Infostealers Weekly Report: 2020-06-01 – 2020-06-07
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 1,632
- #2 Brazil 821
- #3 India 643
- #4 Spain 524
- #5 Indonesia 370
- #6 Egypt 341
- #7 France 322
- #8 Bangladesh 223
- #9 Germany 197
- #10 Canada 182
- #11 Argentina 167
- #12 Algeria 135
- #13 United Kingdom 112
- #14 Chile 107
- #15 Hungary 82
- #16 Colombia 62
- #17 Pakistan 61
- #18 Ecuador 60
- #19 Greece 60
- #20 Australia 59
- #21 Bulgaria 47
- #22 United Arab Emirates 45
- #23 Vietnam 39
- #24 Turkey 39
- #25 Bosnia & Herzegovina 36
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,933 users
-
#2
facebook.com 4,254 users
-
#3
live.com 3,478 users
-
#4
twitter.com 1,829 users
-
#5
amazon.com 1,809 users
-
#6
netflix.com 1,806 users
-
#7
paypal.com 1,717 users
-
#8
instagram.com 1,365 users
-
#9
discordapp.com 1,313 users
-
#10
mega.nz 1,282 users
-
#11
yahoo.com 1,184 users
-
#12
twitch.tv 1,149 users
-
#13
roblox.com 1,139 users
-
#14
epicgames.com 1,092 users
-
#15
1,058 users
-
#16
steampowered.com 1,044 users
-
#17
linkedin.com 1,021 users
-
#18
apple.com 1,004 users
-
#19
minecraft.net 967 users
-
#20
com.facebook.katana 952 users
-
#21
dropbox.com 907 users
-
#22
steamcommunity.com 905 users
-
#23
com.netflix.mediaclient 871 users
-
#24
spotify.com 868 users
-
#25
com.spotify.music 747 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 27 employees
-
#2
rediff.com 23 employees
-
#3
icicibank.com 21 employees
-
#4
abv.bg 18 employees
-
#5
16 employees
-
#6
accenture.com 14 employees
-
#7
freemail.hu 13 employees
-
#8
secureserver.net 13 employees
-
#9
POP3://pop.gmail.com:995 12 employees
-
#10
digimail.in 12 employees
-
#11
uol.com.br 12 employees
-
#12
ovh.net 10 employees
-
#13
nbg.gr 10 employees
-
#14
twc.com 10 employees
-
#15
confused.com 9 employees
-
#16
cox.net 8 employees
-
#17
mail.de 8 employees
-
#18
hostgator.com.br 8 employees
-
#19
spectrum.net 8 employees
-
#20
dadeschools.net 8 employees
-
#21
web-hosting.com 7 employees
-
#22
ig.com.br 7 employees
-
#23
1and1.es 7 employees
-
#24
netpnb.com 7 employees
-
#25
inacap.cl 7 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 27 employees
-
#2
twc.com 10 employees
-
#3
frontier.com 5 employees
-
#4
verizon.com 2 employees
-
#5
delta.com 2 employees
-
#6
charter.com 2 employees
-
#7
ebay.com 2 employees
-
#8
rockwellautomation.com 2 employees
-
#9
oracle.com 1 employees
-
#10
gapinc.com 1 employees
-
#11
honeywell.com 1 employees
-
#12
raytheon.com 1 employees
-
#13
masco.com 1 employees
-
#14
mattel.com 1 employees
-
#15
sherwin.com 1 employees
-
#16
dteenergy.com 1 employees
-
#17
pg.com 1 employees
-
#18
xcelenergy.com 1 employees
-
#19
bestbuy.com 1 employees
-
#20
ibm.com 1 employees
Compromised users
-
#1
google.com 5,933 users
-
#2
facebook.com 4,254 users
-
#3
amazon.com 1,809 users
-
#4
netflix.com 1,806 users
-
#5
paypal.com 1,717 users
-
#6
apple.com 1,004 users
-
#7
ebay.com 705 users
-
#8
walmart.com 310 users
-
#9
capitalone.com 207 users
-
#10
att.com 186 users
-
#11
adp.com 177 users
-
#12
target.com 159 users
-
#13
oracle.com 150 users
-
#14
ups.com 148 users
-
#15
bestbuy.com 129 users
-
#16
fedex.com 126 users
-
#17
wellsfargo.com 121 users
-
#18
bankofamerica.com 120 users
-
#19
americanexpress.com 108 users
-
#20
hp.com 102 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 13,213hits
- #2 sso 4,564hits
- #3 adfs 1,184hits
- #4 webmail 1,004hits
- #5 github 514hits
- #6 imap 509hits
- #7 zoom 389hits
- #8 ftp 384hits
- #9 owa 381hits
- #10 sts 347hits
- #11 zendesk 334hits
- #12 oracle 318hits
- #13 cpanel 304hits
- #14 sap 277hits
- #15 ping 211hits
- #16 extranet 170hits
- #17 vpn 157hits
- #18 st 138hits
- #19 kaspersky 101hits
- #20 salesforce 89hits
- #21 webex 85hits
- #22 zimbra 65hits
- #23 okta 64hits
- #24 citrix 63hits
- #25 dana-na 55hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains