Infostealers Weekly Report: 2020-04-20 – 2020-04-26
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Spain 802
- #2 United States of America 674
- #3 France 248
- #4 Canada 131
- #5 Brazil 112
- #6 Egypt 84
- #7 Turkey 69
- #8 Germany 65
- #9 United Kingdom 58
- #10 Mexico 44
- #11 Pakistan 30
- #12 Argentina 29
- #13 Morocco 26
- #14 Colombia 22
- #15 Algeria 20
- #16 Israel 20
- #17 Australia 19
- #18 Poland 16
- #19 Portugal 15
- #20 Peru 14
- #21 Indonesia 13
- #22 Chile 12
- #23 Romania 11
- #24 Iraq 11
- #25 Ecuador 11
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,266 users
-
#2
live.com 1,679 users
-
#3
facebook.com 1,629 users
-
#4
amazon.com 1,460 users
-
#5
netflix.com 888 users
-
#6
twitter.com 776 users
-
#7
twitch.tv 700 users
-
#8
amazon.es 692 users
-
#9
discordapp.com 688 users
-
#10
epicgames.com 631 users
-
#11
minecraft.net 620 users
-
#12
roblox.com 589 users
-
#13
instagram.com 531 users
-
#14
steampowered.com 524 users
-
#15
spotify.com 492 users
-
#16
mega.nz 466 users
-
#17
steamcommunity.com 464 users
-
#18
com.netflix.mediaclient 459 users
-
#19
com.spotify.music 449 users
-
#20
apple.com 401 users
-
#21
com.facebook.katana 397 users
-
#22
yahoo.com 387 users
-
#23
sonyentertainmentnetwork.com 384 users
-
#24
com.contextlogic.wish 379 users
-
#25
dropbox.com 375 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
jcyl.es 11 employees
-
#2
cned.fr 8 employees
-
#3
gmx.es 8 employees
-
#4
1and1.es 8 employees
-
#5
movistar.es 6 employees
-
#6
ionos.es 6 employees
-
#7
orange.es 6 employees
-
#8
publix.com 6 employees
-
#9
6 employees
-
#10
spectrum.net 6 employees
-
#11
ovh.net 5 employees
-
#12
terra.es 5 employees
-
#13
telecom.pt 5 employees
-
#14
juntadeandalucia.es 5 employees
-
#15
jwpub.org 5 employees
-
#16
ub.edu 5 employees
-
#17
bluehost.com 4 employees
-
#18
one.com 4 employees
-
#19
ua.es 4 employees
-
#20
k12.fl.us 4 employees
-
#21
decathlon.es 4 employees
-
#22
indra.es 3 employees
-
#23
iberia.es 3 employees
-
#24
uottawa.ca 3 employees
-
#25
browardschools.com 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 6 employees
-
#2
johnsoncontrols.com 1 employees
-
#3
starwoodhotels.com 1 employees
-
#4
oracle.com 1 employees
-
#5
ibm.com 1 employees
-
#6
gs.com 1 employees
-
#7
microsoft.com 1 employees
-
#8
halliburton.com 1 employees
-
#9
rockwellautomation.com 1 employees
-
#10
delta.com 1 employees
-
#11
ch2m.com 1 employees
-
#12
cbre.com 1 employees
-
#13
chs.net 1 employees
-
#14
genesishcc.com 1 employees
Compromised users
-
#1
google.com 2,265 users
-
#2
facebook.com 1,628 users
-
#3
amazon.com 1,460 users
-
#4
netflix.com 888 users
-
#5
apple.com 401 users
-
#6
ebay.com 179 users
-
#7
paypal.com 147 users
-
#8
walmart.com 98 users
-
#9
target.com 59 users
-
#10
adp.com 48 users
-
#11
att.com 45 users
-
#12
capitalone.com 42 users
-
#13
nike.com 40 users
-
#14
oracle.com 39 users
-
#15
hp.com 33 users
-
#16
ups.com 30 users
-
#17
costco.com 25 users
-
#18
fedex.com 21 users
-
#19
lowes.com 20 users
-
#20
bestbuy.com 20 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 4,986hits
- #2 sso 1,741hits
- #3 adfs 561hits
- #4 webmail 346hits
- #5 zoom 279hits
- #6 owa 162hits
- #7 github 142hits
- #8 sts 128hits
- #9 sap 116hits
- #10 imap 99hits
- #11 zendesk 93hits
- #12 oracle 90hits
- #13 ping 83hits
- #14 extranet 81hits
- #15 cpanel 72hits
- #16 vpn 66hits
- #17 ftp 58hits
- #18 kaspersky 48hits
- #19 st 44hits
- #20 dana-na 37hits
- #21 zimbra 33hits
- #22 okta 25hits
- #23 webex 24hits
- #24 roundcube 24hits
- #25 salesforce 23hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains