Infostealers Weekly Report: 2020-02-17 – 2020-02-23
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 7,361
- #2 Brazil 7,311
- #3 Indonesia 6,275
- #4 Turkey 4,764
- #5 Vietnam 4,063
- #6 Pakistan 3,623
- #7 Egypt 2,879
- #8 Thailand 2,478
- #9 Philippines 2,368
- #10 United States of America 1,862
- #11 Mexico 1,531
- #12 Argentina 1,478
- #13 Bangladesh 1,263
- #14 Morocco 1,257
- #15 Algeria 1,237
- #16 Malaysia 1,105
- #17 Romania 961
- #18 Colombia 826
- #19 South Korea 765
- #20 Peru 751
- #21 Sri Lanka 628
- #22 South Africa 614
- #23 Ukraine 609
- #24 Chile 609
- #25 Poland 588
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 49,160 users
-
#2
facebook.com 39,137 users
-
#3
live.com 26,549 users
-
#4
twitter.com 13,980 users
-
#5
mega.nz 13,072 users
-
#6
netflix.com 10,903 users
-
#7
instagram.com 10,586 users
-
#8
com.facebook.katana 9,848 users
-
#9
9,264 users
-
#10
yahoo.com 9,231 users
-
#11
paypal.com 9,191 users
-
#12
amazon.com 8,693 users
-
#13
linkedin.com 8,374 users
-
#14
discordapp.com 8,317 users
-
#15
roblox.com 7,411 users
-
#16
apple.com 7,204 users
-
#17
steampowered.com 7,186 users
-
#18
192.168.1.1 6,494 users
-
#19
dropbox.com 5,970 users
-
#20
epicgames.com 5,681 users
-
#21
twitch.tv 5,584 users
-
#22
steamcommunity.com 5,509 users
-
#23
com.netflix.mediaclient 5,416 users
-
#24
adobe.com 4,841 users
-
#25
aliexpress.com 4,308 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 199 employees
-
#2
rediff.com 185 employees
-
#3
157 employees
-
#4
freemail.hu 132 employees
-
#5
secureserver.net 122 employees
-
#6
digimail.in 115 employees
-
#7
yandex.com.tr 92 employees
-
#8
telecom.pt 89 employees
-
#9
accenture.com 88 employees
-
#10
ig.com.br 85 employees
-
#11
http://localhost/wordpress/wp-admin/install.php 81 employees
-
#12
ukr.net 77 employees
-
#13
abv.bg 76 employees
-
#14
o2.pl 65 employees
-
#15
uol.com.br 65 employees
-
#16
interia.pl 63 employees
-
#17
aruba.it 61 employees
-
#18
sapo.pt 57 employees
-
#19
bluehost.com 55 employees
-
#20
bni.co.id 54 employees
-
#21
i.ua 53 employees
-
#22
mail.bg 52 employees
-
#23
isacombank.com.vn 47 employees
-
#24
nbg.gr 47 employees
-
#25
netpnb.com 46 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 19 employees
-
#2
cognizant.com 18 employees
-
#3
publix.com 16 employees
-
#4
twc.com 13 employees
-
#5
microsoft.com 11 employees
-
#6
netflix.com 7 employees
-
#7
pg.com 7 employees
-
#8
hp.com 7 employees
-
#9
paypal.com 4 employees
-
#10
salesforce.com 3 employees
-
#11
amazon.com 3 employees
-
#12
statefarm.com 3 employees
-
#13
google.com 3 employees
-
#14
apple.com 3 employees
-
#15
cbre.com 2 employees
-
#16
ibm.com 2 employees
-
#17
centurylink.com 2 employees
-
#18
aig.com 2 employees
-
#19
aa.com 2 employees
-
#20
ebay.com 2 employees
Compromised users
-
#1
google.com 49,153 users
-
#2
facebook.com 39,131 users
-
#3
netflix.com 10,899 users
-
#4
paypal.com 9,191 users
-
#5
amazon.com 8,693 users
-
#6
apple.com 7,204 users
-
#7
ebay.com 2,876 users
-
#8
oracle.com 1,364 users
-
#9
hp.com 543 users
-
#10
cisco.com 513 users
-
#11
microsoft.com 492 users
-
#12
walmart.com 426 users
-
#13
ibm.com 333 users
-
#14
ups.com 280 users
-
#15
capitalone.com 278 users
-
#16
att.com 244 users
-
#17
westernunion.com 240 users
-
#18
americanexpress.com 238 users
-
#19
nike.com 232 users
-
#20
adp.com 224 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 93,886hits
- #2 sso 33,834hits
- #3 webmail 7,461hits
- #4 adfs 4,076hits
- #5 github 3,980hits
- #6 oracle 3,474hits
- #7 cpanel 2,851hits
- #8 owa 2,640hits
- #9 sap 2,638hits
- #10 ftp 2,135hits
- #11 zendesk 1,958hits
- #12 st 1,494hits
- #13 kaspersky 1,374hits
- #14 zoom 1,313hits
- #15 sts 1,100hits
- #16 vpn 1,070hits
- #17 ping 1,028hits
- #18 extranet 854hits
- #19 roundcube 544hits
- #20 salesforce 467hits
- #21 gitlab 450hits
- #22 webex 437hits
- #23 imap 404hits
- #24 jira 311hits
- #25 bitbucket 308hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains