Infostealers Weekly Report: 2020-02-03 – 2020-02-09
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 2,080
- #2 Vietnam 1,562
- #3 Pakistan 1,343
- #4 Brazil 1,274
- #5 India 1,160
- #6 Indonesia 1,102
- #7 Egypt 1,075
- #8 Turkey 993
- #9 Spain 786
- #10 Iran 719
- #11 Philippines 692
- #12 Algeria 499
- #13 Bangladesh 491
- #14 Morocco 441
- #15 Romania 425
- #16 Thailand 423
- #17 Germany 398
- #18 Serbia 377
- #19 France 377
- #20 Italy 348
- #21 Argentina 289
- #22 Canada 238
- #23 Nepal 235
- #24 Kenya 231
- #25 Hungary 223
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 16,554 users
-
#2
facebook.com 13,355 users
-
#3
live.com 8,203 users
-
#4
twitter.com 4,444 users
-
#5
netflix.com 3,625 users
-
#6
instagram.com 3,467 users
-
#7
amazon.com 3,324 users
-
#8
paypal.com 3,271 users
-
#9
yahoo.com 3,268 users
-
#10
mega.nz 3,173 users
-
#11
roblox.com 3,145 users
-
#12
discordapp.com 2,974 users
-
#13
com.facebook.katana 2,871 users
-
#14
2,637 users
-
#15
steampowered.com 2,526 users
-
#16
epicgames.com 2,508 users
-
#17
linkedin.com 2,356 users
-
#18
twitch.tv 2,352 users
-
#19
apple.com 2,265 users
-
#20
minecraft.net 2,219 users
-
#21
steamcommunity.com 2,022 users
-
#22
192.168.1.1 2,018 users
-
#23
dropbox.com 1,828 users
-
#24
com.netflix.mediaclient 1,627 users
-
#25
spotify.com 1,611 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 50 employees
-
#2
rediff.com 41 employees
-
#3
freemail.hu 41 employees
-
#4
icicibank.com 37 employees
-
#5
tim.it 34 employees
-
#6
pec.it 27 employees
-
#7
secureserver.net 26 employees
-
#8
bluehost.com 26 employees
-
#9
21 employees
-
#10
abv.bg 21 employees
-
#11
publix.com 19 employees
-
#12
aruba.it 19 employees
-
#13
yandex.com.tr 18 employees
-
#14
sapo.pt 18 employees
-
#15
confused.com 17 employees
-
#16
digimail.in 17 employees
-
#17
hostgator.com 16 employees
-
#18
accenture.com 16 employees
-
#19
163.com 15 employees
-
#20
rmunify.com 15 employees
-
#21
webmail.co.za 14 employees
-
#22
telecom.pt 14 employees
-
#23
ig.com.br 14 employees
-
#24
citromail.hu 14 employees
-
#25
one.com 13 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 19 employees
-
#2
twc.com 8 employees
-
#3
frontier.com 7 employees
-
#4
cognizant.com 6 employees
-
#5
microsoft.com 5 employees
-
#6
bestbuy.com 3 employees
-
#7
rockwellautomation.com 2 employees
-
#8
csc.com 2 employees
-
#9
hp.com 2 employees
-
#10
oracle.com 2 employees
-
#11
apple.com 2 employees
-
#12
ups.com 1 employees
-
#13
utc.com 1 employees
-
#14
johnsoncontrols.com 1 employees
-
#15
dupont.com 1 employees
-
#16
pfizer.com 1 employees
-
#17
libertymutual.com 1 employees
-
#18
nucor.com 1 employees
-
#19
costco.com 1 employees
-
#20
ch2m.com 1 employees
Compromised users
-
#1
google.com 16,552 users
-
#2
facebook.com 13,352 users
-
#3
netflix.com 3,625 users
-
#4
amazon.com 3,324 users
-
#5
paypal.com 3,271 users
-
#6
apple.com 2,265 users
-
#7
ebay.com 1,242 users
-
#8
walmart.com 419 users
-
#9
oracle.com 292 users
-
#10
capitalone.com 260 users
-
#11
adp.com 255 users
-
#12
ups.com 239 users
-
#13
bestbuy.com 236 users
-
#14
att.com 235 users
-
#15
target.com 229 users
-
#16
hp.com 222 users
-
#17
wellsfargo.com 198 users
-
#18
fedex.com 163 users
-
#19
bankofamerica.com 161 users
-
#20
americanexpress.com 144 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 26,837hits
- #2 sso 9,767hits
- #3 webmail 2,175hits
- #4 adfs 2,044hits
- #5 imap 1,667hits
- #6 github 917hits
- #7 owa 780hits
- #8 sap 774hits
- #9 zoom 748hits
- #10 oracle 627hits
- #11 ftp 604hits
- #12 zendesk 555hits
- #13 sts 460hits
- #14 cpanel 420hits
- #15 st 378hits
- #16 vpn 329hits
- #17 ping 300hits
- #18 extranet 255hits
- #19 kaspersky 253hits
- #20 salesforce 246hits
- #21 roundcube 170hits
- #22 citrix 109hits
- #23 webex 105hits
- #24 okta 102hits
- #25 zimbra 89hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains