Infostealers Weekly Report: 2020-12-21 – 2020-12-27
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 17,669
- #2 Indonesia 8,842
- #3 Pakistan 5,390
- #4 Turkey 5,073
- #5 Brazil 4,449
- #6 Philippines 2,596
- #7 Egypt 2,504
- #8 Vietnam 2,050
- #9 Thailand 1,613
- #10 Bangladesh 1,412
- #11 Mexico 1,297
- #12 Algeria 1,246
- #13 Sri Lanka 1,215
- #14 Morocco 1,198
- #15 Poland 1,145
- #16 Malaysia 1,138
- #17 Romania 1,118
- #18 Italy 1,036
- #19 South Korea 980
- #20 Germany 940
- #21 Argentina 912
- #22 Colombia 806
- #23 Spain 778
- #24 United States of America 767
- #25 France 763
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 58,942 users
-
#2
facebook.com 43,052 users
-
#3
live.com 30,823 users
-
#4
twitter.com 14,691 users
-
#5
instagram.com 14,552 users
-
#6
netflix.com 12,736 users
-
#7
com.facebook.katana 12,667 users
-
#8
amazon.com 11,382 users
-
#9
mega.nz 11,299 users
-
#10
paypal.com 10,276 users
-
#11
9,889 users
-
#12
discord.com 9,181 users
-
#13
yahoo.com 8,771 users
-
#14
roblox.com 8,387 users
-
#15
steampowered.com 8,358 users
-
#16
linkedin.com 8,154 users
-
#17
epicgames.com 7,437 users
-
#18
microsoftonline.com 7,238 users
-
#19
apple.com 7,127 users
-
#20
twitch.tv 7,096 users
-
#21
riotgames.com 6,881 users
-
#22
com.netflix.mediaclient 6,383 users
-
#23
com.instagram.android 6,282 users
-
#24
steamcommunity.com 6,239 users
-
#25
com.spotify.music 6,157 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 359 employees
-
#2
rediff.com 343 employees
-
#3
digimail.in 148 employees
-
#4
freemail.hu 126 employees
-
#5
interia.pl 120 employees
-
#6
119 employees
-
#7
accenture.com 118 employees
-
#8
netpnb.com 106 employees
-
#9
onlinesbi.com 97 employees
-
#10
pec.it 94 employees
-
#11
tim.it 91 employees
-
#12
o2.pl 89 employees
-
#13
secureserver.net 83 employees
-
#14
aiou.edu.pk 78 employees
-
#15
aruba.it 73 employees
-
#16
abv.bg 73 employees
-
#17
telecom.pt 63 employees
-
#18
skole.hr 61 employees
-
#19
http://localhost/wordpress/wp-admin/install.php 60 employees
-
#20
indusind.com 59 employees
-
#21
yahoosmallbusiness.com 59 employees
-
#22
onet.pl 58 employees
-
#23
bluehost.com 55 employees
-
#24
yandex.com.tr 53 employees
-
#25
bni.co.id 50 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 27 employees
-
#2
rockwellautomation.com 23 employees
-
#3
cognizant.com 21 employees
-
#4
publix.com 10 employees
-
#5
google.com 9 employees
-
#6
hp.com 9 employees
-
#7
netflix.com 8 employees
-
#8
amazon.com 7 employees
-
#9
ibm.com 7 employees
-
#10
csc.com 7 employees
-
#11
paypal.com 6 employees
-
#12
honeywell.com 4 employees
-
#13
salesforce.com 4 employees
-
#14
ford.com 3 employees
-
#15
emc.com 3 employees
-
#16
halliburton.com 3 employees
-
#17
dupont.com 3 employees
-
#18
frontier.com 3 employees
-
#19
cablevision.com 3 employees
-
#20
ups.com 3 employees
Compromised users
-
#1
google.com 58,937 users
-
#2
facebook.com 43,046 users
-
#3
netflix.com 12,735 users
-
#4
amazon.com 11,382 users
-
#5
paypal.com 10,275 users
-
#6
apple.com 7,127 users
-
#7
ebay.com 2,438 users
-
#8
oracle.com 1,377 users
-
#9
cisco.com 782 users
-
#10
hp.com 736 users
-
#11
microsoft.com 571 users
-
#12
nike.com 413 users
-
#13
intel.com 369 users
-
#14
ibm.com 364 users
-
#15
ups.com 307 users
-
#16
walmart.com 301 users
-
#17
westernunion.com 248 users
-
#18
salesforce.com 160 users
-
#19
fedex.com 157 users
-
#20
adp.com 140 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 93,629hits
- #2 sso 32,706hits
- #3 zoom 11,188hits
- #4 webmail 7,492hits
- #5 github 4,896hits
- #6 adfs 4,276hits
- #7 oracle 3,032hits
- #8 owa 2,368hits
- #9 sap 2,352hits
- #10 sts 2,043hits
- #11 cpanel 2,010hits
- #12 webex 1,915hits
- #13 zendesk 1,864hits
- #14 ftp 1,764hits
- #15 vpn 1,445hits
- #16 st 1,170hits
- #17 kaspersky 1,045hits
- #18 ping 939hits
- #19 extranet 856hits
- #20 salesforce 855hits
- #21 roundcube 640hits
- #22 okta 314hits
- #23 gitlab 314hits
- #24 jira 293hits
- #25 zimbra 285hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains