Infostealers Weekly Report: 2020-08-10 – 2020-08-16
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 France 400
- #2 Pakistan 377
- #3 Germany 338
- #4 Spain 306
- #5 United States of America 298
- #6 India 195
- #7 Vietnam 171
- #8 Turkey 167
- #9 Thailand 160
- #10 United Kingdom 124
- #11 Saudi Arabia 107
- #12 Canada 88
- #13 Poland 86
- #14 Australia 85
- #15 South Africa 81
- #16 Israel 74
- #17 Brazil 67
- #18 Belgium 63
- #19 Sweden 63
- #20 Indonesia 59
- #21 Philippines 58
- #22 Russia 57
- #23 Taiwan 46
- #24 Japan 38
- #25 Venezuela 35
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,993 users
-
#2
facebook.com 2,925 users
-
#3
live.com 2,408 users
-
#4
twitter.com 1,167 users
-
#5
netflix.com 1,076 users
-
#6
instagram.com 972 users
-
#7
amazon.com 891 users
-
#8
epicgames.com 818 users
-
#9
twitch.tv 803 users
-
#10
com.facebook.katana 762 users
-
#11
mega.nz 745 users
-
#12
roblox.com 720 users
-
#13
steampowered.com 707 users
-
#14
apple.com 685 users
-
#15
678 users
-
#16
paypal.com 673 users
-
#17
discordapp.com 665 users
-
#18
yahoo.com 627 users
-
#19
steamcommunity.com 623 users
-
#20
discord.com 601 users
-
#21
minecraft.net 588 users
-
#22
com.spotify.music 577 users
-
#23
linkedin.com 576 users
-
#24
riotgames.com 508 users
-
#25
microsoftonline.com 493 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
taqat.sa 14 employees
-
#2
confused.com 11 employees
-
#3
onet.pl 10 employees
-
#4
http://localhost/wordpress/wp-admin/install.php 10 employees
-
#5
icicibank.com 9 employees
-
#6
interia.pl 8 employees
-
#7
one.com 8 employees
-
#8
ovh.net 7 employees
-
#9
vic.edu.au 6 employees
-
#10
rediff.com 6 employees
-
#11
o2.pl 6 employees
-
#12
yahoosmallbusiness.com 6 employees
-
#13
6 employees
-
#14
tim.it 6 employees
-
#15
aiou.edu.pk 6 employees
-
#16
bluehost.com 6 employees
-
#17
vic.gov.au 6 employees
-
#18
hinet.net 5 employees
-
#19
ukr.net 4 employees
-
#20
jwpub.org 4 employees
-
#21
mail.de 4 employees
-
#22
jcyl.es 4 employees
-
#23
strato.com 4 employees
-
#24
publix.com 4 employees
-
#25
accenture.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 4 employees
-
#2
microsoft.com 3 employees
-
#3
aa.com 2 employees
-
#4
verizon.com 1 employees
-
#5
emc.com 1 employees
-
#6
pepsico.com 1 employees
-
#7
rockwellautomation.com 1 employees
-
#8
bestbuy.com 1 employees
-
#9
hollyfrontier.com 1 employees
-
#10
twc.com 1 employees
-
#11
netflix.com 1 employees
-
#12
labcorp.com 1 employees
-
#13
oracle.com 1 employees
-
#14
cognizant.com 1 employees
-
#15
baxter.com 1 employees
Compromised users
-
#1
google.com 3,993 users
-
#2
facebook.com 2,925 users
-
#3
netflix.com 1,076 users
-
#4
amazon.com 891 users
-
#5
apple.com 685 users
-
#6
paypal.com 673 users
-
#7
ebay.com 267 users
-
#8
oracle.com 100 users
-
#9
walmart.com 90 users
-
#10
hp.com 66 users
-
#11
capitalone.com 63 users
-
#12
ups.com 63 users
-
#13
cisco.com 59 users
-
#14
nike.com 58 users
-
#15
adp.com 55 users
-
#16
microsoft.com 49 users
-
#17
fedex.com 47 users
-
#18
bestbuy.com 44 users
-
#19
bankofamerica.com 41 users
-
#20
wellsfargo.com 41 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 8,594hits
- #2 sso 2,642hits
- #3 adfs 680hits
- #4 webmail 609hits
- #5 zoom 562hits
- #6 github 364hits
- #7 owa 293hits
- #8 oracle 225hits
- #9 sap 218hits
- #10 zendesk 164hits
- #11 ftp 155hits
- #12 sts 152hits
- #13 extranet 112hits
- #14 kaspersky 107hits
- #15 imap 101hits
- #16 zimbra 101hits
- #17 cpanel 95hits
- #18 vpn 94hits
- #19 ping 92hits
- #20 citrix 77hits
- #21 webex 62hits
- #22 st 61hits
- #23 dana-na 50hits
- #24 roundcube 49hits
- #25 rlogin 44hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains