Infostealers Weekly Report: 2020-06-29 – 2020-07-05
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,476
- #2 United States of America 1,398
- #3 Brazil 840
- #4 Indonesia 803
- #5 France 581
- #6 Spain 491
- #7 Egypt 442
- #8 Germany 425
- #9 Vietnam 258
- #10 Canada 237
- #11 Pakistan 218
- #12 Turkey 209
- #13 Philippines 199
- #14 Bangladesh 170
- #15 Argentina 164
- #16 Algeria 158
- #17 United Kingdom 158
- #18 Colombia 138
- #19 Morocco 117
- #20 Australia 111
- #21 Thailand 109
- #22 Mexico 101
- #23 Chile 101
- #24 Israel 88
- #25 Romania 75
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 8,540 users
-
#2
facebook.com 6,239 users
-
#3
live.com 4,791 users
-
#4
twitter.com 2,532 users
-
#5
amazon.com 2,291 users
-
#6
netflix.com 2,272 users
-
#7
paypal.com 2,195 users
-
#8
instagram.com 1,945 users
-
#9
discordapp.com 1,789 users
-
#10
mega.nz 1,726 users
-
#11
roblox.com 1,645 users
-
#12
yahoo.com 1,626 users
-
#13
twitch.tv 1,592 users
-
#14
epicgames.com 1,573 users
-
#15
1,547 users
-
#16
steampowered.com 1,468 users
-
#17
linkedin.com 1,428 users
-
#18
com.facebook.katana 1,382 users
-
#19
minecraft.net 1,307 users
-
#20
apple.com 1,302 users
-
#21
steamcommunity.com 1,247 users
-
#22
spotify.com 1,173 users
-
#23
dropbox.com 1,165 users
-
#24
com.netflix.mediaclient 1,066 users
-
#25
com.spotify.music 978 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 44 employees
-
#2
38 employees
-
#3
icicibank.com 36 employees
-
#4
digimail.in 22 employees
-
#5
accenture.com 21 employees
-
#6
publix.com 19 employees
-
#7
secureserver.net 17 employees
-
#8
POP3://pop.gmail.com:995 17 employees
-
#9
http://localhost/wordpress/wp-admin/install.php 17 employees
-
#10
qq.com 16 employees
-
#11
freemail.hu 14 employees
-
#12
cned.fr 13 employees
-
#13
abv.bg 13 employees
-
#14
vic.edu.au 12 employees
-
#15
ig.com.br 12 employees
-
#16
netpnb.com 12 employees
-
#17
idbibank.co.in 12 employees
-
#18
globo.com 12 employees
-
#19
aruba.it 11 employees
-
#20
bluehost.com 11 employees
-
#21
163.com 10 employees
-
#22
one.com 10 employees
-
#23
onlinesbi.com 10 employees
-
#24
hcps.net 10 employees
-
#25
confused.com 9 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 19 employees
-
#2
twc.com 8 employees
-
#3
microsoft.com 4 employees
-
#4
humana.com 4 employees
-
#5
cognizant.com 3 employees
-
#6
frontier.com 3 employees
-
#7
csc.com 3 employees
-
#8
sandisk.com 2 employees
-
#9
rockwellautomation.com 2 employees
-
#10
aecom.com 1 employees
-
#11
gm.com 1 employees
-
#12
amazon.com 1 employees
-
#13
level3.com 1 employees
-
#14
disney.com 1 employees
-
#15
westrock.com 1 employees
-
#16
netflix.com 1 employees
-
#17
cigna.com 1 employees
-
#18
genesishcc.com 1 employees
-
#19
johnsoncontrols.com 1 employees
-
#20
tenethealth.com 1 employees
Compromised users
-
#1
google.com 8,540 users
-
#2
facebook.com 6,239 users
-
#3
amazon.com 2,291 users
-
#4
netflix.com 2,272 users
-
#5
paypal.com 2,195 users
-
#6
apple.com 1,302 users
-
#7
ebay.com 754 users
-
#8
walmart.com 279 users
-
#9
oracle.com 228 users
-
#10
ups.com 180 users
-
#11
capitalone.com 175 users
-
#12
adp.com 167 users
-
#13
att.com 159 users
-
#14
bestbuy.com 134 users
-
#15
target.com 131 users
-
#16
hp.com 122 users
-
#17
americanexpress.com 117 users
-
#18
wellsfargo.com 113 users
-
#19
cisco.com 111 users
-
#20
microsoft.com 102 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 16,279hits
- #2 sso 5,453hits
- #3 webmail 1,451hits
- #4 adfs 1,334hits
- #5 github 761hits
- #6 zoom 682hits
- #7 imap 645hits
- #8 oracle 502hits
- #9 owa 471hits
- #10 zendesk 445hits
- #11 sap 397hits
- #12 ftp 383hits
- #13 cpanel 312hits
- #14 sts 293hits
- #15 vpn 220hits
- #16 ping 200hits
- #17 st 188hits
- #18 extranet 164hits
- #19 kaspersky 153hits
- #20 webex 118hits
- #21 zimbra 110hits
- #22 salesforce 84hits
- #23 dana-na 83hits
- #24 jira 73hits
- #25 roundcube 73hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains