Infostealers Weekly Report: 2020-11-30 – 2020-12-06
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 4,770
- #2 Indonesia 2,132
- #3 Brazil 1,505
- #4 Pakistan 1,375
- #5 United States of America 1,267
- #6 Turkey 1,151
- #7 Philippines 785
- #8 Vietnam 625
- #9 Mexico 492
- #10 Spain 445
- #11 Germany 442
- #12 Thailand 417
- #13 Bangladesh 397
- #14 France 394
- #15 Malaysia 381
- #16 South Korea 340
- #17 Italy 328
- #18 Morocco 322
- #19 Algeria 311
- #20 Sri Lanka 307
- #21 Argentina 303
- #22 Egypt 297
- #23 Colombia 264
- #24 Peru 211
- #25 Nigeria 211
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 19,369 users
-
#2
facebook.com 14,266 users
-
#3
live.com 10,566 users
-
#4
twitter.com 4,981 users
-
#5
netflix.com 4,602 users
-
#6
instagram.com 4,581 users
-
#7
amazon.com 4,424 users
-
#8
com.facebook.katana 4,193 users
-
#9
mega.nz 4,167 users
-
#10
paypal.com 3,914 users
-
#11
roblox.com 3,167 users
-
#12
3,025 users
-
#13
yahoo.com 2,984 users
-
#14
steampowered.com 2,837 users
-
#15
linkedin.com 2,824 users
-
#16
epicgames.com 2,636 users
-
#17
twitch.tv 2,600 users
-
#18
apple.com 2,577 users
-
#19
discord.com 2,476 users
-
#20
com.netflix.mediaclient 2,341 users
-
#21
discordapp.com 2,276 users
-
#22
microsoftonline.com 2,248 users
-
#23
steamcommunity.com 2,184 users
-
#24
minecraft.net 2,142 users
-
#25
riotgames.com 2,021 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 103 employees
-
#2
rediff.com 94 employees
-
#3
54 employees
-
#4
digimail.in 45 employees
-
#5
http://localhost/wordpress/wp-admin/install.php 36 employees
-
#6
onlinesbi.com 29 employees
-
#7
pec.it 28 employees
-
#8
netpnb.com 28 employees
-
#9
freemail.hu 27 employees
-
#10
secureserver.net 27 employees
-
#11
telecom.pt 27 employees
-
#12
accenture.com 26 employees
-
#13
o2.pl 25 employees
-
#14
tim.it 23 employees
-
#15
aruba.it 23 employees
-
#16
interia.pl 22 employees
-
#17
onet.pl 20 employees
-
#18
aiou.edu.pk 18 employees
-
#19
abv.bg 18 employees
-
#20
indusind.com 18 employees
-
#21
ovh.net 18 employees
-
#22
confused.com 18 employees
-
#23
unionbankonline.co.in 16 employees
-
#24
yahoosmallbusiness.com 16 employees
-
#25
citromail.hu 15 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 12 employees
-
#2
netflix.com 9 employees
-
#3
rockwellautomation.com 7 employees
-
#4
cognizant.com 5 employees
-
#5
microsoft.com 5 employees
-
#6
twc.com 3 employees
-
#7
amazon.com 3 employees
-
#8
frontier.com 3 employees
-
#9
netapp.com 3 employees
-
#10
oracle.com 3 employees
-
#11
pepsico.com 2 employees
-
#12
ups.com 2 employees
-
#13
apple.com 2 employees
-
#14
bestbuy.com 2 employees
-
#15
att.com 1 employees
-
#16
gs.com 1 employees
-
#17
goodyear.com 1 employees
-
#18
stryker.com 1 employees
-
#19
dupont.com 1 employees
-
#20
windstream.com 1 employees
Compromised users
-
#1
google.com 19,367 users
-
#2
facebook.com 14,262 users
-
#3
netflix.com 4,602 users
-
#4
amazon.com 4,424 users
-
#5
paypal.com 3,914 users
-
#6
apple.com 2,577 users
-
#7
ebay.com 1,075 users
-
#8
oracle.com 457 users
-
#9
walmart.com 274 users
-
#10
hp.com 264 users
-
#11
microsoft.com 225 users
-
#12
cisco.com 218 users
-
#13
ups.com 174 users
-
#14
capitalone.com 163 users
-
#15
nike.com 150 users
-
#16
att.com 149 users
-
#17
adp.com 146 users
-
#18
westernunion.com 133 users
-
#19
bestbuy.com 127 users
-
#20
intel.com 124 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 34,424hits
- #2 sso 11,541hits
- #3 zoom 3,538hits
- #4 webmail 2,846hits
- #5 adfs 1,904hits
- #6 github 1,695hits
- #7 oracle 1,037hits
- #8 owa 854hits
- #9 sts 848hits
- #10 cpanel 840hits
- #11 sap 801hits
- #12 zendesk 610hits
- #13 ftp 605hits
- #14 webex 565hits
- #15 st 448hits
- #16 salesforce 398hits
- #17 vpn 370hits
- #18 ping 367hits
- #19 extranet 358hits
- #20 kaspersky 268hits
- #21 roundcube 264hits
- #22 imap 209hits
- #23 zimbra 174hits
- #24 jira 114hits
- #25 okta 99hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains