-
#6
rediff.com 15 employees
-
#7
secureserver.net 15 employees
-
#8
yandex.com.tr 14 employees
-
#9
tim.it 13 employees
-
#10
13 employees
-
#11
citromail.hu 10 employees
-
#12
http://localhost/wordpress/wp-admin/install.php 9 employees
-
#13
o2.pl 9 employees
-
#14
globo.com 9 employees
-
#15
sgcpanel.com 8 employees
-
#16
abv.bg 8 employees
-
#17
digimail.in 8 employees
-
#18
skole.hr 8 employees
-
#19
netpnb.com 7 employees
-
#20
confused.com 7 employees
-
#21
icicibank.com 7 employees
-
#22
vic.edu.au 7 employees
-
#23
publix.com 7 employees
-
#24
maccabi4u.co.il 7 employees
-
#25
hostgator.com.br 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 7 employees
-
#2
hp.com 4 employees
-
#3
cognizant.com 4 employees
-
#4
twc.com 4 employees
-
#5
rockwellautomation.com 3 employees
-
#6
microsoft.com 3 employees
-
#7
amazon.com 3 employees
-
#8
mmc.com 2 employees
-
#9
frontier.com 2 employees
-
#10
netflix.com 1 employees
-
#11
tjx.com 1 employees
-
#12
bestbuy.com 1 employees
-
#13
chs.net 1 employees
-
#14
google.com 1 employees
-
#15
ford.com 1 employees
-
#16
pg.com 1 employees
-
#17
suntrust.com 1 employees
-
#18
xerox.com 1 employees
-
#19
gm.com 1 employees
-
#20
broadcom.com 1 employees
Compromised users
-
#1
google.com 8,590 users
-
#2
facebook.com 7,085 users
-
#3
paypal.com 1,898 users
-
#4
netflix.com 1,845 users
-
#5
amazon.com 1,540 users
-
#6
apple.com 1,184 users
-
#7
ebay.com 684 users
-
#8
walmart.com 180 users
-
#9
oracle.com 147 users
-
#10
ups.com 111 users
-
#11
capitalone.com 109 users
-
#12
adp.com 94 users
-
#13
att.com 94 users
-
#14
hp.com 90 users
-
#15
wellsfargo.com 88 users
-
#16
bestbuy.com 80 users
-
#17
target.com 75 users
-
#18
cisco.com 68 users
-
#19
fedex.com 68 users
-
#20
bankofamerica.com 59 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 12,697hits
- #2 sso 5,073hits
- #3 webmail 1,248hits
- #4 adfs 852hits
- #5 github 450hits
- #6 sap 385hits
- #7 cpanel 350hits
- #8 owa 329hits
- #9 zendesk 327hits
- #10 oracle 304hits
- #11 ftp 239hits
- #12 sts 232hits
- #13 imap 196hits
- #14 zoom 168hits
- #15 extranet 167hits
- #16 kaspersky 160hits
- #17 st 141hits
- #18 ping 134hits
- #19 vpn 120hits
- #20 salesforce 104hits
- #21 roundcube 66hits
- #22 okta 49hits
- #23 webex 40hits
- #24 dana-na 40hits
- #25 citrix 34hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains