Infostealers Weekly Report: 2021-01-04 – 2021-01-10
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,703
- #2 Indonesia 1,808
- #3 Pakistan 1,121
- #4 Brazil 736
- #5 Philippines 540
- #6 United States of America 514
- #7 Turkey 508
- #8 Egypt 433
- #9 Vietnam 393
- #10 Finland 391
- #11 Thailand 347
- #12 Bangladesh 301
- #13 Germany 267
- #14 Italy 257
- #15 Mexico 254
- #16 Sri Lanka 226
- #17 Netherlands 223
- #18 Algeria 217
- #19 Malaysia 216
- #20 Argentina 199
- #21 France 196
- #22 Romania 173
- #23 Spain 172
- #24 Poland 164
- #25 South Africa 154
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 13,953 users
-
#2
facebook.com 10,135 users
-
#3
live.com 7,817 users
-
#4
|_) 5,744 users
-
#5
___| 5,744 users
-
#6
\ 5,744 users
-
#7
_ 5,744 users
-
#8
instagram.com 4,132 users
-
#9
twitter.com 4,007 users
-
#10
3,539 users
-
#11
netflix.com 3,459 users
-
#12
discord.com 3,299 users
-
#13
com.facebook.katana 3,160 users
-
#14
amazon.com 3,088 users
-
#15
roblox.com 3,085 users
-
#16
mega.nz 3,047 users
-
#17
paypal.com 2,992 users
-
#18
twitch.tv 2,636 users
-
#19
steampowered.com 2,532 users
-
#20
epicgames.com 2,514 users
-
#21
riotgames.com 2,286 users
-
#22
yahoo.com 2,140 users
-
#23
steamcommunity.com 2,067 users
-
#24
apple.com 2,045 users
-
#25
linkedin.com 1,983 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 78 employees
-
#2
icicibank.com 75 employees
-
#3
tim.it 30 employees
-
#4
onlinesbi.com 30 employees
-
#5
digimail.in 29 employees
-
#6
interia.pl 28 employees
-
#7
o2.pl 28 employees
-
#8
28 employees
-
#9
accenture.com 25 employees
-
#10
pec.it 23 employees
-
#11
freemail.hu 22 employees
-
#12
aruba.it 21 employees
-
#13
aiou.edu.pk 19 employees
-
#14
abv.bg 19 employees
-
#15
netpnb.com 18 employees
-
#16
skole.hr 18 employees
-
#17
unionbankonline.co.in 16 employees
-
#18
http://localhost/wordpress/wp-admin/install.php 16 employees
-
#19
yandex.com.tr 16 employees
-
#20
sp.gov.br 15 employees
-
#21
mail.gov.in 14 employees
-
#22
secureserver.net 14 employees
-
#23
ovh.net 13 employees
-
#24
microsoft.com 13 employees
-
#25
yahoosmallbusiness.com 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 13 employees
-
#2
rockwellautomation.com 7 employees
-
#3
cognizant.com 5 employees
-
#4
publix.com 3 employees
-
#5
halliburton.com 3 employees
-
#6
allstate.com 2 employees
-
#7
fedex.com 2 employees
-
#8
amazon.com 2 employees
-
#9
pg.com 1 employees
-
#10
csc.com 1 employees
-
#11
verizon.com 1 employees
-
#12
staples.com 1 employees
-
#13
entergy.com 1 employees
-
#14
google.com 1 employees
-
#15
ups.com 1 employees
-
#16
ford.com 1 employees
-
#17
hp.com 1 employees
-
#18
starwoodhotels.com 1 employees
-
#19
cummins.com 1 employees
-
#20
conocophillips.com 1 employees
Compromised users
-
#1
google.com 13,952 users
-
#2
facebook.com 10,134 users
-
#3
netflix.com 3,459 users
-
#4
amazon.com 3,088 users
-
#5
paypal.com 2,992 users
-
#6
apple.com 2,045 users
-
#7
ebay.com 621 users
-
#8
oracle.com 329 users
-
#9
cisco.com 208 users
-
#10
hp.com 187 users
-
#11
microsoft.com 176 users
-
#12
nike.com 140 users
-
#13
intel.com 140 users
-
#14
walmart.com 127 users
-
#15
ibm.com 91 users
-
#16
westernunion.com 76 users
-
#17
ups.com 74 users
-
#18
bestbuy.com 63 users
-
#19
adp.com 56 users
-
#20
att.com 52 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 27,661hits
- #2 sso 8,714hits
- #3 zoom 3,105hits
- #4 webmail 1,615hits
- #5 github 1,426hits
- #6 adfs 1,404hits
- #7 oracle 700hits
- #8 sap 554hits
- #9 zendesk 507hits
- #10 sts 449hits
- #11 cpanel 443hits
- #12 owa 431hits
- #13 ftp 414hits
- #14 webex 394hits
- #15 vpn 326hits
- #16 st 294hits
- #17 kaspersky 247hits
- #18 ping 246hits
- #19 extranet 199hits
- #20 salesforce 168hits
- #21 roundcube 129hits
- #22 okta 80hits
- #23 gitlab 76hits
- #24 twilio 70hits
- #25 rlogin 67hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains