Infostealers Weekly Report: 2020-09-21 – 2020-09-27
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 2,293
- #2 India 795
- #3 Spain 718
- #4 Indonesia 478
- #5 Germany 439
- #6 France 426
- #7 United Kingdom 379
- #8 Brazil 362
- #9 Israel 362
- #10 Canada 320
- #11 Pakistan 264
- #12 Turkey 242
- #13 Philippines 239
- #14 Australia 220
- #15 Thailand 177
- #16 Egypt 158
- #17 Vietnam 152
- #18 Belgium 142
- #19 Sweden 131
- #20 Japan 130
- #21 Mexico 128
- #22 Bangladesh 111
- #23 Argentina 100
- #24 Colombia 77
- #25 Algeria 75
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 9,323 users
-
#2
facebook.com 5,917 users
-
#3
live.com 5,306 users
-
#4
amazon.com 2,848 users
-
#5
netflix.com 2,819 users
-
#6
twitter.com 2,789 users
-
#7
paypal.com 2,774 users
-
#8
roblox.com 2,536 users
-
#9
twitch.tv 2,455 users
-
#10
instagram.com 2,380 users
-
#11
epicgames.com 2,261 users
-
#12
discord.com 2,066 users
-
#13
steampowered.com 2,005 users
-
#14
minecraft.net 1,912 users
-
#15
steamcommunity.com 1,888 users
-
#16
discordapp.com 1,832 users
-
#17
mega.nz 1,626 users
-
#18
apple.com 1,623 users
-
#19
spotify.com 1,594 users
-
#20
yahoo.com 1,542 users
-
#21
riotgames.com 1,469 users
-
#22
com.facebook.katana 1,409 users
-
#23
com.spotify.music 1,352 users
-
#24
sonyentertainmentnetwork.com 1,229 users
-
#25
linkedin.com 1,224 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 35 employees
-
#2
confused.com 31 employees
-
#3
k12.fl.us 26 employees
-
#4
maccabi4u.co.il 25 employees
-
#5
18 employees
-
#6
rediff.com 18 employees
-
#7
dadeschools.net 17 employees
-
#8
vic.edu.au 15 employees
-
#9
rmunify.com 15 employees
-
#10
one.com 15 employees
-
#11
ovh.net 12 employees
-
#12
freenet.de 12 employees
-
#13
1and1.es 11 employees
-
#14
secureserver.net 11 employees
-
#15
interia.pl 10 employees
-
#16
duvalschools.org 10 employees
-
#17
http://localhost/wordpress/wp-admin/install.php 10 employees
-
#18
pdsb.org 10 employees
-
#19
hostgator.com 10 employees
-
#20
yahoosmallbusiness.com 9 employees
-
#21
icicibank.com 9 employees
-
#22
mail.de 9 employees
-
#23
senecacollege.ca 9 employees
-
#24
iinet.net.au 9 employees
-
#25
digimail.in 9 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 35 employees
-
#2
twc.com 5 employees
-
#3
att.com 5 employees
-
#4
microsoft.com 4 employees
-
#5
oracle.com 3 employees
-
#6
hp.com 3 employees
-
#7
bestbuy.com 3 employees
-
#8
cognizant.com 2 employees
-
#9
netflix.com 2 employees
-
#10
cbre.com 2 employees
-
#11
chs.net 2 employees
-
#12
bnymellon.com 2 employees
-
#13
johnsoncontrols.com 2 employees
-
#14
costco.com 1 employees
-
#15
allstate.com 1 employees
-
#16
emc.com 1 employees
-
#17
cablevision.com 1 employees
-
#18
xerox.com 1 employees
-
#19
ibm.com 1 employees
-
#20
frontier.com 1 employees
Compromised users
-
#1
google.com 9,317 users
-
#2
facebook.com 5,914 users
-
#3
amazon.com 2,845 users
-
#4
netflix.com 2,819 users
-
#5
paypal.com 2,772 users
-
#6
apple.com 1,622 users
-
#7
ebay.com 956 users
-
#8
walmart.com 443 users
-
#9
ups.com 279 users
-
#10
capitalone.com 260 users
-
#11
att.com 243 users
-
#12
target.com 225 users
-
#13
bestbuy.com 224 users
-
#14
adp.com 192 users
-
#15
wellsfargo.com 185 users
-
#16
oracle.com 183 users
-
#17
fedex.com 182 users
-
#18
nike.com 176 users
-
#19
bankofamerica.com 175 users
-
#20
americanexpress.com 149 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 24,079hits
- #2 sso 7,650hits
- #3 adfs 2,177hits
- #4 zoom 1,591hits
- #5 webmail 1,304hits
- #6 github 882hits
- #7 zendesk 540hits
- #8 owa 538hits
- #9 oracle 447hits
- #10 sts 444hits
- #11 sap 418hits
- #12 ftp 376hits
- #13 cpanel 310hits
- #14 ping 308hits
- #15 vpn 303hits
- #16 imap 301hits
- #17 st 211hits
- #18 extranet 188hits
- #19 salesforce 176hits
- #20 webex 174hits
- #21 kaspersky 174hits
- #22 dana-na 153hits
- #23 okta 116hits
- #24 citrix 94hits
- #25 zimbra 77hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains