Infostealers Weekly Report: 2020-10-26 – 2020-11-01
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 7,028
- #2 Indonesia 3,418
- #3 Pakistan 2,185
- #4 Brazil 1,918
- #5 Vietnam 1,711
- #6 Turkey 1,503
- #7 Philippines 1,230
- #8 Thailand 752
- #9 Bangladesh 728
- #10 South Africa 718
- #11 Mexico 711
- #12 Egypt 688
- #13 Poland 648
- #14 Italy 596
- #15 Romania 566
- #16 Malaysia 523
- #17 Sri Lanka 481
- #18 United States of America 481
- #19 Argentina 462
- #20 Algeria 440
- #21 Portugal 438
- #22 Germany 433
- #23 Venezuela 418
- #24 Colombia 417
- #25 Spain 408
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 31,528 users
-
#2
facebook.com 23,947 users
-
#3
live.com 17,213 users
-
#4
twitter.com 8,113 users
-
#5
instagram.com 7,399 users
-
#6
netflix.com 7,236 users
-
#7
mega.nz 6,979 users
-
#8
com.facebook.katana 6,876 users
-
#9
6,600 users
-
#10
amazon.com 6,380 users
-
#11
paypal.com 5,838 users
-
#12
yahoo.com 5,144 users
-
#13
linkedin.com 5,135 users
-
#14
steampowered.com 4,540 users
-
#15
discord.com 4,262 users
-
#16
roblox.com 4,224 users
-
#17
apple.com 4,151 users
-
#18
microsoftonline.com 4,102 users
-
#19
epicgames.com 3,857 users
-
#20
twitch.tv 3,580 users
-
#21
com.netflix.mediaclient 3,551 users
-
#22
steamcommunity.com 3,402 users
-
#23
riotgames.com 3,295 users
-
#24
dropbox.com 3,185 users
-
#25
com.spotify.music 3,088 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 190 employees
-
#2
icicibank.com 174 employees
-
#3
digimail.in 93 employees
-
#4
87 employees
-
#5
telecom.pt 80 employees
-
#6
o2.pl 77 employees
-
#7
freemail.hu 68 employees
-
#8
onlinesbi.com 67 employees
-
#9
accenture.com 61 employees
-
#10
http://localhost/wordpress/wp-admin/install.php 60 employees
-
#11
tim.it 53 employees
-
#12
pec.it 51 employees
-
#13
interia.pl 51 employees
-
#14
netpnb.com 47 employees
-
#15
abv.bg 46 employees
-
#16
sapo.pt 42 employees
-
#17
onet.pl 42 employees
-
#18
secureserver.net 42 employees
-
#19
aruba.it 42 employees
-
#20
aiou.edu.pk 32 employees
-
#21
yandex.com.tr 31 employees
-
#22
indusind.com 31 employees
-
#23
ovh.net 29 employees
-
#24
confused.com 29 employees
-
#25
bluehost.com 28 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 18 employees
-
#2
rockwellautomation.com 9 employees
-
#3
cognizant.com 9 employees
-
#4
publix.com 8 employees
-
#5
conocophillips.com 4 employees
-
#6
hp.com 4 employees
-
#7
ford.com 4 employees
-
#8
amazon.com 3 employees
-
#9
google.com 3 employees
-
#10
apple.com 3 employees
-
#11
pepsico.com 2 employees
-
#12
abbvie.com 2 employees
-
#13
utc.com 2 employees
-
#14
att.com 2 employees
-
#15
paypal.com 2 employees
-
#16
staples.com 2 employees
-
#17
bnymellon.com 2 employees
-
#18
cbre.com 2 employees
-
#19
oracle.com 2 employees
-
#20
honeywell.com 2 employees
Compromised users
-
#1
google.com 31,526 users
-
#2
facebook.com 23,941 users
-
#3
netflix.com 7,236 users
-
#4
amazon.com 6,380 users
-
#5
paypal.com 5,838 users
-
#6
apple.com 4,151 users
-
#7
ebay.com 1,610 users
-
#8
oracle.com 866 users
-
#9
hp.com 456 users
-
#10
cisco.com 447 users
-
#11
microsoft.com 344 users
-
#12
nike.com 246 users
-
#13
ibm.com 228 users
-
#14
ups.com 200 users
-
#15
intel.com 176 users
-
#16
westernunion.com 155 users
-
#17
walmart.com 142 users
-
#18
americanexpress.com 97 users
-
#19
salesforce.com 97 users
-
#20
fedex.com 84 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 56,933hits
- #2 sso 20,654hits
- #3 zoom 6,447hits
- #4 webmail 5,489hits
- #5 github 2,980hits
- #6 adfs 2,955hits
- #7 oracle 2,019hits
- #8 owa 1,643hits
- #9 sap 1,473hits
- #10 cpanel 1,411hits
- #11 ftp 1,300hits
- #12 webex 1,236hits
- #13 zendesk 1,194hits
- #14 sts 926hits
- #15 vpn 787hits
- #16 st 702hits
- #17 kaspersky 676hits
- #18 ping 651hits
- #19 extranet 626hits
- #20 roundcube 472hits
- #21 zimbra 375hits
- #22 salesforce 341hits
- #23 gitlab 244hits
- #24 jira 206hits
- #25 okta 196hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains