Infostealers Weekly Report: 2020-12-28 – 2021-01-03
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,594
- #2 United States of America 977
- #3 Russia 731
- #4 Indonesia 704
- #5 Brazil 630
- #6 Finland 553
- #7 Egypt 435
- #8 Germany 417
- #9 Turkey 403
- #10 Philippines 369
- #11 Thailand 329
- #12 Pakistan 326
- #13 Poland 295
- #14 Spain 262
- #15 Argentina 252
- #16 France 251
- #17 United Kingdom 224
- #18 Italy 222
- #19 Vietnam 214
- #20 Bangladesh 204
- #21 Mexico 168
- #22 Algeria 165
- #23 Romania 158
- #24 Malaysia 148
- #25 Peru 125
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 12,147 users
-
#2
___| 10,020 users
-
#3
\ 10,020 users
-
#4
|_) 10,020 users
-
#5
_ 10,020 users
-
#6
facebook.com 8,624 users
-
#7
live.com 8,004 users
-
#8
discord.com 4,656 users
-
#9
twitter.com 4,568 users
-
#10
twitch.tv 4,408 users
-
#11
netflix.com 4,131 users
-
#12
roblox.com 4,044 users
-
#13
paypal.com 4,007 users
-
#14
instagram.com 4,007 users
-
#15
epicgames.com 3,871 users
-
#16
amazon.com 3,868 users
-
#17
steampowered.com 3,611 users
-
#18
3,527 users
-
#19
steamcommunity.com 3,484 users
-
#20
riotgames.com 3,259 users
-
#21
mega.nz 2,868 users
-
#22
com.facebook.katana 2,657 users
-
#23
rockstargames.com 2,576 users
-
#24
spotify.com 2,490 users
-
#25
minecraft.net 2,428 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 51 employees
-
#2
39 employees
-
#3
icicibank.com 36 employees
-
#4
interia.pl 30 employees
-
#5
o2.pl 27 employees
-
#6
onet.pl 24 employees
-
#7
aruba.it 23 employees
-
#8
rmunify.com 23 employees
-
#9
freemail.hu 22 employees
-
#10
pec.it 22 employees
-
#11
confused.com 22 employees
-
#12
abv.bg 21 employees
-
#13
hostgator.com 18 employees
-
#14
publix.com 17 employees
-
#15
skole.hr 17 employees
-
#16
accenture.com 17 employees
-
#17
browardschools.com 16 employees
-
#18
tim.it 16 employees
-
#19
zsthost.com 15 employees
-
#20
moe.gov.ae 15 employees
-
#21
vic.edu.au 13 employees
-
#22
onlinesbi.com 13 employees
-
#23
sapo.pt 13 employees
-
#24
netpnb.com 12 employees
-
#25
yandex.com.tr 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 17 employees
-
#2
microsoft.com 6 employees
-
#3
ups.com 4 employees
-
#4
twc.com 4 employees
-
#5
rockwellautomation.com 3 employees
-
#6
frontier.com 2 employees
-
#7
amazon.com 2 employees
-
#8
paypal.com 2 employees
-
#9
netflix.com 2 employees
-
#10
hp.com 2 employees
-
#11
verizon.com 2 employees
-
#12
sandisk.com 1 employees
-
#13
interpublic.com 1 employees
-
#14
johnsoncontrols.com 1 employees
-
#15
salesforce.com 1 employees
-
#16
bankofamerica.com 1 employees
-
#17
pepsico.com 1 employees
-
#18
libertymutual.com 1 employees
-
#19
aetna.com 1 employees
-
#20
aa.com 1 employees
Compromised users
-
#1
google.com 12,147 users
-
#2
facebook.com 8,624 users
-
#3
netflix.com 4,131 users
-
#4
paypal.com 4,007 users
-
#5
amazon.com 3,868 users
-
#6
apple.com 2,203 users
-
#7
ebay.com 933 users
-
#8
walmart.com 382 users
-
#9
oracle.com 307 users
-
#10
intel.com 256 users
-
#11
ups.com 254 users
-
#12
bestbuy.com 230 users
-
#13
nike.com 214 users
-
#14
hp.com 192 users
-
#15
cisco.com 178 users
-
#16
capitalone.com 178 users
-
#17
target.com 175 users
-
#18
att.com 165 users
-
#19
adp.com 161 users
-
#20
fedex.com 157 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 37,299hits
- #2 sso 9,791hits
- #3 zoom 2,930hits
- #4 adfs 2,242hits
- #5 webmail 1,636hits
- #6 github 1,513hits
- #7 owa 738hits
- #8 oracle 737hits
- #9 zendesk 661hits
- #10 sts 562hits
- #11 cpanel 462hits
- #12 ftp 461hits
- #13 vpn 439hits
- #14 sap 386hits
- #15 webex 376hits
- #16 ping 357hits
- #17 st 290hits
- #18 kaspersky 218hits
- #19 extranet 171hits
- #20 imap 159hits
- #21 salesforce 138hits
- #22 okta 131hits
- #23 roundcube 130hits
- #24 zimbra 115hits
- #25 twilio 94hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains