Infostealers Weekly Report: 2020-03-09 – 2020-03-15
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 1,075
- #2 Indonesia 461
- #3 Brazil 300
- #4 Spain 258
- #5 France 219
- #6 Turkey 204
- #7 Pakistan 198
- #8 Egypt 174
- #9 Germany 171
- #10 Thailand 157
- #11 Philippines 122
- #12 Canada 102
- #13 Morocco 85
- #14 Algeria 83
- #15 Vietnam 80
- #16 Argentina 80
- #17 Bangladesh 74
- #18 United Kingdom 73
- #19 Romania 69
- #20 Malaysia 55
- #21 Peru 54
- #22 Israel 47
- #23 Japan 38
- #24 Nepal 38
- #25 Australia 37
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,109 users
-
#2
facebook.com 2,815 users
-
#3
live.com 2,450 users
-
#4
netflix.com 1,296 users
-
#5
amazon.com 1,273 users
-
#6
twitter.com 1,262 users
-
#7
paypal.com 1,221 users
-
#8
instagram.com 1,010 users
-
#9
roblox.com 966 users
-
#10
twitch.tv 934 users
-
#11
epicgames.com 886 users
-
#12
discordapp.com 848 users
-
#13
steampowered.com 845 users
-
#14
mega.nz 840 users
-
#15
yahoo.com 806 users
-
#16
apple.com 766 users
-
#17
steamcommunity.com 761 users
-
#18
com.facebook.katana 741 users
-
#19
minecraft.net 701 users
-
#20
linkedin.com 693 users
-
#21
spotify.com 621 users
-
#22
dropbox.com 593 users
-
#23
574 users
-
#24
com.netflix.mediaclient 557 users
-
#25
sonyentertainmentnetwork.com 547 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 14 employees
-
#2
freemail.hu 12 employees
-
#3
k12.fl.us 11 employees
-
#4
abv.bg 10 employees
-
#5
10 employees
-
#6
bluehost.com 9 employees
-
#7
lausd.net 8 employees
-
#8
confused.com 8 employees
-
#9
mail.de 7 employees
-
#10
yahoosmallbusiness.com 7 employees
-
#11
ovh.net 7 employees
-
#12
telecom.pt 6 employees
-
#13
snhu.edu 6 employees
-
#14
jcyl.es 6 employees
-
#15
taqat.sa 5 employees
-
#16
duvalschools.org 5 employees
-
#17
browardschools.com 5 employees
-
#18
dadeschools.net 5 employees
-
#19
icicibank.com 5 employees
-
#20
http://localhost/wordpress/wp-admin/install.php 5 employees
-
#21
ocps.net 5 employees
-
#22
ig.com.br 5 employees
-
#23
twc.com 5 employees
-
#24
yandex.com.tr 5 employees
-
#25
one.com 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 14 employees
-
#2
twc.com 5 employees
-
#3
rockwellautomation.com 2 employees
-
#4
apple.com 2 employees
-
#5
amazon.com 1 employees
-
#6
microsoft.com 1 employees
-
#7
ncr.com 1 employees
-
#8
att.com 1 employees
-
#9
charter.com 1 employees
-
#10
fedex.com 1 employees
-
#11
johnsoncontrols.com 1 employees
-
#12
bankofamerica.com 1 employees
-
#13
core-mark.com 1 employees
-
#14
newmont.com 1 employees
-
#15
frontier.com 1 employees
-
#16
sherwin.com 1 employees
-
#17
libertymutual.com 1 employees
-
#18
allstate.com 1 employees
Compromised users
-
#1
google.com 4,109 users
-
#2
facebook.com 2,814 users
-
#3
netflix.com 1,295 users
-
#4
amazon.com 1,272 users
-
#5
paypal.com 1,221 users
-
#6
apple.com 766 users
-
#7
ebay.com 505 users
-
#8
walmart.com 225 users
-
#9
att.com 148 users
-
#10
capitalone.com 148 users
-
#11
ups.com 145 users
-
#12
adp.com 136 users
-
#13
bestbuy.com 133 users
-
#14
target.com 132 users
-
#15
wellsfargo.com 97 users
-
#16
oracle.com 88 users
-
#17
fedex.com 85 users
-
#18
hp.com 81 users
-
#19
nike.com 75 users
-
#20
bankofamerica.com 74 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 11,278hits
- #2 sso 3,572hits
- #3 adfs 1,004hits
- #4 webmail 617hits
- #5 zoom 437hits
- #6 github 349hits
- #7 owa 279hits
- #8 zendesk 255hits
- #9 sap 220hits
- #10 sts 215hits
- #11 oracle 190hits
- #12 cpanel 165hits
- #13 ping 137hits
- #14 ftp 136hits
- #15 vpn 136hits
- #16 extranet 122hits
- #17 st 115hits
- #18 imap 96hits
- #19 salesforce 95hits
- #20 okta 80hits
- #21 zimbra 74hits
- #22 webex 57hits
- #23 kaspersky 52hits
- #24 roundcube 49hits
- #25 dana-na 33hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains