Infostealers Weekly Report: 2020-02-24 – 2020-03-01
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 6,295
- #2 Brazil 4,650
- #3 Indonesia 3,936
- #4 Pakistan 2,674
- #5 Turkey 2,226
- #6 Vietnam 2,170
- #7 Egypt 1,939
- #8 Philippines 1,891
- #9 Thailand 1,805
- #10 Mexico 1,149
- #11 Malaysia 999
- #12 South Korea 981
- #13 Bangladesh 964
- #14 Argentina 892
- #15 Algeria 741
- #16 Morocco 717
- #17 Romania 625
- #18 Colombia 617
- #19 Ukraine 566
- #20 Poland 527
- #21 Peru 486
- #22 Portugal 464
- #23 Sri Lanka 461
- #24 Chile 410
- #25 Hungary 388
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 33,526 users
-
#2
facebook.com 25,950 users
-
#3
live.com 18,637 users
-
#4
twitter.com 10,287 users
-
#5
mega.nz 9,335 users
-
#6
9,013 users
-
#7
netflix.com 7,426 users
-
#8
instagram.com 7,338 users
-
#9
com.facebook.katana 7,053 users
-
#10
paypal.com 6,572 users
-
#11
yahoo.com 6,450 users
-
#12
linkedin.com 6,282 users
-
#13
amazon.com 6,255 users
-
#14
discordapp.com 5,570 users
-
#15
apple.com 5,379 users
-
#16
steampowered.com 5,146 users
-
#17
dropbox.com 4,365 users
-
#18
192.168.1.1 4,108 users
-
#19
steamcommunity.com 4,063 users
-
#20
roblox.com 3,866 users
-
#21
twitch.tv 3,858 users
-
#22
com.netflix.mediaclient 3,801 users
-
#23
adobe.com 3,776 users
-
#24
epicgames.com 3,725 users
-
#25
aliexpress.com 3,327 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 174 employees
-
#2
rediff.com 165 employees
-
#3
155 employees
-
#4
digimail.in 103 employees
-
#5
freemail.hu 84 employees
-
#6
secureserver.net 84 employees
-
#7
ukr.net 83 employees
-
#8
telecom.pt 80 employees
-
#9
http://localhost/wordpress/wp-admin/install.php 79 employees
-
#10
yandex.com.tr 76 employees
-
#11
accenture.com 70 employees
-
#12
o2.pl 65 employees
-
#13
netpnb.com 57 employees
-
#14
bluehost.com 55 employees
-
#15
onlinesbi.com 49 employees
-
#16
interia.pl 43 employees
-
#17
onet.pl 41 employees
-
#18
bni.co.id 39 employees
-
#19
idbibank.co.in 38 employees
-
#20
i.ua 38 employees
-
#21
abv.bg 37 employees
-
#22
sapo.pt 37 employees
-
#23
163.com 35 employees
-
#24
qq.com 32 employees
-
#25
hostgator.com 32 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 26 employees
-
#2
rockwellautomation.com 18 employees
-
#3
microsoft.com 10 employees
-
#4
hp.com 5 employees
-
#5
apple.com 4 employees
-
#6
amazon.com 4 employees
-
#7
xerox.com 3 employees
-
#8
netflix.com 3 employees
-
#9
publix.com 2 employees
-
#10
google.com 2 employees
-
#11
pg.com 2 employees
-
#12
aa.com 2 employees
-
#13
ncr.com 2 employees
-
#14
paypal.com 2 employees
-
#15
ibm.com 2 employees
-
#16
csc.com 2 employees
-
#17
navistar.com 1 employees
-
#18
facebook.com 1 employees
-
#19
quantaservices.com 1 employees
-
#20
micron.com 1 employees
Compromised users
-
#1
google.com 33,525 users
-
#2
facebook.com 25,947 users
-
#3
netflix.com 7,426 users
-
#4
paypal.com 6,572 users
-
#5
amazon.com 6,255 users
-
#6
apple.com 5,379 users
-
#7
ebay.com 2,034 users
-
#8
oracle.com 1,223 users
-
#9
cisco.com 520 users
-
#10
hp.com 409 users
-
#11
microsoft.com 340 users
-
#12
ibm.com 282 users
-
#13
nike.com 186 users
-
#14
walmart.com 168 users
-
#15
ups.com 168 users
-
#16
westernunion.com 142 users
-
#17
intel.com 131 users
-
#18
americanexpress.com 110 users
-
#19
salesforce.com 106 users
-
#20
bestbuy.com 83 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 74,956hits
- #2 sso 25,844hits
- #3 webmail 5,959hits
- #4 github 3,880hits
- #5 oracle 3,138hits
- #6 adfs 3,025hits
- #7 cpanel 2,834hits
- #8 sap 2,221hits
- #9 owa 2,095hits
- #10 ftp 2,065hits
- #11 zendesk 1,442hits
- #12 st 1,230hits
- #13 kaspersky 1,025hits
- #14 zoom 910hits
- #15 vpn 821hits
- #16 extranet 760hits
- #17 sts 744hits
- #18 ping 713hits
- #19 roundcube 571hits
- #20 gitlab 444hits
- #21 salesforce 357hits
- #22 imap 350hits
- #23 bitbucket 344hits
- #24 jira 286hits
- #25 webex 277hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains