Infostealers Weekly Report: 2020-12-14 – 2020-12-20
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 3,746
- #2 Turkey 2,053
- #3 United States of America 1,671
- #4 Indonesia 1,559
- #5 Brazil 1,395
- #6 Pakistan 1,101
- #7 Egypt 648
- #8 Vietnam 645
- #9 Philippines 621
- #10 Poland 527
- #11 Mexico 479
- #12 Romania 387
- #13 Thailand 384
- #14 Algeria 373
- #15 South Korea 332
- #16 Morocco 329
- #17 Argentina 315
- #18 Malaysia 313
- #19 Bangladesh 294
- #20 Sri Lanka 284
- #21 Colombia 271
- #22 Hungary 256
- #23 Spain 215
- #24 Peru 215
- #25 Germany 208
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 16,401 users
-
#2
facebook.com 12,212 users
-
#3
live.com 9,501 users
-
#4
twitter.com 5,559 users
-
#5
instagram.com 4,708 users
-
#6
netflix.com 4,486 users
-
#7
amazon.com 4,175 users
-
#8
paypal.com 3,875 users
-
#9
discord.com 3,813 users
-
#10
roblox.com 3,790 users
-
#11
twitch.tv 3,760 users
-
#12
mega.nz 3,530 users
-
#13
com.facebook.katana 3,515 users
-
#14
steampowered.com 3,499 users
-
#15
epicgames.com 3,477 users
-
#16
steamcommunity.com 3,241 users
-
#17
3,143 users
-
#18
riotgames.com 3,099 users
-
#19
apple.com 2,649 users
-
#20
minecraft.net 2,609 users
-
#21
discordapp.com 2,571 users
-
#22
rockstargames.com 2,526 users
-
#23
yahoo.com 2,459 users
-
#24
microsoftonline.com 2,424 users
-
#25
com.spotify.music 2,285 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 75 employees
-
#2
icicibank.com 58 employees
-
#3
o2.pl 44 employees
-
#4
37 employees
-
#5
interia.pl 36 employees
-
#6
freemail.hu 30 employees
-
#7
digimail.in 27 employees
-
#8
publix.com 26 employees
-
#9
aruba.it 24 employees
-
#10
onlinesbi.com 24 employees
-
#11
yandex.com.tr 23 employees
-
#12
pec.it 21 employees
-
#13
secureserver.net 20 employees
-
#14
accenture.com 20 employees
-
#15
citromail.hu 19 employees
-
#16
abv.bg 18 employees
-
#17
onet.pl 18 employees
-
#18
tim.it 17 employees
-
#19
http://localhost/wordpress/wp-admin/install.php 16 employees
-
#20
skole.hr 16 employees
-
#21
dadeschools.net 15 employees
-
#22
netpnb.com 14 employees
-
#23
bluehost.com 14 employees
-
#24
k12.fl.us 14 employees
-
#25
telecom.pt 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 26 employees
-
#2
rockwellautomation.com 7 employees
-
#3
microsoft.com 5 employees
-
#4
twc.com 4 employees
-
#5
netflix.com 3 employees
-
#6
ups.com 3 employees
-
#7
apple.com 3 employees
-
#8
google.com 3 employees
-
#9
cognizant.com 2 employees
-
#10
amazon.com 2 employees
-
#11
cigna.com 2 employees
-
#12
oracle.com 2 employees
-
#13
cisco.com 2 employees
-
#14
hp.com 2 employees
-
#15
bestbuy.com 2 employees
-
#16
cbre.com 1 employees
-
#17
ibm.com 1 employees
-
#18
aramark.com 1 employees
-
#19
paypal.com 1 employees
-
#20
cokecce.com 1 employees
Compromised users
-
#1
google.com 16,397 users
-
#2
facebook.com 12,209 users
-
#3
netflix.com 4,485 users
-
#4
amazon.com 4,175 users
-
#5
paypal.com 3,875 users
-
#6
apple.com 2,649 users
-
#7
ebay.com 1,095 users
-
#8
walmart.com 411 users
-
#9
oracle.com 398 users
-
#10
bestbuy.com 240 users
-
#11
hp.com 228 users
-
#12
cisco.com 222 users
-
#13
target.com 218 users
-
#14
ups.com 213 users
-
#15
nike.com 210 users
-
#16
capitalone.com 189 users
-
#17
att.com 185 users
-
#18
fedex.com 181 users
-
#19
adp.com 180 users
-
#20
intel.com 173 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 36,662hits
- #2 sso 10,506hits
- #3 zoom 3,276hits
- #4 adfs 2,070hits
- #5 webmail 1,919hits
- #6 github 1,546hits
- #7 oracle 914hits
- #8 owa 734hits
- #9 sts 618hits
- #10 sap 598hits
- #11 zendesk 594hits
- #12 cpanel 584hits
- #13 ftp 526hits
- #14 webex 471hits
- #15 st 415hits
- #16 ping 378hits
- #17 vpn 312hits
- #18 kaspersky 289hits
- #19 imap 229hits
- #20 extranet 222hits
- #21 roundcube 149hits
- #22 okta 134hits
- #23 citrix 129hits
- #24 salesforce 125hits
- #25 jira 84hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains