Infostealers Weekly Report: 2020-10-12 – 2020-10-18
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 289
- #2 Turkey 245
- #3 Indonesia 201
- #4 Brazil 188
- #5 United States of America 147
- #6 Egypt 117
- #7 Vietnam 114
- #8 Pakistan 95
- #9 Thailand 72
- #10 Russia 69
- #11 Algeria 66
- #12 Spain 63
- #13 Philippines 62
- #14 Romania 57
- #15 Argentina 50
- #16 Morocco 49
- #17 Italy 45
- #18 France 43
- #19 Serbia 37
- #20 Peru 36
- #21 Mexico 36
- #22 Germany 35
- #23 Poland 34
- #24 Malaysia 31
- #25 Colombia 30
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,152 users
-
#2
facebook.com 1,609 users
-
#3
live.com 1,122 users
-
#4
twitter.com 566 users
-
#5
netflix.com 514 users
-
#6
amazon.com 493 users
-
#7
instagram.com 485 users
-
#8
paypal.com 451 users
-
#9
mega.nz 436 users
-
#10
roblox.com 434 users
-
#11
epicgames.com 379 users
-
#12
com.facebook.katana 378 users
-
#13
linkedin.com 372 users
-
#14
yahoo.com 365 users
-
#15
twitch.tv 351 users
-
#16
steampowered.com 340 users
-
#17
discordapp.com 325 users
-
#18
apple.com 270 users
-
#19
minecraft.net 265 users
-
#20
263 users
-
#21
steamcommunity.com 259 users
-
#22
discord.com 255 users
-
#23
dropbox.com 235 users
-
#24
com.netflix.mediaclient 231 users
-
#25
spotify.com 230 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 12 employees
-
#2
yandex.com.tr 7 employees
-
#3
pec.it 7 employees
-
#4
tim.it 7 employees
-
#5
aruba.it 7 employees
-
#6
telecom.pt 6 employees
-
#7
secureserver.net 6 employees
-
#8
6 employees
-
#9
icicibank.com 6 employees
-
#10
sp.gov.br 5 employees
-
#11
o2.pl 4 employees
-
#12
accenture.com 4 employees
-
#13
abv.bg 3 employees
-
#14
ovh.net 3 employees
-
#15
confused.com 3 employees
-
#16
maccabi4u.co.il 3 employees
-
#17
hostinger.com 3 employees
-
#18
onlinesbi.com 2 employees
-
#19
mc3.edu 2 employees
-
#20
solv.ads 2 employees
-
#21
xsolla.com 2 employees
-
#22
interia.pl 2 employees
-
#23
sonatrach.dz 2 employees
-
#24
ipleiria.pt 2 employees
-
#25
swinerton.com 2 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 2 employees
-
#2
eastman.com 1 employees
-
#3
oxy.com 1 employees
-
#4
rockwellautomation.com 1 employees
-
#5
jacobs.com 1 employees
-
#6
honeywell.com 1 employees
-
#7
google.com 1 employees
-
#8
cognizant.com 1 employees
-
#9
interpublic.com 1 employees
-
#10
broadcom.com 1 employees
Compromised users
-
#1
google.com 2,151 users
-
#2
facebook.com 1,608 users
-
#3
netflix.com 513 users
-
#4
amazon.com 493 users
-
#5
paypal.com 451 users
-
#6
apple.com 270 users
-
#7
ebay.com 157 users
-
#8
oracle.com 40 users
-
#9
walmart.com 40 users
-
#10
hp.com 30 users
-
#11
ups.com 24 users
-
#12
capitalone.com 23 users
-
#13
microsoft.com 23 users
-
#14
target.com 22 users
-
#15
adp.com 22 users
-
#16
wellsfargo.com 21 users
-
#17
fedex.com 20 users
-
#18
nike.com 19 users
-
#19
bestbuy.com 19 users
-
#20
att.com 18 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,699hits
- #2 sso 1,211hits
- #3 webmail 400hits
- #4 zoom 257hits
- #5 adfs 181hits
- #6 github 162hits
- #7 sap 135hits
- #8 zendesk 92hits
- #9 st 86hits
- #10 owa 82hits
- #11 ftp 79hits
- #12 oracle 72hits
- #13 sts 66hits
- #14 cpanel 62hits
- #15 ping 55hits
- #16 extranet 37hits
- #17 vpn 30hits
- #18 gitlab 28hits
- #19 webex 28hits
- #20 kaspersky 24hits
- #21 okta 23hits
- #22 salesforce 22hits
- #23 jira 21hits
- #24 imap 20hits
- #25 roundcube 19hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains