Infostealers Weekly Report: 2020-07-06 – 2020-07-12
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 6,089
- #2 United States of America 2,995
- #3 Brazil 2,338
- #4 Indonesia 2,176
- #5 Pakistan 1,397
- #6 Turkey 1,298
- #7 Philippines 1,212
- #8 Egypt 986
- #9 Mexico 886
- #10 Vietnam 776
- #11 Spain 763
- #12 Thailand 682
- #13 Bangladesh 627
- #14 France 613
- #15 Germany 555
- #16 Argentina 550
- #17 Colombia 520
- #18 Algeria 489
- #19 Russia 481
- #20 Morocco 454
- #21 Nigeria 433
- #22 Poland 375
- #23 Malaysia 364
- #24 Peru 354
- #25 South Africa 335
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 27,318 users
-
#2
facebook.com 20,920 users
-
#3
live.com 14,862 users
-
#4
twitter.com 7,159 users
-
#5
netflix.com 6,627 users
-
#6
amazon.com 6,475 users
-
#7
instagram.com 6,034 users
-
#8
paypal.com 5,784 users
-
#9
mega.nz 5,403 users
-
#10
yahoo.com 4,912 users
-
#11
linkedin.com 4,693 users
-
#12
com.facebook.katana 4,431 users
-
#13
roblox.com 4,190 users
-
#14
3,855 users
-
#15
epicgames.com 3,623 users
-
#16
steampowered.com 3,560 users
-
#17
twitch.tv 3,558 users
-
#18
apple.com 3,453 users
-
#19
discordapp.com 3,312 users
-
#20
microsoftonline.com 3,247 users
-
#21
dropbox.com 3,009 users
-
#22
com.netflix.mediaclient 3,005 users
-
#23
discord.com 2,846 users
-
#24
minecraft.net 2,766 users
-
#25
steamcommunity.com 2,754 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 185 employees
-
#2
icicibank.com 121 employees
-
#3
digimail.in 96 employees
-
#4
accenture.com 75 employees
-
#5
74 employees
-
#6
onlinesbi.com 58 employees
-
#7
secureserver.net 58 employees
-
#8
o2.pl 49 employees
-
#9
interia.pl 49 employees
-
#10
http://localhost/wordpress/wp-admin/install.php 40 employees
-
#11
ovh.net 36 employees
-
#12
publix.com 35 employees
-
#13
onet.pl 34 employees
-
#14
freemail.hu 33 employees
-
#15
tim.it 33 employees
-
#16
aruba.it 31 employees
-
#17
uol.com.br 31 employees
-
#18
hostgator.com 30 employees
-
#19
pec.it 29 employees
-
#20
mail.gov.in 29 employees
-
#21
telecom.pt 28 employees
-
#22
freenet.de 27 employees
-
#23
microsoft.com 27 employees
-
#24
netpnb.com 26 employees
-
#25
bluehost.com 25 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 35 employees
-
#2
microsoft.com 27 employees
-
#3
cognizant.com 16 employees
-
#4
rockwellautomation.com 12 employees
-
#5
twc.com 10 employees
-
#6
fisglobal.com 6 employees
-
#7
csc.com 6 employees
-
#8
ford.com 4 employees
-
#9
hp.com 4 employees
-
#10
pg.com 4 employees
-
#11
honeywell.com 4 employees
-
#12
cisco.com 4 employees
-
#13
att.com 4 employees
-
#14
emc.com 3 employees
-
#15
essendant.com 3 employees
-
#16
ibm.com 3 employees
-
#17
delta.com 3 employees
-
#18
halliburton.com 3 employees
-
#19
rockwellcollins.com 2 employees
-
#20
frontier.com 2 employees
Compromised users
-
#1
google.com 27,307 users
-
#2
facebook.com 20,915 users
-
#3
netflix.com 6,624 users
-
#4
amazon.com 6,475 users
-
#5
paypal.com 5,783 users
-
#6
apple.com 3,453 users
-
#7
ebay.com 1,848 users
-
#8
oracle.com 731 users
-
#9
walmart.com 579 users
-
#10
cisco.com 437 users
-
#11
capitalone.com 379 users
-
#12
hp.com 378 users
-
#13
ups.com 354 users
-
#14
att.com 339 users
-
#15
microsoft.com 318 users
-
#16
bestbuy.com 294 users
-
#17
adp.com 289 users
-
#18
target.com 285 users
-
#19
wellsfargo.com 258 users
-
#20
fedex.com 233 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 49,498hits
- #2 sso 18,876hits
- #3 webmail 4,713hits
- #4 zoom 4,362hits
- #5 adfs 3,276hits
- #6 github 2,467hits
- #7 cpanel 1,767hits
- #8 oracle 1,648hits
- #9 owa 1,488hits
- #10 sap 1,317hits
- #11 zendesk 1,165hits
- #12 ftp 1,056hits
- #13 sts 903hits
- #14 vpn 653hits
- #15 webex 645hits
- #16 ping 616hits
- #17 st 536hits
- #18 salesforce 525hits
- #19 extranet 513hits
- #20 kaspersky 485hits
- #21 roundcube 320hits
- #22 zimbra 297hits
- #23 gitlab 282hits
- #24 citrix 253hits
- #25 jira 202hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains