Infostealers Weekly Report: 2019-07-29 – 2019-08-04
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 112
- #2 Germany 65
- #3 Indonesia 59
- #4 Russia 52
- #5 Canada 50
- #6 Philippines 42
- #7 United Kingdom 35
- #8 Malaysia 33
- #9 India 32
- #10 Brazil 19
- #11 Australia 14
- #12 Kazakhstan 13
- #13 France 12
- #14 South Africa 10
- #15 Bangladesh 9
- #16 Iraq 8
- #17 Ukraine 8
- #18 Sri Lanka 7
- #19 Nepal 7
- #20 Finland 7
- #21 Georgia 6
- #22 Egypt 6
- #23 Pakistan 5
- #24 Portugal 5
- #25 United Arab Emirates 5
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 476 users
-
#2
facebook.com 391 users
-
#3
live.com 249 users
-
#4
paypal.com 151 users
-
#5
twitter.com 130 users
-
#6
netflix.com 124 users
-
#7
roblox.com 117 users
-
#8
amazon.com 115 users
-
#9
discordapp.com 115 users
-
#10
epicgames.com 112 users
-
#11
twitch.tv 106 users
-
#12
yahoo.com 103 users
-
#13
97 users
-
#14
instagram.com 97 users
-
#15
steamcommunity.com 96 users
-
#16
steampowered.com 87 users
-
#17
apple.com 83 users
-
#18
linkedin.com 73 users
-
#19
dropbox.com 70 users
-
#20
ebay.com 61 users
-
#21
ea.com 60 users
-
#22
vk.com 58 users
-
#23
minecraft.net 58 users
-
#24
sonyentertainmentnetwork.com 58 users
-
#25
spotify.com 55 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://[email protected]:0 9 employees
-
#2
POP3://[email protected]:0 9 employees
-
#3
POP3://pop.gmail.com:995 5 employees
-
#4
1govuc.gov.my 3 employees
-
#5
confused.com 3 employees
-
#6
freenet.de 3 employees
-
#7
epost.de 2 employees
-
#8
o2.pl 2 employees
-
#9
techdron.co.in 2 employees
-
#10
POP3://pop3.web.de:995 2 employees
-
#11
ktmb.com.my 2 employees
-
#12
minesmith.com.au 2 employees
-
#13
1blu.de 2 employees
-
#14
radio-zwiebel.com 2 employees
-
#15
engelbert-strauss.de 2 employees
-
#16
POP3://secure.emailsrvr.com:995 2 employees
-
#17
micromine.com 2 employees
-
#18
mail.de 2 employees
-
#19
stoss-medica.de 2 employees
-
#20
malaysiaairlines.com 2 employees
-
#21
2 employees
-
#22
biz.tm 1 employees
-
#23
trailerparkflamingo.com 1 employees
-
#24
POP3://imap.gmail.com:995 1 employees
-
#25
sina.com.cn 1 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
paypal.com 1 employees
Compromised users
-
#1
google.com 476 users
-
#2
facebook.com 391 users
-
#3
paypal.com 151 users
-
#4
netflix.com 124 users
-
#5
amazon.com 115 users
-
#6
apple.com 83 users
-
#7
ebay.com 61 users
-
#8
walmart.com 17 users
-
#9
ups.com 16 users
-
#10
wellsfargo.com 14 users
-
#11
att.com 13 users
-
#12
capitalone.com 11 users
-
#13
adp.com 11 users
-
#14
bestbuy.com 8 users
-
#15
fedex.com 8 users
-
#16
oracle.com 8 users
-
#17
hp.com 7 users
-
#18
bankofamerica.com 7 users
-
#19
americanexpress.com 7 users
-
#20
homedepot.com 6 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 756hits
- #2 sso 290hits
- #3 imap 104hits
- #4 webmail 90hits
- #5 adfs 68hits
- #6 owa 37hits
- #7 ftp 34hits
- #8 oracle 34hits
- #9 github 32hits
- #10 sap 20hits
- #11 sts 19hits
- #12 rlogin 16hits
- #13 zendesk 13hits
- #14 st 13hits
- #15 vpn 10hits
- #16 extranet 8hits
- #17 salesforce 8hits
- #18 cpanel 7hits
- #19 zoom 7hits
- #20 dana-na 6hits
- #21 webex 6hits
- #22 ping 6hits
- #23 kaspersky 6hits
- #24 citrix 5hits
- #25 bitbucket 4hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains