Infostealers Weekly Report: 2020-08-03 – 2020-08-09
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 2,455
- #2 France 397
- #3 Spain 368
- #4 Germany 285
- #5 United Kingdom 216
- #6 India 183
- #7 Canada 147
- #8 Indonesia 147
- #9 Brazil 117
- #10 Israel 81
- #11 Philippines 68
- #12 Pakistan 61
- #13 Russia 60
- #14 Belgium 49
- #15 Italy 49
- #16 Vietnam 45
- #17 Turkey 45
- #18 Mexico 43
- #19 Australia 39
- #20 Sweden 36
- #21 Egypt 35
- #22 Argentina 33
- #23 Japan 24
- #24 Thailand 23
- #25 Poland 23
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,218 users
-
#2
facebook.com 3,549 users
-
#3
live.com 3,147 users
-
#4
amazon.com 1,942 users
-
#5
netflix.com 1,712 users
-
#6
paypal.com 1,668 users
-
#7
twitter.com 1,617 users
-
#8
twitch.tv 1,390 users
-
#9
roblox.com 1,352 users
-
#10
discordapp.com 1,342 users
-
#11
epicgames.com 1,269 users
-
#12
minecraft.net 1,255 users
-
#13
instagram.com 1,230 users
-
#14
yahoo.com 1,050 users
-
#15
steampowered.com 1,047 users
-
#16
apple.com 998 users
-
#17
spotify.com 986 users
-
#18
steamcommunity.com 983 users
-
#19
linkedin.com 803 users
-
#20
mega.nz 768 users
-
#21
dropbox.com 756 users
-
#22
com.netflix.mediaclient 746 users
-
#23
ebay.com 742 users
-
#24
sonyentertainmentnetwork.com 738 users
-
#25
726 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 32 employees
-
#2
k12.fl.us 19 employees
-
#3
16 employees
-
#4
secureserver.net 14 employees
-
#5
spectrum.net 14 employees
-
#6
icicibank.com 11 employees
-
#7
twc.com 11 employees
-
#8
dadeschools.net 11 employees
-
#9
confused.com 10 employees
-
#10
one.com 10 employees
-
#11
ky.gov 9 employees
-
#12
hcps.net 9 employees
-
#13
maccabi4u.co.il 9 employees
-
#14
accenture.com 9 employees
-
#15
bluehost.com 8 employees
-
#16
ovh.net 8 employees
-
#17
ovh.com 7 employees
-
#18
rmunify.com 7 employees
-
#19
163.com 7 employees
-
#20
browardschools.com 7 employees
-
#21
hostgator.com 6 employees
-
#22
katyisd.org 6 employees
-
#23
jwpub.org 6 employees
-
#24
jcyl.es 6 employees
-
#25
lausd.net 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 32 employees
-
#2
twc.com 11 employees
-
#3
microsoft.com 4 employees
-
#4
frontier.com 4 employees
-
#5
rockwellautomation.com 4 employees
-
#6
apple.com 4 employees
-
#7
aa.com 2 employees
-
#8
ibm.com 2 employees
-
#9
blackrock.com 2 employees
-
#10
wrberkley.com 1 employees
-
#11
marriott.com 1 employees
-
#12
dish.com 1 employees
-
#13
att.com 1 employees
-
#14
netflix.com 1 employees
-
#15
ncr.com 1 employees
-
#16
harman.com 1 employees
-
#17
aramark.com 1 employees
-
#18
chs.net 1 employees
-
#19
johnsoncontrols.com 1 employees
-
#20
fedex.com 1 employees
Compromised users
-
#1
google.com 5,217 users
-
#2
facebook.com 3,548 users
-
#3
amazon.com 1,942 users
-
#4
netflix.com 1,712 users
-
#5
paypal.com 1,668 users
-
#6
apple.com 998 users
-
#7
ebay.com 742 users
-
#8
walmart.com 427 users
-
#9
capitalone.com 258 users
-
#10
att.com 252 users
-
#11
adp.com 244 users
-
#12
target.com 229 users
-
#13
wellsfargo.com 219 users
-
#14
bestbuy.com 206 users
-
#15
ups.com 200 users
-
#16
bankofamerica.com 153 users
-
#17
fedex.com 148 users
-
#18
oracle.com 141 users
-
#19
costco.com 133 users
-
#20
americanexpress.com 120 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 14,723hits
- #2 sso 4,969hits
- #3 adfs 1,652hits
- #4 zoom 836hits
- #5 webmail 816hits
- #6 github 510hits
- #7 owa 406hits
- #8 sts 364hits
- #9 zendesk 328hits
- #10 oracle 322hits
- #11 ftp 286hits
- #12 sap 282hits
- #13 ping 226hits
- #14 vpn 170hits
- #15 cpanel 160hits
- #16 imap 135hits
- #17 st 134hits
- #18 kaspersky 128hits
- #19 extranet 121hits
- #20 webex 107hits
- #21 salesforce 96hits
- #22 dana-na 71hits
- #23 citrix 70hits
- #24 zimbra 60hits
- #25 okta 58hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains