Infostealers Weekly Report: 2019-06-03 – 2019-06-09
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 1,239
- #2 Vietnam 883
- #3 India 829
- #4 Indonesia 660
- #5 Egypt 329
- #6 Germany 324
- #7 Philippines 321
- #8 Thailand 283
- #9 Algeria 274
- #10 United Kingdom 228
- #11 Argentina 209
- #12 Mexico 208
- #13 Morocco 205
- #14 Pakistan 192
- #15 Turkey 165
- #16 Romania 148
- #17 United States of America 147
- #18 Colombia 145
- #19 Malaysia 141
- #20 Bangladesh 129
- #21 Chile 100
- #22 Poland 86
- #23 Peru 84
- #24 Iraq 74
- #25 Canada 74
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,801 users
-
#2
facebook.com 5,221 users
-
#3
live.com 2,836 users
-
#4
twitter.com 1,467 users
-
#5
netflix.com 1,163 users
-
#6
mega.nz 1,137 users
-
#7
yahoo.com 1,124 users
-
#8
instagram.com 1,029 users
-
#9
986 users
-
#10
paypal.com 942 users
-
#11
discordapp.com 911 users
-
#12
roblox.com 860 users
-
#13
epicgames.com 784 users
-
#14
linkedin.com 772 users
-
#15
192.168.1.1 746 users
-
#16
steampowered.com 743 users
-
#17
amazon.com 743 users
-
#18
apple.com 674 users
-
#19
twitch.tv 658 users
-
#20
com.facebook.katana 651 users
-
#21
dropbox.com 648 users
-
#22
steamcommunity.com 580 users
-
#23
chrome://FirefoxAccounts 491 users
-
#24
com.netflix.mediaclient 450 users
-
#25
adobe.com 445 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 38 employees
-
#2
rediff.com 25 employees
-
#3
icicibank.com 22 employees
-
#4
14 employees
-
#5
ig.com.br 14 employees
-
#6
telecom.pt 11 employees
-
#7
freemail.hu 11 employees
-
#8
iu.edu 10 employees
-
#9
sapo.pt 10 employees
-
#10
rediris.es 10 employees
-
#11
heanet.ie 10 employees
-
#12
gwdg.de 10 employees
-
#13
globo.com 9 employees
-
#14
secureserver.net 9 employees
-
#15
POP3://pop.web-experto.com.ar:0 8 employees
-
#16
accenture.com 8 employees
-
#17
uol.com.br 8 employees
-
#18
POP3://[email protected]:0 8 employees
-
#19
POP3://[email protected]:0 8 employees
-
#20
abv.bg 8 employees
-
#21
digimail.in 8 employees
-
#22
freenet.de 7 employees
-
#23
onet.pl 7 employees
-
#24
rockwellautomation.com 7 employees
-
#25
confused.com 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 7 employees
-
#2
cognizant.com 4 employees
-
#3
att.com 2 employees
-
#4
cbre.com 1 employees
-
#5
microsoft.com 1 employees
-
#6
interpublic.com 1 employees
-
#7
fedex.com 1 employees
-
#8
emerson.com 1 employees
-
#9
google.com 1 employees
-
#10
emc.com 1 employees
-
#11
pepsico.com 1 employees
-
#12
netflix.com 1 employees
-
#13
ge.com 1 employees
Compromised users
-
#1
google.com 5,801 users
-
#2
facebook.com 5,221 users
-
#3
netflix.com 1,163 users
-
#4
paypal.com 942 users
-
#5
amazon.com 743 users
-
#6
apple.com 674 users
-
#7
ebay.com 278 users
-
#8
oracle.com 68 users
-
#9
hp.com 49 users
-
#10
ups.com 27 users
-
#11
ibm.com 22 users
-
#12
americanexpress.com 22 users
-
#13
walmart.com 21 users
-
#14
microsoft.com 20 users
-
#15
nike.com 18 users
-
#16
intel.com 14 users
-
#17
adp.com 11 users
-
#18
westernunion.com 11 users
-
#19
visa.com 11 users
-
#20
att.com 10 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 6,556hits
- #2 sso 2,842hits
- #3 imap 717hits
- #4 webmail 578hits
- #5 adfs 331hits
- #6 ftp 295hits
- #7 cpanel 282hits
- #8 github 238hits
- #9 owa 234hits
- #10 oracle 199hits
- #11 zendesk 146hits
- #12 sap 118hits
- #13 st 108hits
- #14 sts 101hits
- #15 kaspersky 90hits
- #16 extranet 87hits
- #17 vpn 83hits
- #18 zoom 56hits
- #19 ping 44hits
- #20 roundcube 38hits
- #21 jira 34hits
- #22 salesforce 31hits
- #23 gitlab 20hits
- #24 bitbucket 19hits
- #25 zimbra 17hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains