Infostealers Weekly Report: 2021-01-11 – 2021-01-17
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,966
- #2 Indonesia 2,696
- #3 Pakistan 1,185
- #4 Brazil 1,111
- #5 Egypt 731
- #6 Philippines 701
- #7 Mexico 549
- #8 Turkey 528
- #9 Bangladesh 435
- #10 Thailand 391
- #11 Italy 365
- #12 Germany 339
- #13 Algeria 337
- #14 Malaysia 269
- #15 Poland 269
- #16 Vietnam 264
- #17 France 258
- #18 United States of America 252
- #19 Spain 245
- #20 Romania 242
- #21 Colombia 228
- #22 Sri Lanka 228
- #23 Argentina 225
- #24 Russia 221
- #25 Morocco 204
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 15,316 users
-
#2
facebook.com 11,372 users
-
#3
live.com 8,605 users
-
#4
twitter.com 4,274 users
-
#5
instagram.com 4,117 users
-
#6
netflix.com 3,895 users
-
#7
com.facebook.katana 3,603 users
-
#8
amazon.com 3,350 users
-
#9
paypal.com 3,276 users
-
#10
mega.nz 3,236 users
-
#11
3,148 users
-
#12
discord.com 3,137 users
-
#13
roblox.com 2,965 users
-
#14
steampowered.com 2,622 users
-
#15
twitch.tv 2,437 users
-
#16
yahoo.com 2,420 users
-
#17
epicgames.com 2,360 users
-
#18
2,348 users
-
#19
linkedin.com 2,307 users
-
#20
\ 2,251 users
-
#21
|_) 2,251 users
-
#22
___| 2,251 users
-
#23
_ 2,251 users
-
#24
microsoftonline.com 2,203 users
-
#25
apple.com 2,090 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 73 employees
-
#2
icicibank.com 60 employees
-
#3
44 employees
-
#4
aruba.it 35 employees
-
#5
tim.it 34 employees
-
#6
o2.pl 32 employees
-
#7
interia.pl 30 employees
-
#8
digimail.in 30 employees
-
#9
pec.it 28 employees
-
#10
bluehost.com 28 employees
-
#11
freemail.hu 25 employees
-
#12
abv.bg 24 employees
-
#13
accenture.com 22 employees
-
#14
mail.bg 21 employees
-
#15
http://localhost/wordpress/wp-admin/install.php 20 employees
-
#16
secureserver.net 17 employees
-
#17
yandex.com.tr 16 employees
-
#18
onlinesbi.com 16 employees
-
#19
unionbankonline.co.in 15 employees
-
#20
skole.hr 15 employees
-
#21
onet.pl 14 employees
-
#22
itesm.mx 14 employees
-
#23
one.com 13 employees
-
#24
infocert.it 13 employees
-
#25
netpnb.com 13 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 11 employees
-
#2
publix.com 5 employees
-
#3
netflix.com 4 employees
-
#4
rockwellautomation.com 4 employees
-
#5
amazon.com 3 employees
-
#6
att.com 3 employees
-
#7
cognizant.com 2 employees
-
#8
paypal.com 2 employees
-
#9
twc.com 2 employees
-
#10
pepsico.com 2 employees
-
#11
oracle.com 2 employees
-
#12
uhsinc.com 1 employees
-
#13
marriott.com 1 employees
-
#14
aa.com 1 employees
-
#15
aramark.com 1 employees
-
#16
cummins.com 1 employees
-
#17
ibm.com 1 employees
-
#18
frontier.com 1 employees
-
#19
cigna.com 1 employees
-
#20
ups.com 1 employees
Compromised users
-
#1
google.com 15,316 users
-
#2
facebook.com 11,372 users
-
#3
netflix.com 3,895 users
-
#4
amazon.com 3,350 users
-
#5
paypal.com 3,276 users
-
#6
apple.com 2,090 users
-
#7
ebay.com 897 users
-
#8
oracle.com 382 users
-
#9
hp.com 210 users
-
#10
cisco.com 201 users
-
#11
walmart.com 171 users
-
#12
ups.com 163 users
-
#13
microsoft.com 146 users
-
#14
nike.com 141 users
-
#15
ibm.com 112 users
-
#16
intel.com 111 users
-
#17
bestbuy.com 102 users
-
#18
westernunion.com 98 users
-
#19
adp.com 95 users
-
#20
fedex.com 89 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 31,481hits
- #2 sso 11,078hits
- #3 zoom 3,334hits
- #4 webmail 2,217hits
- #5 github 1,432hits
- #6 adfs 1,427hits
- #7 oracle 897hits
- #8 owa 704hits
- #9 zendesk 697hits
- #10 sap 632hits
- #11 cpanel 579hits
- #12 ftp 543hits
- #13 webex 514hits
- #14 sts 442hits
- #15 vpn 376hits
- #16 st 353hits
- #17 ping 340hits
- #18 kaspersky 321hits
- #19 extranet 285hits
- #20 rlogin 192hits
- #21 salesforce 163hits
- #22 zimbra 149hits
- #23 roundcube 124hits
- #24 okta 82hits
- #25 twilio 78hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains