Infostealers Weekly Report: 2020-04-27 – 2020-05-03
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Spain 696
- #2 Brazil 386
- #3 France 338
- #4 Pakistan 260
- #5 Turkey 240
- #6 United Kingdom 230
- #7 Germany 215
- #8 United States of America 183
- #9 Canada 163
- #10 Indonesia 144
- #11 Egypt 107
- #12 Algeria 105
- #13 Israel 87
- #14 Argentina 86
- #15 Bangladesh 80
- #16 Philippines 78
- #17 Thailand 70
- #18 Morocco 61
- #19 Romania 53
- #20 Malaysia 51
- #21 Vietnam 49
- #22 Australia 44
- #23 Belgium 39
- #24 India 38
- #25 Hungary 35
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,501 users
-
#2
facebook.com 3,014 users
-
#3
live.com 2,243 users
-
#4
paypal.com 1,238 users
-
#5
twitter.com 1,168 users
-
#6
netflix.com 1,133 users
-
#7
discordapp.com 918 users
-
#8
instagram.com 878 users
-
#9
epicgames.com 817 users
-
#10
twitch.tv 810 users
-
#11
mega.nz 787 users
-
#12
steampowered.com 742 users
-
#13
roblox.com 740 users
-
#14
amazon.com 725 users
-
#15
com.facebook.katana 687 users
-
#16
minecraft.net 661 users
-
#17
steamcommunity.com 658 users
-
#18
yahoo.com 547 users
-
#19
apple.com 541 users
-
#20
com.spotify.music 541 users
-
#21
com.netflix.mediaclient 528 users
-
#22
spotify.com 518 users
-
#23
sonyentertainmentnetwork.com 514 users
-
#24
dropbox.com 485 users
-
#25
482 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
confused.com 15 employees
-
#2
rmunify.com 11 employees
-
#3
cned.fr 10 employees
-
#4
orange.es 9 employees
-
#5
9 employees
-
#6
jcyl.es 8 employees
-
#7
jwpub.org 7 employees
-
#8
abv.bg 7 employees
-
#9
freenet.de 7 employees
-
#10
maccabi4u.co.il 7 employees
-
#11
freemail.hu 7 employees
-
#12
1and1.es 7 employees
-
#13
ig.com.br 6 employees
-
#14
juntadeandalucia.es 6 employees
-
#15
microsoft.com 5 employees
-
#16
webmail.es 5 employees
-
#17
vic.edu.au 5 employees
-
#18
ionos.es 5 employees
-
#19
ovh.net 5 employees
-
#20
one.com 5 employees
-
#21
gmx.es 4 employees
-
#22
pdsb.org 4 employees
-
#23
uol.com.br 4 employees
-
#24
secureserver.net 4 employees
-
#25
engelbert-strauss.de 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 5 employees
-
#2
cognizant.com 2 employees
-
#3
rockwellautomation.com 1 employees
-
#4
ebay.com 1 employees
-
#5
paypal.com 1 employees
-
#6
amerisourcebergen.com 1 employees
-
#7
publix.com 1 employees
-
#8
netflix.com 1 employees
-
#9
cbre.com 1 employees
-
#10
aa.com 1 employees
Compromised users
-
#1
google.com 3,498 users
-
#2
facebook.com 3,012 users
-
#3
paypal.com 1,238 users
-
#4
netflix.com 1,132 users
-
#5
amazon.com 725 users
-
#6
apple.com 541 users
-
#7
ebay.com 222 users
-
#8
oracle.com 67 users
-
#9
nike.com 55 users
-
#10
hp.com 52 users
-
#11
ups.com 38 users
-
#12
walmart.com 37 users
-
#13
westernunion.com 34 users
-
#14
microsoft.com 29 users
-
#15
americanexpress.com 28 users
-
#16
capitalone.com 27 users
-
#17
adp.com 25 users
-
#18
cisco.com 22 users
-
#19
target.com 21 users
-
#20
att.com 19 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 6,239hits
- #2 sso 1,976hits
- #3 adfs 444hits
- #4 webmail 426hits
- #5 zoom 291hits
- #6 github 200hits
- #7 imap 188hits
- #8 sts 177hits
- #9 owa 176hits
- #10 oracle 156hits
- #11 sap 127hits
- #12 ftp 121hits
- #13 zendesk 110hits
- #14 kaspersky 81hits
- #15 extranet 75hits
- #16 cpanel 74hits
- #17 salesforce 72hits
- #18 st 72hits
- #19 vpn 52hits
- #20 ping 50hits
- #21 webex 35hits
- #22 dana-na 33hits
- #23 roundcube 33hits
- #24 citrix 32hits
- #25 zimbra 23hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains