Infostealers Weekly Report: 2020-03-02 – 2020-03-08
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 1,717
- #2 Indonesia 789
- #3 Spain 678
- #4 Egypt 536
- #5 India 497
- #6 Vietnam 491
- #7 Germany 326
- #8 Pakistan 321
- #9 Turkey 281
- #10 Iran 234
- #11 Brazil 228
- #12 Philippines 221
- #13 Algeria 162
- #14 United Kingdom 155
- #15 Canada 132
- #16 France 131
- #17 Thailand 122
- #18 Morocco 108
- #19 Romania 104
- #20 Bangladesh 101
- #21 Israel 92
- #22 Serbia 80
- #23 Nepal 72
- #24 Chile 71
- #25 South Africa 69
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 7,301 users
-
#2
facebook.com 5,422 users
-
#3
live.com 3,743 users
-
#4
twitter.com 2,009 users
-
#5
amazon.com 1,840 users
-
#6
netflix.com 1,776 users
-
#7
paypal.com 1,734 users
-
#8
instagram.com 1,620 users
-
#9
roblox.com 1,596 users
-
#10
discordapp.com 1,489 users
-
#11
yahoo.com 1,450 users
-
#12
epicgames.com 1,380 users
-
#13
twitch.tv 1,357 users
-
#14
minecraft.net 1,325 users
-
#15
steampowered.com 1,253 users
-
#16
mega.nz 1,209 users
-
#17
steamcommunity.com 1,088 users
-
#18
apple.com 1,069 users
-
#19
com.facebook.katana 1,069 users
-
#20
1,066 users
-
#21
linkedin.com 1,023 users
-
#22
spotify.com 936 users
-
#23
dropbox.com 859 users
-
#24
com.netflix.mediaclient 780 users
-
#25
com.spotify.music 779 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 22 employees
-
#2
icicibank.com 21 employees
-
#3
rediff.com 19 employees
-
#4
k12.fl.us 17 employees
-
#5
publix.com 16 employees
-
#6
13 employees
-
#7
secureserver.net 13 employees
-
#8
browardschools.com 11 employees
-
#9
POP3://pop.gmail.com:995 11 employees
-
#10
1and1.es 11 employees
-
#11
orange.es 10 employees
-
#12
rmunify.com 10 employees
-
#13
bluehost.com 10 employees
-
#14
aruba.it 9 employees
-
#15
http://localhost/wordpress/wp-admin/install.php 9 employees
-
#16
vic.edu.au 7 employees
-
#17
accenture.com 7 employees
-
#18
ovh.net 7 employees
-
#19
engelbert-strauss.de 7 employees
-
#20
bni.co.id 7 employees
-
#21
peoplematter.com 7 employees
-
#22
roadrunner.com 6 employees
-
#23
twc.com 6 employees
-
#24
yahoosmallbusiness.com 6 employees
-
#25
nbg.gr 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 16 employees
-
#2
twc.com 6 employees
-
#3
rockwellautomation.com 4 employees
-
#4
frontier.com 3 employees
-
#5
netflix.com 2 employees
-
#6
cognizant.com 2 employees
-
#7
aecom.com 1 employees
-
#8
delta.com 1 employees
-
#9
pvh.com 1 employees
-
#10
pg.com 1 employees
-
#11
google.com 1 employees
-
#12
bestbuy.com 1 employees
-
#13
hp.com 1 employees
-
#14
morganstanley.com 1 employees
-
#15
raytheon.com 1 employees
-
#16
mastercard.com 1 employees
-
#17
fisglobal.com 1 employees
-
#18
libertymutual.com 1 employees
-
#19
costco.com 1 employees
-
#20
allstate.com 1 employees
Compromised users
-
#1
google.com 7,301 users
-
#2
facebook.com 5,422 users
-
#3
amazon.com 1,840 users
-
#4
netflix.com 1,776 users
-
#5
paypal.com 1,734 users
-
#6
apple.com 1,069 users
-
#7
ebay.com 720 users
-
#8
walmart.com 288 users
-
#9
capitalone.com 182 users
-
#10
att.com 176 users
-
#11
ups.com 176 users
-
#12
bestbuy.com 167 users
-
#13
adp.com 163 users
-
#14
wellsfargo.com 153 users
-
#15
target.com 141 users
-
#16
oracle.com 125 users
-
#17
bankofamerica.com 107 users
-
#18
fedex.com 101 users
-
#19
hp.com 99 users
-
#20
americanexpress.com 95 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 12,749hits
- #2 sso 4,594hits
- #3 adfs 1,083hits
- #4 webmail 774hits
- #5 owa 411hits
- #6 st 386hits
- #7 zendesk 373hits
- #8 zoom 371hits
- #9 github 367hits
- #10 sap 324hits
- #11 imap 301hits
- #12 oracle 285hits
- #13 sts 279hits
- #14 ftp 222hits
- #15 ping 194hits
- #16 vpn 180hits
- #17 cpanel 128hits
- #18 extranet 128hits
- #19 kaspersky 116hits
- #20 okta 89hits
- #21 salesforce 75hits
- #22 citrix 67hits
- #23 webex 59hits
- #24 roundcube 53hits
- #25 dana-na 41hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains