Infostealers Weekly Report: 2020-10-19 – 2020-10-25
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 566
- #2 Brazil 340
- #3 Indonesia 289
- #4 Turkey 286
- #5 Philippines 205
- #6 Egypt 205
- #7 Pakistan 189
- #8 Vietnam 144
- #9 Mexico 134
- #10 Thailand 116
- #11 Poland 107
- #12 Argentina 90
- #13 Colombia 84
- #14 Romania 78
- #15 Algeria 78
- #16 Spain 75
- #17 Bangladesh 72
- #18 United States of America 65
- #19 Portugal 64
- #20 Malaysia 64
- #21 United Kingdom 60
- #22 Hungary 60
- #23 Morocco 60
- #24 Serbia 58
- #25 Russia 57
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,637 users
-
#2
facebook.com 3,324 users
-
#3
live.com 2,878 users
-
#4
netflix.com 1,519 users
-
#5
amazon.com 1,405 users
-
#6
twitter.com 1,402 users
-
#7
paypal.com 1,391 users
-
#8
instagram.com 1,092 users
-
#9
yahoo.com 983 users
-
#10
linkedin.com 965 users
-
#11
mega.nz 938 users
-
#12
apple.com 932 users
-
#13
com.facebook.katana 914 users
-
#14
steampowered.com 883 users
-
#15
twitch.tv 857 users
-
#16
discordapp.com 799 users
-
#17
793 users
-
#18
epicgames.com 784 users
-
#19
steamcommunity.com 762 users
-
#20
dropbox.com 758 users
-
#21
roblox.com 709 users
-
#22
spotify.com 686 users
-
#23
com.netflix.mediaclient 680 users
-
#24
microsoftonline.com 651 users
-
#25
com.spotify.music 644 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
confused.com 27 employees
-
#2
rediff.com 22 employees
-
#3
20 employees
-
#4
interia.pl 17 employees
-
#5
o2.pl 16 employees
-
#6
icicibank.com 15 employees
-
#7
freemail.hu 15 employees
-
#8
rmunify.com 11 employees
-
#9
accenture.com 10 employees
-
#10
telecom.pt 9 employees
-
#11
one.com 9 employees
-
#12
secureserver.net 8 employees
-
#13
publix.com 8 employees
-
#14
jwpub.org 7 employees
-
#15
ovh.net 7 employees
-
#16
isacombank.com.vn 6 employees
-
#17
deped.gov.ph 6 employees
-
#18
ionos.com 6 employees
-
#19
telus.net 6 employees
-
#20
onet.pl 6 employees
-
#21
iinet.net.au 6 employees
-
#22
hostgator.com 6 employees
-
#23
spectrum.net 5 employees
-
#24
bigpond.com 5 employees
-
#25
sgcpanel.com 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 8 employees
-
#2
microsoft.com 5 employees
-
#3
bestbuy.com 3 employees
-
#4
hp.com 3 employees
-
#5
twc.com 3 employees
-
#6
att.com 3 employees
-
#7
rockwellautomation.com 2 employees
-
#8
group1auto.com 1 employees
-
#9
facebook.com 1 employees
-
#10
costco.com 1 employees
-
#11
csc.com 1 employees
-
#12
citigroup.com 1 employees
-
#13
fedex.com 1 employees
-
#14
ups.com 1 employees
-
#15
frontier.com 1 employees
-
#16
oracle.com 1 employees
-
#17
wyndhamworldwide.com 1 employees
-
#18
cisco.com 1 employees
-
#19
netflix.com 1 employees
-
#20
spglobal.com 1 employees
Compromised users
-
#1
google.com 4,637 users
-
#2
facebook.com 3,324 users
-
#3
netflix.com 1,518 users
-
#4
amazon.com 1,405 users
-
#5
paypal.com 1,391 users
-
#6
apple.com 932 users
-
#7
ebay.com 571 users
-
#8
walmart.com 176 users
-
#9
ups.com 154 users
-
#10
oracle.com 146 users
-
#11
adp.com 130 users
-
#12
capitalone.com 120 users
-
#13
bestbuy.com 119 users
-
#14
att.com 112 users
-
#15
hp.com 111 users
-
#16
fedex.com 95 users
-
#17
wellsfargo.com 93 users
-
#18
target.com 85 users
-
#19
nike.com 83 users
-
#20
americanexpress.com 74 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 12,632hits
- #2 sso 4,234hits
- #3 webmail 1,241hits
- #4 adfs 1,108hits
- #5 zoom 732hits
- #6 salesforce 535hits
- #7 github 517hits
- #8 oracle 396hits
- #9 owa 395hits
- #10 sts 324hits
- #11 ftp 263hits
- #12 zendesk 262hits
- #13 sap 243hits
- #14 ping 200hits
- #15 vpn 185hits
- #16 imap 164hits
- #17 cpanel 161hits
- #18 kaspersky 142hits
- #19 extranet 123hits
- #20 st 122hits
- #21 webex 86hits
- #22 okta 59hits
- #23 roundcube 54hits
- #24 jira 51hits
- #25 dana-na 51hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains