Infostealers Weekly Report: 2020-03-30 – 2020-04-05
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 1,906
- #2 France 966
- #3 Indonesia 944
- #4 Turkey 746
- #5 Brazil 596
- #6 Pakistan 595
- #7 Vietnam 457
- #8 Spain 436
- #9 Egypt 372
- #10 India 360
- #11 Italy 332
- #12 Germany 319
- #13 Canada 279
- #14 United Kingdom 271
- #15 Algeria 262
- #16 Bangladesh 228
- #17 Thailand 224
- #18 Philippines 186
- #19 Morocco 177
- #20 Romania 158
- #21 Argentina 157
- #22 Malaysia 140
- #23 Portugal 125
- #24 Australia 113
- #25 Nepal 99
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 10,264 users
-
#2
facebook.com 6,656 users
-
#3
live.com 5,339 users
-
#4
twitter.com 2,715 users
-
#5
netflix.com 2,614 users
-
#6
discordapp.com 2,450 users
-
#7
roblox.com 2,168 users
-
#8
instagram.com 2,143 users
-
#9
paypal.com 2,056 users
-
#10
epicgames.com 2,012 users
-
#11
amazon.com 1,986 users
-
#12
twitch.tv 1,980 users
-
#13
minecraft.net 1,947 users
-
#14
steampowered.com 1,816 users
-
#15
mega.nz 1,772 users
-
#16
yahoo.com 1,610 users
-
#17
steamcommunity.com 1,594 users
-
#18
com.facebook.katana 1,523 users
-
#19
apple.com 1,398 users
-
#20
spotify.com 1,266 users
-
#21
com.netflix.mediaclient 1,203 users
-
#22
1,160 users
-
#23
com.spotify.music 1,154 users
-
#24
linkedin.com 1,135 users
-
#25
sonyentertainmentnetwork.com 1,071 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
pec.it 39 employees
-
#2
tim.it 30 employees
-
#3
telecom.pt 25 employees
-
#4
aruba.it 24 employees
-
#5
freemail.hu 18 employees
-
#6
rediff.com 16 employees
-
#7
rmunify.com 15 employees
-
#8
icicibank.com 15 employees
-
#9
ovh.net 15 employees
-
#10
14 employees
-
#11
abv.bg 14 employees
-
#12
sapo.pt 13 employees
-
#13
nbg.gr 12 employees
-
#14
publix.com 11 employees
-
#15
yandex.com.tr 11 employees
-
#16
cned.fr 10 employees
-
#17
lausd.net 10 employees
-
#18
bluehost.com 10 employees
-
#19
secureserver.net 10 employees
-
#20
digimail.in 10 employees
-
#21
confused.com 10 employees
-
#22
163.com 9 employees
-
#23
numericable.fr 9 employees
-
#24
infocert.it 9 employees
-
#25
netpnb.com 8 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 11 employees
-
#2
frontier.com 4 employees
-
#3
halliburton.com 3 employees
-
#4
twc.com 3 employees
-
#5
cognizant.com 2 employees
-
#6
apple.com 2 employees
-
#7
nike.com 2 employees
-
#8
netflix.com 2 employees
-
#9
hp.com 2 employees
-
#10
rockwellautomation.com 2 employees
-
#11
microsoft.com 1 employees
-
#12
domtar.com 1 employees
-
#13
charter.com 1 employees
-
#14
aramark.com 1 employees
-
#15
att.com 1 employees
-
#16
cbre.com 1 employees
-
#17
fedex.com 1 employees
-
#18
manpowergroup.com 1 employees
-
#19
cmc.com 1 employees
-
#20
citigroup.com 1 employees
Compromised users
-
#1
google.com 10,264 users
-
#2
facebook.com 6,655 users
-
#3
netflix.com 2,614 users
-
#4
paypal.com 2,056 users
-
#5
amazon.com 1,986 users
-
#6
apple.com 1,398 users
-
#7
ebay.com 649 users
-
#8
walmart.com 224 users
-
#9
oracle.com 173 users
-
#10
nike.com 146 users
-
#11
ups.com 143 users
-
#12
adp.com 138 users
-
#13
capitalone.com 130 users
-
#14
target.com 124 users
-
#15
att.com 122 users
-
#16
bestbuy.com 122 users
-
#17
hp.com 105 users
-
#18
wellsfargo.com 99 users
-
#19
fedex.com 85 users
-
#20
westernunion.com 84 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 14,821hits
- #2 sso 5,386hits
- #3 adfs 1,437hits
- #4 webmail 1,070hits
- #5 github 502hits
- #6 owa 438hits
- #7 zoom 432hits
- #8 oracle 364hits
- #9 ftp 338hits
- #10 sap 321hits
- #11 sts 310hits
- #12 imap 299hits
- #13 zendesk 284hits
- #14 cpanel 243hits
- #15 extranet 211hits
- #16 ping 194hits
- #17 st 189hits
- #18 zimbra 154hits
- #19 vpn 152hits
- #20 kaspersky 109hits
- #21 salesforce 87hits
- #22 webex 76hits
- #23 roundcube 53hits
- #24 dana-na 40hits
- #25 bitbucket 35hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains