Infostealers Weekly Report: 2019-07-01 – 2019-07-07
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Germany 438
- #2 Indonesia 365
- #3 India 315
- #4 Brazil 282
- #5 Canada 241
- #6 United Kingdom 225
- #7 United States of America 135
- #8 Philippines 133
- #9 Vietnam 112
- #10 Pakistan 110
- #11 Algeria 89
- #12 Australia 87
- #13 Bangladesh 86
- #14 Mexico 64
- #15 Malaysia 64
- #16 Italy 49
- #17 Colombia 43
- #18 Egypt 43
- #19 Morocco 42
- #20 Peru 41
- #21 Thailand 41
- #22 France 33
- #23 Nepal 32
- #24 Poland 27
- #25 Romania 27
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,252 users
-
#2
facebook.com 1,884 users
-
#3
live.com 1,183 users
-
#4
twitter.com 578 users
-
#5
paypal.com 522 users
-
#6
netflix.com 490 users
-
#7
roblox.com 476 users
-
#8
discordapp.com 467 users
-
#9
461 users
-
#10
yahoo.com 451 users
-
#11
epicgames.com 432 users
-
#12
instagram.com 393 users
-
#13
amazon.com 387 users
-
#14
steampowered.com 349 users
-
#15
twitch.tv 324 users
-
#16
steamcommunity.com 319 users
-
#17
mega.nz 317 users
-
#18
linkedin.com 317 users
-
#19
minecraft.net 272 users
-
#20
dropbox.com 270 users
-
#21
apple.com 247 users
-
#22
chrome://FirefoxAccounts 242 users
-
#23
ea.com 230 users
-
#24
sonyentertainmentnetwork.com 223 users
-
#25
firefox.com 215 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 16 employees
-
#2
POP3://[email protected]:0 10 employees
-
#3
POP3://[email protected]:0 10 employees
-
#4
icicibank.com 9 employees
-
#5
freenet.de 8 employees
-
#6
mail.de 8 employees
-
#7
gwdg.de 6 employees
-
#8
POP3://pop.gmx.de:995 6 employees
-
#9
POP3://pop3.web.de:995 6 employees
-
#10
rediris.es 6 employees
-
#11
heanet.ie 6 employees
-
#12
confused.com 6 employees
-
#13
iu.edu 6 employees
-
#14
tim.it 5 employees
-
#15
rediff.com 5 employees
-
#16
POP3://pop.1und1.de:995 5 employees
-
#17
o2.pl 5 employees
-
#18
secureserver.net 4 employees
-
#19
uploaded.net 4 employees
-
#20
POP3://pop.mail.yahoo.com:995 4 employees
-
#21
arcor.de 4 employees
-
#22
talktalk.co.uk 4 employees
-
#23
strato.com 4 employees
-
#24
accenture.com 4 employees
-
#25
POP3://pop.gmx.net:995 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 2 employees
-
#2
synnex.com 1 employees
-
#3
libertymutual.com 1 employees
-
#4
ncr.com 1 employees
-
#5
cognizant.com 1 employees
-
#6
henryschein.com 1 employees
Compromised users
-
#1
google.com 2,252 users
-
#2
facebook.com 1,883 users
-
#3
paypal.com 522 users
-
#4
netflix.com 490 users
-
#5
amazon.com 387 users
-
#6
apple.com 247 users
-
#7
ebay.com 145 users
-
#8
oracle.com 35 users
-
#9
hp.com 28 users
-
#10
ups.com 19 users
-
#11
adp.com 17 users
-
#12
walmart.com 16 users
-
#13
wellsfargo.com 15 users
-
#14
westernunion.com 14 users
-
#15
cisco.com 12 users
-
#16
capitalone.com 12 users
-
#17
americanexpress.com 12 users
-
#18
microsoft.com 12 users
-
#19
att.com 11 users
-
#20
nike.com 11 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 2,590hits
- #2 sso 953hits
- #3 imap 491hits
- #4 webmail 328hits
- #5 adfs 186hits
- #6 cpanel 140hits
- #7 ftp 117hits
- #8 github 100hits
- #9 owa 72hits
- #10 oracle 72hits
- #11 zendesk 71hits
- #12 sts 64hits
- #13 st 63hits
- #14 sap 52hits
- #15 kaspersky 32hits
- #16 extranet 26hits
- #17 ping 26hits
- #18 zoom 20hits
- #19 roundcube 19hits
- #20 vpn 19hits
- #21 okta 14hits
- #22 salesforce 12hits
- #23 webex 10hits
- #24 jira 10hits
- #25 twilio 7hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains