Infostealers Weekly Report: 2020-05-04 – 2020-05-10
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 4,053
- #2 Brazil 2,987
- #3 United States of America 2,748
- #4 Turkey 1,910
- #5 Pakistan 1,706
- #6 Indonesia 1,532
- #7 Egypt 1,481
- #8 Vietnam 1,088
- #9 Spain 1,053
- #10 Thailand 865
- #11 France 841
- #12 Philippines 802
- #13 Algeria 716
- #14 Argentina 662
- #15 Mexico 601
- #16 Germany 599
- #17 Morocco 595
- #18 Bangladesh 574
- #19 Peru 510
- #20 Colombia 457
- #21 Malaysia 451
- #22 Romania 417
- #23 Sri Lanka 380
- #24 Canada 333
- #25 Chile 320
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 26,224 users
-
#2
facebook.com 17,501 users
-
#3
live.com 14,230 users
-
#4
twitter.com 6,871 users
-
#5
netflix.com 6,641 users
-
#6
mega.nz 5,906 users
-
#7
instagram.com 5,660 users
-
#8
amazon.com 5,405 users
-
#9
paypal.com 4,953 users
-
#10
roblox.com 4,632 users
-
#11
discordapp.com 4,508 users
-
#12
yahoo.com 4,454 users
-
#13
4,228 users
-
#14
epicgames.com 4,065 users
-
#15
steampowered.com 3,913 users
-
#16
com.facebook.katana 3,844 users
-
#17
twitch.tv 3,825 users
-
#18
linkedin.com 3,771 users
-
#19
apple.com 3,193 users
-
#20
minecraft.net 3,140 users
-
#21
steamcommunity.com 3,085 users
-
#22
microsoftonline.com 2,806 users
-
#23
com.netflix.mediaclient 2,715 users
-
#24
dropbox.com 2,706 users
-
#25
spotify.com 2,557 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 101 employees
-
#2
rediff.com 90 employees
-
#3
secureserver.net 56 employees
-
#4
digimail.in 53 employees
-
#5
52 employees
-
#6
o2.pl 40 employees
-
#7
onlinesbi.com 36 employees
-
#8
freemail.hu 36 employees
-
#9
yandex.com.tr 36 employees
-
#10
http://localhost/wordpress/wp-admin/install.php 32 employees
-
#11
abv.bg 32 employees
-
#12
ig.com.br 29 employees
-
#13
accenture.com 28 employees
-
#14
netpnb.com 27 employees
-
#15
mail.gov.in 27 employees
-
#16
jwpub.org 26 employees
-
#17
telecom.pt 25 employees
-
#18
onet.pl 25 employees
-
#19
interia.pl 23 employees
-
#20
publix.com 23 employees
-
#21
moe.gov.ae 22 employees
-
#22
bluehost.com 22 employees
-
#23
ovh.net 22 employees
-
#24
indusind.com 22 employees
-
#25
sapo.pt 20 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 23 employees
-
#2
microsoft.com 12 employees
-
#3
cognizant.com 11 employees
-
#4
twc.com 9 employees
-
#5
rockwellautomation.com 7 employees
-
#6
frontier.com 6 employees
-
#7
att.com 6 employees
-
#8
amazon.com 5 employees
-
#9
hp.com 5 employees
-
#10
netflix.com 4 employees
-
#11
emc.com 3 employees
-
#12
praxair.com 2 employees
-
#13
fedex.com 2 employees
-
#14
oracle.com 2 employees
-
#15
gs.com 2 employees
-
#16
centurylink.com 1 employees
-
#17
csc.com 1 employees
-
#18
cummins.com 1 employees
-
#19
cigna.com 1 employees
-
#20
unfi.com 1 employees
Compromised users
-
#1
google.com 26,218 users
-
#2
facebook.com 17,494 users
-
#3
netflix.com 6,641 users
-
#4
amazon.com 5,405 users
-
#5
paypal.com 4,953 users
-
#6
apple.com 3,193 users
-
#7
ebay.com 1,579 users
-
#8
oracle.com 601 users
-
#9
walmart.com 486 users
-
#10
hp.com 308 users
-
#11
ups.com 305 users
-
#12
capitalone.com 291 users
-
#13
cisco.com 283 users
-
#14
microsoft.com 273 users
-
#15
att.com 273 users
-
#16
adp.com 268 users
-
#17
bestbuy.com 247 users
-
#18
target.com 225 users
-
#19
wellsfargo.com 209 users
-
#20
fedex.com 200 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 43,907hits
- #2 sso 16,891hits
- #3 webmail 3,448hits
- #4 adfs 3,181hits
- #5 zoom 2,672hits
- #6 github 1,814hits
- #7 owa 1,430hits
- #8 oracle 1,295hits
- #9 sap 1,226hits
- #10 sts 1,006hits
- #11 zendesk 882hits
- #12 cpanel 841hits
- #13 ftp 789hits
- #14 ping 587hits
- #15 extranet 554hits
- #16 st 488hits
- #17 webex 467hits
- #18 vpn 442hits
- #19 kaspersky 356hits
- #20 salesforce 279hits
- #21 imap 224hits
- #22 roundcube 202hits
- #23 zimbra 167hits
- #24 citrix 144hits
- #25 dana-na 142hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains