Infostealers Weekly Report: 2020-05-25 – 2020-05-31
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 250
- #2 United States of America 158
- #3 Egypt 78
- #4 Thailand 73
- #5 Turkey 70
- #6 Indonesia 62
- #7 Brazil 57
- #8 Philippines 53
- #9 Pakistan 48
- #10 Vietnam 39
- #11 Japan 30
- #12 Sri Lanka 24
- #13 Morocco 24
- #14 South Korea 22
- #15 Malaysia 22
- #16 Algeria 18
- #17 Bangladesh 16
- #18 Australia 15
- #19 Argentina 15
- #20 Colombia 14
- #21 Mexico 14
- #22 Poland 13
- #23 Spain 13
- #24 Germany 13
- #25 Romania 12
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,069 users
-
#2
facebook.com 593 users
-
#3
live.com 510 users
-
#4
netflix.com 260 users
-
#5
twitter.com 258 users
-
#6
246 users
-
#7
amazon.com 223 users
-
#8
instagram.com 215 users
-
#9
mega.nz 209 users
-
#10
roblox.com 199 users
-
#11
epicgames.com 192 users
-
#12
yahoo.com 183 users
-
#13
paypal.com 176 users
-
#14
discordapp.com 171 users
-
#15
twitch.tv 162 users
-
#16
linkedin.com 155 users
-
#17
steampowered.com 151 users
-
#18
apple.com 126 users
-
#19
steamcommunity.com 125 users
-
#20
minecraft.net 122 users
-
#21
microsoftonline.com 103 users
-
#22
dropbox.com 102 users
-
#23
rockstargames.com 99 users
-
#24
spotify.com 93 users
-
#25
discord.com 85 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 7 employees
-
#2
digimail.in 4 employees
-
#3
onet.pl 4 employees
-
#4
icicibank.com 4 employees
-
#5
3 employees
-
#6
emailsrvr.com 2 employees
-
#7
hawaiiantel.net 2 employees
-
#8
sgcpanel.com 2 employees
-
#9
aiep.cl 2 employees
-
#10
indusind.com 2 employees
-
#11
goo.ne.jp 2 employees
-
#12
freenet.de 2 employees
-
#13
ocps.net 2 employees
-
#14
earthlink.net 2 employees
-
#15
spectrum.net 2 employees
-
#16
aruba.it 2 employees
-
#17
1govuc.gov.my 2 employees
-
#18
ig.com.br 2 employees
-
#19
vox.co.za 2 employees
-
#20
docomo.ne.jp 2 employees
-
#21
gigaplanet.si 1 employees
-
#22
bluehost.com 1 employees
-
#23
hostingnovapyme29.com 1 employees
-
#24
commercebank.com 1 employees
-
#25
manitu.de 1 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
bestbuy.com 1 employees
-
#2
rockwellautomation.com 1 employees
-
#3
frontier.com 1 employees
-
#4
genesishcc.com 1 employees
Compromised users
-
#1
google.com 1,069 users
-
#2
facebook.com 593 users
-
#3
netflix.com 260 users
-
#4
amazon.com 223 users
-
#5
paypal.com 176 users
-
#6
apple.com 126 users
-
#7
ebay.com 60 users
-
#8
oracle.com 23 users
-
#9
walmart.com 16 users
-
#10
capitalone.com 15 users
-
#11
att.com 13 users
-
#12
wellsfargo.com 13 users
-
#13
hp.com 13 users
-
#14
cisco.com 13 users
-
#15
adp.com 12 users
-
#16
ups.com 11 users
-
#17
bestbuy.com 8 users
-
#18
intel.com 7 users
-
#19
ibm.com 7 users
-
#20
americanexpress.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 1,591hits
- #2 sso 510hits
- #3 webmail 128hits
- #4 adfs 99hits
- #5 github 80hits
- #6 zoom 78hits
- #7 owa 59hits
- #8 ftp 47hits
- #9 oracle 46hits
- #10 sap 34hits
- #11 cpanel 33hits
- #12 zendesk 27hits
- #13 ping 26hits
- #14 sts 24hits
- #15 vpn 18hits
- #16 st 18hits
- #17 extranet 15hits
- #18 roundcube 15hits
- #19 kaspersky 13hits
- #20 gitlab 7hits
- #21 salesforce 7hits
- #22 okta 7hits
- #23 citrix 6hits
- #24 webex 5hits
- #25 git 4hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains