Infostealers Weekly Report: 2020-11-02 – 2020-11-08
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 3,443
- #2 United States of America 2,362
- #3 Indonesia 1,646
- #4 Pakistan 1,194
- #5 Brazil 861
- #6 Philippines 683
- #7 Spain 683
- #8 Germany 529
- #9 Turkey 527
- #10 France 460
- #11 Thailand 426
- #12 Mexico 393
- #13 Bangladesh 380
- #14 Italy 347
- #15 Malaysia 324
- #16 Poland 323
- #17 Canada 296
- #18 Argentina 292
- #19 United Kingdom 278
- #20 Sri Lanka 271
- #21 Romania 245
- #22 Portugal 235
- #23 Egypt 215
- #24 South Korea 200
- #25 Colombia 198
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 16,989 users
-
#2
facebook.com 12,193 users
-
#3
live.com 9,699 users
-
#4
twitter.com 4,739 users
-
#5
amazon.com 4,589 users
-
#6
netflix.com 4,522 users
-
#7
instagram.com 4,124 users
-
#8
paypal.com 4,111 users
-
#9
mega.nz 3,613 users
-
#10
roblox.com 3,421 users
-
#11
com.facebook.katana 3,265 users
-
#12
twitch.tv 3,189 users
-
#13
epicgames.com 3,110 users
-
#14
steampowered.com 3,038 users
-
#15
2,884 users
-
#16
yahoo.com 2,860 users
-
#17
discord.com 2,695 users
-
#18
discordapp.com 2,634 users
-
#19
steamcommunity.com 2,609 users
-
#20
linkedin.com 2,599 users
-
#21
minecraft.net 2,555 users
-
#22
apple.com 2,512 users
-
#23
microsoftonline.com 2,277 users
-
#24
riotgames.com 2,210 users
-
#25
com.netflix.mediaclient 2,088 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 89 employees
-
#2
icicibank.com 77 employees
-
#3
telecom.pt 46 employees
-
#4
o2.pl 45 employees
-
#5
42 employees
-
#6
secureserver.net 39 employees
-
#7
digimail.in 38 employees
-
#8
abv.bg 34 employees
-
#9
accenture.com 34 employees
-
#10
publix.com 31 employees
-
#11
sapo.pt 28 employees
-
#12
pec.it 28 employees
-
#13
tim.it 27 employees
-
#14
freemail.hu 26 employees
-
#15
http://localhost/wordpress/wp-admin/install.php 26 employees
-
#16
netpnb.com 26 employees
-
#17
interia.pl 25 employees
-
#18
onlinesbi.com 22 employees
-
#19
onet.pl 22 employees
-
#20
aruba.it 18 employees
-
#21
ovh.net 17 employees
-
#22
confused.com 17 employees
-
#23
bni.co.id 17 employees
-
#24
aiou.edu.pk 16 employees
-
#25
one.com 16 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 31 employees
-
#2
microsoft.com 12 employees
-
#3
cognizant.com 11 employees
-
#4
rockwellautomation.com 10 employees
-
#5
twc.com 9 employees
-
#6
frontier.com 5 employees
-
#7
amazon.com 4 employees
-
#8
oracle.com 3 employees
-
#9
netflix.com 3 employees
-
#10
ups.com 3 employees
-
#11
google.com 2 employees
-
#12
aa.com 2 employees
-
#13
disney.com 2 employees
-
#14
ibm.com 2 employees
-
#15
hp.com 1 employees
-
#16
ppg.com 1 employees
-
#17
rockwellcollins.com 1 employees
-
#18
gm.com 1 employees
-
#19
iheartmedia.com 1 employees
-
#20
conocophillips.com 1 employees
Compromised users
-
#1
google.com 16,986 users
-
#2
facebook.com 12,189 users
-
#3
amazon.com 4,589 users
-
#4
netflix.com 4,521 users
-
#5
paypal.com 4,111 users
-
#6
apple.com 2,511 users
-
#7
ebay.com 1,317 users
-
#8
walmart.com 470 users
-
#9
oracle.com 408 users
-
#10
ups.com 287 users
-
#11
hp.com 277 users
-
#12
att.com 275 users
-
#13
capitalone.com 273 users
-
#14
adp.com 247 users
-
#15
bestbuy.com 241 users
-
#16
cisco.com 240 users
-
#17
target.com 208 users
-
#18
fedex.com 198 users
-
#19
wellsfargo.com 189 users
-
#20
microsoft.com 186 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 34,523hits
- #2 sso 11,546hits
- #3 zoom 3,286hits
- #4 adfs 2,538hits
- #5 webmail 2,318hits
- #6 github 1,721hits
- #7 owa 999hits
- #8 oracle 972hits
- #9 sts 790hits
- #10 sap 747hits
- #11 zendesk 679hits
- #12 cpanel 619hits
- #13 ftp 542hits
- #14 vpn 520hits
- #15 ping 517hits
- #16 webex 492hits
- #17 extranet 363hits
- #18 kaspersky 346hits
- #19 st 279hits
- #20 salesforce 226hits
- #21 imap 218hits
- #22 okta 163hits
- #23 roundcube 155hits
- #24 jira 150hits
- #25 gitlab 143hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains