Infostealers Weekly Report: 2020-08-31 – 2020-09-06
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,057
- #2 United States of America 1,432
- #3 Indonesia 1,045
- #4 Spain 540
- #5 France 481
- #6 Egypt 316
- #7 Brazil 293
- #8 Germany 213
- #9 Israel 166
- #10 United Kingdom 137
- #11 Canada 124
- #12 Bangladesh 115
- #13 Algeria 114
- #14 Australia 87
- #15 Hungary 85
- #16 Turkey 74
- #17 Greece 67
- #18 Philippines 62
- #19 Ghana 60
- #20 Colombia 59
- #21 Argentina 58
- #22 Chile 55
- #23 Vietnam 41
- #24 Hong Kong SAR China 39
- #25 Belarus 37
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,853 users
-
#2
facebook.com 4,798 users
-
#3
live.com 3,702 users
-
#4
amazon.com 1,988 users
-
#5
twitter.com 1,940 users
-
#6
netflix.com 1,672 users
-
#7
instagram.com 1,665 users
-
#8
paypal.com 1,575 users
-
#9
1,391 users
-
#10
yahoo.com 1,255 users
-
#11
com.facebook.katana 1,246 users
-
#12
mega.nz 1,209 users
-
#13
discordapp.com 1,174 users
-
#14
twitch.tv 1,154 users
-
#15
epicgames.com 1,144 users
-
#16
roblox.com 1,125 users
-
#17
linkedin.com 1,109 users
-
#18
steampowered.com 1,078 users
-
#19
apple.com 1,024 users
-
#20
com.spotify.music 938 users
-
#21
minecraft.net 900 users
-
#22
com.netflix.mediaclient 900 users
-
#23
steamcommunity.com 878 users
-
#24
spotify.com 876 users
-
#25
dropbox.com 799 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 56 employees
-
#2
icicibank.com 41 employees
-
#3
accenture.com 19 employees
-
#4
digimail.in 16 employees
-
#5
16 employees
-
#6
onlinesbi.com 16 employees
-
#7
secureserver.net 16 employees
-
#8
publix.com 15 employees
-
#9
netpnb.com 14 employees
-
#10
ovh.net 13 employees
-
#11
freemail.hu 13 employees
-
#12
confused.com 12 employees
-
#13
maccabi4u.co.il 10 employees
-
#14
dadeschools.net 9 employees
-
#15
nbg.gr 9 employees
-
#16
unionbankonline.co.in 9 employees
-
#17
mail.gov.in 9 employees
-
#18
cognizant.com 8 employees
-
#19
http://localhost/wordpress/wp-admin/install.php 8 employees
-
#20
jcyl.es 8 employees
-
#21
indiapost.gov.in 7 employees
-
#22
1and1.es 7 employees
-
#23
bluehost.com 7 employees
-
#24
hcps.net 7 employees
-
#25
POP3://pop.gmail.com:995 7 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 15 employees
-
#2
cognizant.com 8 employees
-
#3
twc.com 4 employees
-
#4
microsoft.com 3 employees
-
#5
rockwellautomation.com 2 employees
-
#6
chs.net 2 employees
-
#7
google.com 2 employees
-
#8
att.com 1 employees
-
#9
centurylink.com 1 employees
-
#10
charter.com 1 employees
-
#11
halliburton.com 1 employees
-
#12
amazon.com 1 employees
-
#13
lear.com 1 employees
-
#14
genesishcc.com 1 employees
-
#15
nationwide.com 1 employees
-
#16
ups.com 1 employees
-
#17
frontier.com 1 employees
-
#18
apple.com 1 employees
-
#19
oracle.com 1 employees
-
#20
cisco.com 1 employees
Compromised users
-
#1
google.com 6,853 users
-
#2
facebook.com 4,798 users
-
#3
amazon.com 1,988 users
-
#4
netflix.com 1,672 users
-
#5
paypal.com 1,575 users
-
#6
apple.com 1,024 users
-
#7
ebay.com 588 users
-
#8
walmart.com 248 users
-
#9
oracle.com 196 users
-
#10
capitalone.com 159 users
-
#11
ups.com 156 users
-
#12
hp.com 144 users
-
#13
adp.com 133 users
-
#14
att.com 123 users
-
#15
bestbuy.com 122 users
-
#16
target.com 110 users
-
#17
wellsfargo.com 97 users
-
#18
cisco.com 90 users
-
#19
fedex.com 89 users
-
#20
americanexpress.com 88 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 12,935hits
- #2 sso 4,490hits
- #3 adfs 1,009hits
- #4 webmail 914hits
- #5 zoom 832hits
- #6 oracle 646hits
- #7 salesforce 606hits
- #8 github 557hits
- #9 ftp 409hits
- #10 sap 401hits
- #11 owa 383hits
- #12 imap 372hits
- #13 cpanel 283hits
- #14 zendesk 273hits
- #15 sts 251hits
- #16 ping 216hits
- #17 vpn 215hits
- #18 webex 181hits
- #19 st 154hits
- #20 kaspersky 153hits
- #21 extranet 130hits
- #22 zimbra 69hits
- #23 jira 68hits
- #24 gitlab 67hits
- #25 roundcube 66hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains