Infostealers Weekly Report: 2020-05-11 – 2020-05-17
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 798
- #2 India 587
- #3 France 439
- #4 Spain 394
- #5 Brazil 210
- #6 Turkey 207
- #7 Pakistan 171
- #8 Germany 131
- #9 Egypt 120
- #10 Thailand 98
- #11 United Kingdom 83
- #12 Indonesia 81
- #13 Canada 75
- #14 Philippines 68
- #15 Vietnam 49
- #16 Poland 49
- #17 Bangladesh 47
- #18 Algeria 47
- #19 Morocco 46
- #20 Israel 41
- #21 Romania 40
- #22 Ukraine 38
- #23 Argentina 36
- #24 Mexico 34
- #25 Australia 33
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,963 users
-
#2
facebook.com 2,758 users
-
#3
live.com 2,188 users
-
#4
roblox.com 934 users
-
#5
netflix.com 923 users
-
#6
twitter.com 881 users
-
#7
discordapp.com 831 users
-
#8
instagram.com 825 users
-
#9
epicgames.com 798 users
-
#10
twitch.tv 763 users
-
#11
minecraft.net 662 users
-
#12
mega.nz 655 users
-
#13
steampowered.com 653 users
-
#14
amazon.com 603 users
-
#15
598 users
-
#16
steamcommunity.com 569 users
-
#17
paypal.com 559 users
-
#18
yahoo.com 476 users
-
#19
apple.com 432 users
-
#20
linkedin.com 412 users
-
#21
spotify.com 410 users
-
#22
sonyentertainmentnetwork.com 397 users
-
#23
microsoftonline.com 373 users
-
#24
leagueoflegends.com 364 users
-
#25
com.spotify.music 355 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 18 employees
-
#2
rediff.com 14 employees
-
#3
11 employees
-
#4
ukr.net 9 employees
-
#5
o2.pl 9 employees
-
#6
jcyl.es 7 employees
-
#7
netpnb.com 7 employees
-
#8
mail.de 6 employees
-
#9
telefonica.net 6 employees
-
#10
one.com 5 employees
-
#11
interia.pl 5 employees
-
#12
accenture.com 5 employees
-
#13
ovh.net 5 employees
-
#14
freemail.hu 4 employees
-
#15
mail.com.tr 4 employees
-
#16
twc.com 4 employees
-
#17
skole.hr 4 employees
-
#18
hostgator.com 4 employees
-
#19
digimail.in 4 employees
-
#20
inacap.cl 4 employees
-
#21
dadeschools.net 4 employees
-
#22
movistar.es 4 employees
-
#23
qq.com 3 employees
-
#24
webmail.es 3 employees
-
#25
ocps.net 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
twc.com 4 employees
-
#2
publix.com 2 employees
-
#3
cognizant.com 2 employees
-
#4
honeywell.com 1 employees
-
#5
pg.com 1 employees
-
#6
rockwellautomation.com 1 employees
-
#7
pfizer.com 1 employees
-
#8
cisco.com 1 employees
-
#9
disney.com 1 employees
-
#10
apple.com 1 employees
-
#11
amazon.com 1 employees
-
#12
emc.com 1 employees
-
#13
jpmorganchase.com 1 employees
Compromised users
-
#1
google.com 3,963 users
-
#2
facebook.com 2,757 users
-
#3
netflix.com 923 users
-
#4
amazon.com 603 users
-
#5
paypal.com 559 users
-
#6
apple.com 432 users
-
#7
ebay.com 179 users
-
#8
oracle.com 79 users
-
#9
walmart.com 40 users
-
#10
ups.com 35 users
-
#11
adp.com 32 users
-
#12
hp.com 32 users
-
#13
nike.com 30 users
-
#14
att.com 29 users
-
#15
capitalone.com 29 users
-
#16
target.com 21 users
-
#17
microsoft.com 21 users
-
#18
cisco.com 20 users
-
#19
americanexpress.com 18 users
-
#20
wellsfargo.com 18 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 6,149hits
- #2 sso 1,857hits
- #3 adfs 542hits
- #4 webmail 374hits
- #5 zoom 210hits
- #6 owa 210hits
- #7 github 196hits
- #8 oracle 172hits
- #9 sap 164hits
- #10 sts 110hits
- #11 extranet 94hits
- #12 zendesk 87hits
- #13 zimbra 86hits
- #14 st 56hits
- #15 ftp 56hits
- #16 kaspersky 55hits
- #17 cpanel 42hits
- #18 ping 38hits
- #19 webex 38hits
- #20 roundcube 29hits
- #21 dana-na 25hits
- #22 vpn 25hits
- #23 salesforce 23hits
- #24 citrix 19hits
- #25 jira 18hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains