Infostealers Weekly Report: 2020-03-23 – 2020-03-29
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 317
- #2 United States of America 240
- #3 Italy 220
- #4 Indonesia 209
- #5 Vietnam 157
- #6 Brazil 155
- #7 Pakistan 155
- #8 Thailand 104
- #9 Philippines 99
- #10 Spain 80
- #11 Algeria 75
- #12 Morocco 71
- #13 Romania 54
- #14 Egypt 53
- #15 Bangladesh 48
- #16 France 45
- #17 Hungary 41
- #18 Germany 39
- #19 Malaysia 39
- #20 Serbia 38
- #21 Argentina 38
- #22 Canada 33
- #23 Saudi Arabia 27
- #24 Sri Lanka 27
- #25 Nepal 26
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,018 users
-
#2
facebook.com 1,380 users
-
#3
live.com 1,130 users
-
#4
twitter.com 568 users
-
#5
netflix.com 517 users
-
#6
roblox.com 450 users
-
#7
instagram.com 444 users
-
#8
paypal.com 441 users
-
#9
discordapp.com 410 users
-
#10
amazon.com 403 users
-
#11
mega.nz 390 users
-
#12
epicgames.com 381 users
-
#13
yahoo.com 341 users
-
#14
com.facebook.katana 340 users
-
#15
steampowered.com 339 users
-
#16
apple.com 296 users
-
#17
twitch.tv 284 users
-
#18
265 users
-
#19
minecraft.net 264 users
-
#20
linkedin.com 262 users
-
#21
steamcommunity.com 257 users
-
#22
dropbox.com 245 users
-
#23
com.spotify.music 236 users
-
#24
com.netflix.mediaclient 233 users
-
#25
192.168.1.1 220 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
pec.it 25 employees
-
#2
tim.it 19 employees
-
#3
aruba.it 16 employees
-
#4
freemail.hu 10 employees
-
#5
infocert.it 6 employees
-
#6
yandex.com.tr 5 employees
-
#7
abv.bg 5 employees
-
#8
4 employees
-
#9
telecom.pt 4 employees
-
#10
nbg.gr 4 employees
-
#11
k12.fl.us 4 employees
-
#12
roadrunner.com 3 employees
-
#13
telecompost.it 3 employees
-
#14
fiatgroup.com 3 employees
-
#15
ovh.com 3 employees
-
#16
one.com 3 employees
-
#17
maccabi4u.co.il 3 employees
-
#18
secureserver.net 3 employees
-
#19
bluehost.com 3 employees
-
#20
mail.bg 3 employees
-
#21
spectrum.net 3 employees
-
#22
rockwellautomation.com 2 employees
-
#23
andriasoft.com 2 employees
-
#24
ig.com.br 2 employees
-
#25
k12.tr 2 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 2 employees
-
#2
rockwellautomation.com 2 employees
-
#3
twc.com 1 employees
-
#4
netflix.com 1 employees
-
#5
henryschein.com 1 employees
-
#6
fedex.com 1 employees
-
#7
cognizant.com 1 employees
-
#8
boeing.com 1 employees
Compromised users
-
#1
google.com 2,017 users
-
#2
facebook.com 1,380 users
-
#3
netflix.com 517 users
-
#4
paypal.com 441 users
-
#5
amazon.com 403 users
-
#6
apple.com 296 users
-
#7
ebay.com 137 users
-
#8
ups.com 28 users
-
#9
oracle.com 28 users
-
#10
hp.com 26 users
-
#11
walmart.com 25 users
-
#12
microsoft.com 24 users
-
#13
nike.com 20 users
-
#14
capitalone.com 19 users
-
#15
att.com 18 users
-
#16
wellsfargo.com 17 users
-
#17
adp.com 17 users
-
#18
bankofamerica.com 16 users
-
#19
cisco.com 15 users
-
#20
bestbuy.com 15 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,371hits
- #2 sso 1,140hits
- #3 webmail 342hits
- #4 adfs 249hits
- #5 owa 117hits
- #6 github 94hits
- #7 imap 84hits
- #8 zoom 79hits
- #9 zendesk 64hits
- #10 sts 62hits
- #11 oracle 59hits
- #12 extranet 55hits
- #13 ftp 47hits
- #14 vpn 47hits
- #15 cpanel 45hits
- #16 sap 41hits
- #17 st 35hits
- #18 kaspersky 31hits
- #19 citrix 21hits
- #20 dana-na 20hits
- #21 webex 17hits
- #22 ping 16hits
- #23 gitlab 13hits
- #24 zimbra 12hits
- #25 roundcube 10hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains