Infostealers Weekly Report: 2020-05-18 – 2020-05-24
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,882
- #2 United States of America 998
- #3 Brazil 766
- #4 Pakistan 407
- #5 Indonesia 344
- #6 Turkey 301
- #7 Thailand 300
- #8 Mexico 289
- #9 Egypt 245
- #10 Vietnam 196
- #11 Colombia 190
- #12 Argentina 188
- #13 Philippines 158
- #14 Peru 149
- #15 Romania 141
- #16 Poland 137
- #17 Chile 136
- #18 Malaysia 126
- #19 Bangladesh 121
- #20 Sri Lanka 116
- #21 Morocco 110
- #22 Algeria 109
- #23 South Korea 103
- #24 Ukraine 96
- #25 South Africa 92
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,734 users
-
#2
facebook.com 3,903 users
-
#3
live.com 3,448 users
-
#4
1,993 users
-
#5
netflix.com 1,508 users
-
#6
twitter.com 1,459 users
-
#7
mega.nz 1,453 users
-
#8
instagram.com 1,299 users
-
#9
roblox.com 1,162 users
-
#10
discordapp.com 1,122 users
-
#11
amazon.com 1,120 users
-
#12
epicgames.com 1,100 users
-
#13
paypal.com 1,051 users
-
#14
steampowered.com 994 users
-
#15
yahoo.com 967 users
-
#16
twitch.tv 922 users
-
#17
linkedin.com 883 users
-
#18
admin 809 users
-
#19
steamcommunity.com 755 users
-
#20
minecraft.net 754 users
-
#21
microsoftonline.com 606 users
-
#22
dropbox.com 586 users
-
#23
spotify.com 583 users
-
#24
rockstargames.com 571 users
-
#25
javascript:; 560 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 53 employees
-
#2
icicibank.com 49 employees
-
#3
digimail.in 17 employees
-
#4
interia.pl 15 employees
-
#5
onlinesbi.com 15 employees
-
#6
13 employees
-
#7
telecom.pt 13 employees
-
#8
o2.pl 13 employees
-
#9
secureserver.net 13 employees
-
#10
netpnb.com 12 employees
-
#11
idbibank.co.in 10 employees
-
#12
freemail.hu 10 employees
-
#13
accenture.com 10 employees
-
#14
mail.gov.in 8 employees
-
#15
skole.hr 8 employees
-
#16
sapo.pt 7 employees
-
#17
jwpub.org 7 employees
-
#18
indiapost.gov.in 6 employees
-
#19
inacap.cl 6 employees
-
#20
unionbankonline.co.in 6 employees
-
#21
http://localhost/wordpress/wp-admin/install.php 6 employees
-
#22
uol.com.br 6 employees
-
#23
mail.bg 6 employees
-
#24
k12.fl.us 5 employees
-
#25
icai.org 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 4 employees
-
#2
rockwellautomation.com 3 employees
-
#3
microsoft.com 3 employees
-
#4
hp.com 2 employees
-
#5
apple.com 1 employees
-
#6
aig.com 1 employees
-
#7
bbt.com 1 employees
-
#8
kiewit.com 1 employees
-
#9
adm.com 1 employees
-
#10
jacobs.com 1 employees
-
#11
starwoodhotels.com 1 employees
-
#12
jetblue.com 1 employees
-
#13
halliburton.com 1 employees
Compromised users
-
#1
google.com 6,734 users
-
#2
facebook.com 3,903 users
-
#3
netflix.com 1,508 users
-
#4
amazon.com 1,120 users
-
#5
paypal.com 1,051 users
-
#6
apple.com 528 users
-
#7
ebay.com 289 users
-
#8
oracle.com 122 users
-
#9
walmart.com 62 users
-
#10
hp.com 59 users
-
#11
cisco.com 55 users
-
#12
adp.com 45 users
-
#13
microsoft.com 45 users
-
#14
americanexpress.com 39 users
-
#15
att.com 36 users
-
#16
bestbuy.com 33 users
-
#17
capitalone.com 32 users
-
#18
ibm.com 28 users
-
#19
westernunion.com 26 users
-
#20
target.com 25 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 8,919hits
- #2 sso 3,273hits
- #3 adfs 626hits
- #4 webmail 510hits
- #5 owa 289hits
- #6 github 277hits
- #7 oracle 238hits
- #8 sts 222hits
- #9 sap 168hits
- #10 zendesk 152hits
- #11 cpanel 131hits
- #12 zoom 130hits
- #13 ping 115hits
- #14 extranet 108hits
- #15 webex 98hits
- #16 st 73hits
- #17 ftp 69hits
- #18 kaspersky 63hits
- #19 roundcube 59hits
- #20 git 50hits
- #21 vpn 39hits
- #22 salesforce 36hits
- #23 gitlab 34hits
- #24 imap 32hits
- #25 zimbra 24hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains