Infostealers Weekly Report: 2020-06-15 – 2020-06-21
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,966
- #2 United States of America 1,863
- #3 Brazil 813
- #4 Indonesia 790
- #5 France 614
- #6 Pakistan 534
- #7 Spain 460
- #8 Philippines 379
- #9 Germany 373
- #10 Thailand 345
- #11 Egypt 335
- #12 Turkey 245
- #13 Mexico 226
- #14 Vietnam 195
- #15 Algeria 186
- #16 Bangladesh 183
- #17 Argentina 183
- #18 Colombia 177
- #19 Poland 177
- #20 Peru 173
- #21 Morocco 173
- #22 Malaysia 165
- #23 Canada 142
- #24 Chile 127
- #25 Sri Lanka 112
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 10,015 users
-
#2
facebook.com 7,114 users
-
#3
live.com 5,581 users
-
#4
\ 2,818 users
-
#5
|_) 2,818 users
-
#6
___| 2,818 users
-
#7
_ 2,818 users
-
#8
twitter.com 2,749 users
-
#9
netflix.com 2,684 users
-
#10
amazon.com 2,660 users
-
#11
paypal.com 2,229 users
-
#12
instagram.com 2,214 users
-
#13
roblox.com 1,957 users
-
#14
mega.nz 1,952 users
-
#15
1,928 users
-
#16
yahoo.com 1,893 users
-
#17
com.facebook.katana 1,856 users
-
#18
epicgames.com 1,819 users
-
#19
discordapp.com 1,790 users
-
#20
twitch.tv 1,688 users
-
#21
steampowered.com 1,588 users
-
#22
linkedin.com 1,515 users
-
#23
minecraft.net 1,433 users
-
#24
apple.com 1,378 users
-
#25
com.netflix.mediaclient 1,332 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 62 employees
-
#2
icicibank.com 40 employees
-
#3
38 employees
-
#4
publix.com 34 employees
-
#5
digimail.in 32 employees
-
#6
secureserver.net 23 employees
-
#7
http://localhost/wordpress/wp-admin/install.php 16 employees
-
#8
onlinesbi.com 16 employees
-
#9
interia.pl 16 employees
-
#10
o2.pl 15 employees
-
#11
aruba.it 13 employees
-
#12
ovh.net 12 employees
-
#13
hostgator.com 12 employees
-
#14
bni.co.id 12 employees
-
#15
rockwellautomation.com 12 employees
-
#16
onet.pl 11 employees
-
#17
k12.fl.us 11 employees
-
#18
accenture.com 10 employees
-
#19
ig.com.br 10 employees
-
#20
cognizant.com 10 employees
-
#21
163.com 10 employees
-
#22
telecom.pt 10 employees
-
#23
freemail.hu 10 employees
-
#24
bluehost.com 9 employees
-
#25
mail.gov.in 9 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 34 employees
-
#2
rockwellautomation.com 12 employees
-
#3
cognizant.com 10 employees
-
#4
twc.com 7 employees
-
#5
microsoft.com 4 employees
-
#6
delta.com 3 employees
-
#7
netflix.com 2 employees
-
#8
att.com 2 employees
-
#9
frontier.com 2 employees
-
#10
emc.com 2 employees
-
#11
hp.com 2 employees
-
#12
ncr.com 1 employees
-
#13
centurylink.com 1 employees
-
#14
tjx.com 1 employees
-
#15
supervalu.com 1 employees
-
#16
aramark.com 1 employees
-
#17
aa.com 1 employees
-
#18
charter.com 1 employees
-
#19
halliburton.com 1 employees
-
#20
humana.com 1 employees
Compromised users
-
#1
google.com 10,015 users
-
#2
facebook.com 7,113 users
-
#3
netflix.com 2,684 users
-
#4
amazon.com 2,660 users
-
#5
paypal.com 2,229 users
-
#6
apple.com 1,378 users
-
#7
ebay.com 859 users
-
#8
walmart.com 407 users
-
#9
oracle.com 303 users
-
#10
capitalone.com 241 users
-
#11
att.com 224 users
-
#12
ups.com 209 users
-
#13
adp.com 203 users
-
#14
wellsfargo.com 198 users
-
#15
target.com 187 users
-
#16
bestbuy.com 167 users
-
#17
fedex.com 165 users
-
#18
americanexpress.com 153 users
-
#19
bankofamerica.com 152 users
-
#20
cisco.com 141 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 20,767hits
- #2 sso 7,754hits
- #3 webmail 1,922hits
- #4 zoom 1,659hits
- #5 adfs 1,656hits
- #6 github 1,013hits
- #7 owa 665hits
- #8 oracle 642hits
- #9 sap 470hits
- #10 cpanel 463hits
- #11 imap 402hits
- #12 zendesk 399hits
- #13 sts 359hits
- #14 ftp 356hits
- #15 ping 317hits
- #16 vpn 280hits
- #17 st 270hits
- #18 webex 243hits
- #19 extranet 212hits
- #20 citrix 173hits
- #21 roundcube 144hits
- #22 zimbra 117hits
- #23 twilio 109hits
- #24 gitlab 107hits
- #25 kaspersky 105hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains