Infostealers Weekly Report: 2019-03-18 – 2019-03-24
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Germany 385
- #2 France 275
- #3 Brazil 206
- #4 Serbia 197
- #5 Portugal 195
- #6 United Kingdom 188
- #7 Indonesia 168
- #8 Poland 163
- #9 Russia 148
- #10 Canada 138
- #11 United States of America 134
- #12 Romania 99
- #13 India 88
- #14 Australia 74
- #15 Egypt 73
- #16 Pakistan 56
- #17 Hungary 52
- #18 Bosnia & Herzegovina 48
- #19 Bangladesh 43
- #20 Colombia 40
- #21 Czechia 40
- #22 Algeria 39
- #23 Croatia 34
- #24 Mexico 34
- #25 Greece 33
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,268 users
-
#2
facebook.com 1,962 users
-
#3
live.com 1,303 users
-
#4
twitter.com 629 users
-
#5
paypal.com 601 users
-
#6
epicgames.com 565 users
-
#7
netflix.com 534 users
-
#8
discordapp.com 508 users
-
#9
roblox.com 487 users
-
#10
twitch.tv 466 users
-
#11
steamcommunity.com 459 users
-
#12
steampowered.com 459 users
-
#13
instagram.com 448 users
-
#14
yahoo.com 408 users
-
#15
383 users
-
#16
amazon.com 361 users
-
#17
mega.nz 356 users
-
#18
dropbox.com 316 users
-
#19
minecraft.net 308 users
-
#20
sonyentertainmentnetwork.com 297 users
-
#21
ea.com 295 users
-
#22
linkedin.com 293 users
-
#23
apple.com 292 users
-
#24
aliexpress.com 260 users
-
#25
spotify.com 229 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
o2.pl 27 employees
-
#2
freenet.de 16 employees
-
#3
POP3://pop.gmail.com:995 16 employees
-
#4
telecom.pt 15 employees
-
#5
sapo.pt 15 employees
-
#6
onet.pl 14 employees
-
#7
interia.pl 14 employees
-
#8
mail.de 9 employees
-
#9
abv.bg 8 employees
-
#10
7 employees
-
#11
rmunify.com 7 employees
-
#12
freemail.hu 7 employees
-
#13
skole.hr 7 employees
-
#14
epost.de 6 employees
-
#15
secureserver.net 6 employees
-
#16
gmx.at 5 employees
-
#17
mail.bg 5 employees
-
#18
telekom.rs 4 employees
-
#19
strato.com 4 employees
-
#20
idbibank.co.in 4 employees
-
#21
hidemyass.com 4 employees
-
#22
sbb.rs 4 employees
-
#23
nbg.gr 4 employees
-
#24
POP3://pop.gmx.net:995 4 employees
-
#25
lgflmail.net 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 2 employees
-
#2
publix.com 1 employees
-
#3
hp.com 1 employees
-
#4
cognizant.com 1 employees
-
#5
staples.com 1 employees
Compromised users
-
#1
google.com 2,268 users
-
#2
facebook.com 1,962 users
-
#3
paypal.com 601 users
-
#4
netflix.com 534 users
-
#5
amazon.com 361 users
-
#6
apple.com 292 users
-
#7
ebay.com 184 users
-
#8
ups.com 29 users
-
#9
hp.com 27 users
-
#10
nike.com 18 users
-
#11
capitalone.com 17 users
-
#12
walmart.com 16 users
-
#13
westernunion.com 15 users
-
#14
ibm.com 14 users
-
#15
oracle.com 13 users
-
#16
microsoft.com 12 users
-
#17
americanexpress.com 11 users
-
#18
att.com 10 users
-
#19
adp.com 8 users
-
#20
salesforce.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,107hits
- #2 sso 1,017hits
- #3 imap 456hits
- #4 webmail 361hits
- #5 adfs 188hits
- #6 ftp 129hits
- #7 cpanel 96hits
- #8 github 95hits
- #9 owa 86hits
- #10 sts 84hits
- #11 zendesk 69hits
- #12 extranet 69hits
- #13 zimbra 64hits
- #14 st 52hits
- #15 oracle 42hits
- #16 sap 39hits
- #17 kaspersky 39hits
- #18 roundcube 33hits
- #19 vpn 29hits
- #20 rlogin 26hits
- #21 zoom 21hits
- #22 ping 21hits
- #23 bitbucket 13hits
- #24 salesforce 13hits
- #25 citrix 7hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains