Infostealers Weekly Report: 2020-02-10 – 2020-02-16
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 475
- #2 United States of America 254
- #3 Turkey 116
- #4 Pakistan 102
- #5 Brazil 84
- #6 Egypt 83
- #7 Indonesia 78
- #8 Philippines 61
- #9 South Africa 59
- #10 Germany 58
- #11 Algeria 56
- #12 Australia 42
- #13 Argentina 39
- #14 Canada 37
- #15 Romania 34
- #16 Morocco 34
- #17 Spain 32
- #18 Russia 32
- #19 Serbia 32
- #20 Bangladesh 30
- #21 Thailand 29
- #22 Kenya 20
- #23 India 18
- #24 Malaysia 16
- #25 France 15
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,868 users
-
#2
facebook.com 1,491 users
-
#3
live.com 955 users
-
#4
roblox.com 559 users
-
#5
twitter.com 508 users
-
#6
paypal.com 449 users
-
#7
netflix.com 439 users
-
#8
discordapp.com 418 users
-
#9
twitch.tv 381 users
-
#10
amazon.com 380 users
-
#11
instagram.com 373 users
-
#12
epicgames.com 356 users
-
#13
steampowered.com 351 users
-
#14
yahoo.com 344 users
-
#15
minecraft.net 336 users
-
#16
steamcommunity.com 321 users
-
#17
mega.nz 321 users
-
#18
com.facebook.katana 292 users
-
#19
apple.com 283 users
-
#20
linkedin.com 245 users
-
#21
spotify.com 241 users
-
#22
sonyentertainmentnetwork.com 216 users
-
#23
215 users
-
#24
dropbox.com 193 users
-
#25
192.168.1.1 192 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 4 employees
-
#2
ovh.net 4 employees
-
#3
nbg.gr 3 employees
-
#4
ftp://117.3.169.92/ 3 employees
-
#5
saint-lukes.org 3 employees
-
#6
ftp://113.160.245.72/ 3 employees
-
#7
sapo.pt 3 employees
-
#8
zing.vn 3 employees
-
#9
192.168.4.189 3 employees
-
#10
ftp://27.118.28.235/ 3 employees
-
#11
isacombank.com.vn 3 employees
-
#12
abv.bg 3 employees
-
#13
confused.com 3 employees
-
#14
arcor.de 3 employees
-
#15
mbbank.com.vn 3 employees
-
#16
tnmtquangnam.gov.vn 3 employees
-
#17
sa.edu.au 3 employees
-
#18
snhu.edu 3 employees
-
#19
bluehost.com 3 employees
-
#20
freenet.de 3 employees
-
#21
http://localhost/vission/wp-admin/install.php 2 employees
-
#22
remax.com.ec 2 employees
-
#23
zetkay.com 2 employees
-
#24
seznam.cz 2 employees
-
#25
aliceadsl.fr 2 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 4 employees
-
#2
hp.com 1 employees
-
#3
broadcom.com 1 employees
-
#4
frontier.com 1 employees
-
#5
davita.com 1 employees
-
#6
twc.com 1 employees
Compromised users
-
#1
google.com 1,868 users
-
#2
facebook.com 1,491 users
-
#3
paypal.com 449 users
-
#4
netflix.com 439 users
-
#5
amazon.com 380 users
-
#6
apple.com 283 users
-
#7
ebay.com 145 users
-
#8
capitalone.com 51 users
-
#9
walmart.com 51 users
-
#10
ups.com 47 users
-
#11
att.com 40 users
-
#12
adp.com 35 users
-
#13
bestbuy.com 32 users
-
#14
target.com 31 users
-
#15
oracle.com 31 users
-
#16
fedex.com 30 users
-
#17
wellsfargo.com 29 users
-
#18
westernunion.com 26 users
-
#19
nike.com 22 users
-
#20
bankofamerica.com 21 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,485hits
- #2 sso 1,351hits
- #3 adfs 220hits
- #4 webmail 198hits
- #5 github 137hits
- #6 zoom 109hits
- #7 sap 105hits
- #8 owa 90hits
- #9 ftp 80hits
- #10 cpanel 75hits
- #11 salesforce 74hits
- #12 sts 69hits
- #13 oracle 65hits
- #14 zendesk 56hits
- #15 imap 54hits
- #16 ping 39hits
- #17 vpn 37hits
- #18 st 35hits
- #19 kaspersky 35hits
- #20 extranet 22hits
- #21 webex 13hits
- #22 roundcube 12hits
- #23 git 12hits
- #24 okta 11hits
- #25 zimbra 10hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains