Infostealers Weekly Report: 2020-01-13 – 2020-01-19
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 4,686
- #2 Brazil 3,726
- #3 Vietnam 3,647
- #4 India 3,572
- #5 Pakistan 2,063
- #6 Egypt 2,030
- #7 Turkey 1,834
- #8 Philippines 1,197
- #9 Thailand 1,139
- #10 Algeria 1,019
- #11 United States of America 1,001
- #12 Bangladesh 902
- #13 Argentina 876
- #14 Romania 813
- #15 Morocco 790
- #16 Serbia 536
- #17 Mexico 524
- #18 Malaysia 522
- #19 Hungary 513
- #20 Chile 508
- #21 Poland 431
- #22 South Africa 408
- #23 Peru 401
- #24 Portugal 386
- #25 Iraq 380
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 29,706 users
-
#2
facebook.com 24,817 users
-
#3
live.com 13,964 users
-
#4
twitter.com 6,670 users
-
#5
6,286 users
-
#6
mega.nz 6,274 users
-
#7
netflix.com 5,693 users
-
#8
yahoo.com 5,575 users
-
#9
instagram.com 5,491 users
-
#10
paypal.com 4,918 users
-
#11
discordapp.com 4,790 users
-
#12
roblox.com 4,534 users
-
#13
linkedin.com 4,254 users
-
#14
amazon.com 4,150 users
-
#15
steampowered.com 4,132 users
-
#16
epicgames.com 3,648 users
-
#17
twitch.tv 3,214 users
-
#18
steamcommunity.com 3,097 users
-
#19
dropbox.com 3,015 users
-
#20
apple.com 2,918 users
-
#21
192.168.1.1 2,666 users
-
#22
minecraft.net 2,514 users
-
#23
ea.com 2,175 users
-
#24
ul 2,137 users
-
#25
adobe.com 2,023 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 124 employees
-
#2
rediff.com 113 employees
-
#3
icicibank.com 101 employees
-
#4
97 employees
-
#5
telecom.pt 55 employees
-
#6
secureserver.net 48 employees
-
#7
ig.com.br 47 employees
-
#8
digimail.in 45 employees
-
#9
interia.pl 45 employees
-
#10
netpnb.com 43 employees
-
#11
accenture.com 40 employees
-
#12
bluehost.com 38 employees
-
#13
sapo.pt 37 employees
-
#14
idbibank.co.in 37 employees
-
#15
o2.pl 36 employees
-
#16
bni.co.id 30 employees
-
#17
aruba.it 29 employees
-
#18
isacombank.com.vn 29 employees
-
#19
ukr.net 27 employees
-
#20
sgcpanel.com 27 employees
-
#21
nbg.gr 27 employees
-
#22
tim.it 25 employees
-
#23
onlinesbi.com 24 employees
-
#24
citromail.hu 22 employees
-
#25
mail.bg 22 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 6 employees
-
#2
netflix.com 6 employees
-
#3
cognizant.com 6 employees
-
#4
rockwellautomation.com 6 employees
-
#5
marriott.com 4 employees
-
#6
publix.com 3 employees
-
#7
halliburton.com 2 employees
-
#8
ncr.com 2 employees
-
#9
disney.com 2 employees
-
#10
genesishcc.com 2 employees
-
#11
apple.com 2 employees
-
#12
google.com 2 employees
-
#13
hp.com 2 employees
-
#14
pg.com 2 employees
-
#15
twc.com 1 employees
-
#16
harman.com 1 employees
-
#17
johnsoncontrols.com 1 employees
-
#18
sandisk.com 1 employees
-
#19
interpublic.com 1 employees
-
#20
visteon.com 1 employees
Compromised users
-
#1
google.com 29,705 users
-
#2
facebook.com 24,813 users
-
#3
netflix.com 5,693 users
-
#4
paypal.com 4,918 users
-
#5
amazon.com 4,149 users
-
#6
apple.com 2,918 users
-
#7
ebay.com 1,603 users
-
#8
oracle.com 516 users
-
#9
hp.com 264 users
-
#10
walmart.com 227 users
-
#11
microsoft.com 169 users
-
#12
cisco.com 153 users
-
#13
ibm.com 148 users
-
#14
att.com 122 users
-
#15
westernunion.com 120 users
-
#16
ups.com 115 users
-
#17
americanexpress.com 114 users
-
#18
capitalone.com 101 users
-
#19
fedex.com 94 users
-
#20
adp.com 93 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 47,694hits
- #2 sso 14,856hits
- #3 webmail 2,826hits
- #4 owa 1,664hits
- #5 adfs 1,403hits
- #6 github 1,399hits
- #7 oracle 1,049hits
- #8 sap 1,001hits
- #9 cpanel 986hits
- #10 sts 804hits
- #11 zendesk 791hits
- #12 ping 537hits
- #13 kaspersky 464hits
- #14 ftp 420hits
- #15 st 403hits
- #16 extranet 350hits
- #17 salesforce 290hits
- #18 zimbra 213hits
- #19 roundcube 187hits
- #20 imap 152hits
- #21 zoom 141hits
- #22 webex 108hits
- #23 vpn 106hits
- #24 gitlab 98hits
- #25 bitbucket 89hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains