Infostealers Weekly Report: 2020-09-28 – 2020-10-04
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,260
- #2 Indonesia 1,415
- #3 Brazil 836
- #4 Pakistan 783
- #5 Turkey 694
- #6 Philippines 589
- #7 Vietnam 328
- #8 Bangladesh 325
- #9 United States of America 314
- #10 Russia 313
- #11 Thailand 289
- #12 Mexico 288
- #13 Egypt 264
- #14 Romania 245
- #15 Argentina 244
- #16 Poland 234
- #17 Colombia 189
- #18 South Africa 186
- #19 Malaysia 178
- #20 Algeria 173
- #21 Serbia 167
- #22 Kenya 157
- #23 Morocco 155
- #24 Peru 150
- #25 Nigeria 144
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 10,540 users
-
#2
facebook.com 8,026 users
-
#3
live.com 5,380 users
-
#4
twitter.com 2,508 users
-
#5
netflix.com 2,304 users
-
#6
instagram.com 2,267 users
-
#7
mega.nz 2,099 users
-
#8
com.facebook.katana 2,014 users
-
#9
amazon.com 1,935 users
-
#10
linkedin.com 1,759 users
-
#11
yahoo.com 1,707 users
-
#12
paypal.com 1,701 users
-
#13
roblox.com 1,531 users
-
#14
1,491 users
-
#15
steampowered.com 1,458 users
-
#16
epicgames.com 1,341 users
-
#17
microsoftonline.com 1,277 users
-
#18
apple.com 1,243 users
-
#19
discord.com 1,241 users
-
#20
twitch.tv 1,212 users
-
#21
steamcommunity.com 1,143 users
-
#22
com.netflix.mediaclient 1,112 users
-
#23
discordapp.com 1,062 users
-
#24
192.168.1.1 1,042 users
-
#25
riotgames.com 986 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 50 employees
-
#2
icicibank.com 34 employees
-
#3
interia.pl 31 employees
-
#4
onet.pl 23 employees
-
#5
o2.pl 23 employees
-
#6
20 employees
-
#7
digimail.in 20 employees
-
#8
freemail.hu 18 employees
-
#9
onlinesbi.com 17 employees
-
#10
secureserver.net 17 employees
-
#11
mail.gov.in 15 employees
-
#12
jwpub.org 13 employees
-
#13
aiou.edu.pk 12 employees
-
#14
sapo.pt 11 employees
-
#15
bni.co.id 11 employees
-
#16
telecom.pt 11 employees
-
#17
yandex.com.tr 11 employees
-
#18
accenture.com 11 employees
-
#19
abv.bg 10 employees
-
#20
http://localhost/wordpress/wp-admin/install.php 10 employees
-
#21
netpnb.com 10 employees
-
#22
bluehost.com 10 employees
-
#23
sp.gov.br 10 employees
-
#24
aruba.it 10 employees
-
#25
ig.com.br 10 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 6 employees
-
#2
publix.com 5 employees
-
#3
rockwellautomation.com 4 employees
-
#4
microsoft.com 3 employees
-
#5
halliburton.com 2 employees
-
#6
netflix.com 2 employees
-
#7
hp.com 2 employees
-
#8
ebay.com 1 employees
-
#9
apple.com 1 employees
-
#10
oracle.com 1 employees
-
#11
paypal.com 1 employees
-
#12
twc.com 1 employees
-
#13
jll.com 1 employees
-
#14
qualcomm.com 1 employees
-
#15
ford.com 1 employees
-
#16
cbre.com 1 employees
-
#17
johnsoncontrols.com 1 employees
-
#18
sherwin.com 1 employees
-
#19
csc.com 1 employees
-
#20
autoliv.com 1 employees
Compromised users
-
#1
google.com 10,540 users
-
#2
facebook.com 8,025 users
-
#3
netflix.com 2,304 users
-
#4
amazon.com 1,935 users
-
#5
paypal.com 1,701 users
-
#6
apple.com 1,243 users
-
#7
ebay.com 546 users
-
#8
oracle.com 213 users
-
#9
cisco.com 133 users
-
#10
microsoft.com 107 users
-
#11
hp.com 107 users
-
#12
walmart.com 78 users
-
#13
ups.com 62 users
-
#14
nike.com 60 users
-
#15
fedex.com 51 users
-
#16
ibm.com 50 users
-
#17
capitalone.com 48 users
-
#18
adp.com 48 users
-
#19
att.com 47 users
-
#20
westernunion.com 44 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 17,228hits
- #2 sso 5,644hits
- #3 zoom 1,852hits
- #4 webmail 1,246hits
- #5 adfs 811hits
- #6 github 776hits
- #7 sap 539hits
- #8 oracle 449hits
- #9 owa 416hits
- #10 cpanel 403hits
- #11 zendesk 313hits
- #12 webex 302hits
- #13 ftp 290hits
- #14 sts 216hits
- #15 vpn 205hits
- #16 kaspersky 180hits
- #17 st 178hits
- #18 ping 160hits
- #19 extranet 116hits
- #20 roundcube 103hits
- #21 imap 95hits
- #22 salesforce 80hits
- #23 okta 76hits
- #24 gitlab 55hits
- #25 dana-na 50hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains