Infostealers Weekly Report: 2019-03-04 – 2019-03-10
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 648
- #2 Brazil 518
- #3 Indonesia 454
- #4 Vietnam 366
- #5 Germany 291
- #6 Canada 169
- #7 United Kingdom 168
- #8 Algeria 147
- #9 Russia 139
- #10 Pakistan 130
- #11 Thailand 117
- #12 Poland 111
- #13 Bangladesh 103
- #14 Philippines 92
- #15 Egypt 90
- #16 Colombia 88
- #17 Malaysia 84
- #18 Romania 84
- #19 Argentina 75
- #20 United States of America 74
- #21 Australia 72
- #22 Morocco 70
- #23 Serbia 63
- #24 Mexico 61
- #25 Hungary 59
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,278 users
-
#2
facebook.com 2,793 users
-
#3
live.com 1,563 users
-
#4
twitter.com 795 users
-
#5
paypal.com 654 users
-
#6
yahoo.com 628 users
-
#7
netflix.com 623 users
-
#8
605 users
-
#9
discordapp.com 539 users
-
#10
instagram.com 526 users
-
#11
mega.nz 523 users
-
#12
roblox.com 521 users
-
#13
steampowered.com 499 users
-
#14
epicgames.com 467 users
-
#15
amazon.com 454 users
-
#16
linkedin.com 441 users
-
#17
steamcommunity.com 417 users
-
#18
twitch.tv 408 users
-
#19
192.168.1.1 387 users
-
#20
apple.com 383 users
-
#21
dropbox.com 344 users
-
#22
ea.com 298 users
-
#23
com.facebook.katana 285 users
-
#24
chrome://FirefoxAccounts 262 users
-
#25
aliexpress.com 259 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 22 employees
-
#2
rediff.com 20 employees
-
#3
interia.pl 18 employees
-
#4
o2.pl 15 employees
-
#5
ig.com.br 9 employees
-
#6
confused.com 8 employees
-
#7
onet.pl 8 employees
-
#8
icicibank.com 8 employees
-
#9
digimail.in 8 employees
-
#10
freenet.de 8 employees
-
#11
netpnb.com 8 employees
-
#12
onlinesbi.com 8 employees
-
#13
freemail.hu 8 employees
-
#14
secureserver.net 7 employees
-
#15
mail.de 7 employees
-
#16
mail.gov.in 6 employees
-
#17
telecom.pt 5 employees
-
#18
5 employees
-
#19
unionbankonline.co.in 4 employees
-
#20
abv.bg 4 employees
-
#21
accenture.com 4 employees
-
#22
arcor.de 4 employees
-
#23
ocb.com.vn 4 employees
-
#24
sbb.rs 4 employees
-
#25
bluehost.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 2 employees
-
#2
ibm.com 1 employees
-
#3
amazon.com 1 employees
Compromised users
-
#1
google.com 3,278 users
-
#2
facebook.com 2,793 users
-
#3
paypal.com 654 users
-
#4
netflix.com 623 users
-
#5
amazon.com 454 users
-
#6
apple.com 383 users
-
#7
ebay.com 178 users
-
#8
oracle.com 51 users
-
#9
hp.com 28 users
-
#10
capitalone.com 17 users
-
#11
westernunion.com 16 users
-
#12
walmart.com 16 users
-
#13
ups.com 13 users
-
#14
adp.com 13 users
-
#15
microsoft.com 12 users
-
#16
americanexpress.com 11 users
-
#17
cisco.com 9 users
-
#18
nike.com 9 users
-
#19
att.com 8 users
-
#20
ibm.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 4,013hits
- #2 sso 1,551hits
- #3 imap 494hits
- #4 webmail 247hits
- #5 adfs 208hits
- #6 github 151hits
- #7 sap 135hits
- #8 owa 130hits
- #9 ftp 116hits
- #10 oracle 111hits
- #11 cpanel 90hits
- #12 sts 76hits
- #13 extranet 75hits
- #14 zendesk 70hits
- #15 vpn 50hits
- #16 st 46hits
- #17 kaspersky 45hits
- #18 zoom 35hits
- #19 ping 31hits
- #20 rlogin 26hits
- #21 bitbucket 23hits
- #22 citrix 23hits
- #23 salesforce 22hits
- #24 gitlab 16hits
- #25 dana-na 16hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains