Infostealers Weekly Report: 2019-10-07 – 2019-10-13
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 554
- #2 India 461
- #3 Indonesia 151
- #4 Pakistan 146
- #5 Algeria 76
- #6 France 70
- #7 United Kingdom 65
- #8 Romania 52
- #9 Germany 45
- #10 Bangladesh 45
- #11 Serbia 40
- #12 Thailand 37
- #13 Philippines 34
- #14 Peru 31
- #15 Morocco 28
- #16 Mexico 26
- #17 Argentina 25
- #18 South Africa 22
- #19 Brazil 21
- #20 Colombia 20
- #21 Chile 20
- #22 Ecuador 18
- #23 South Korea 17
- #24 United States of America 17
- #25 Hungary 16
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,604 users
-
#2
facebook.com 1,271 users
-
#3
live.com 658 users
-
#4
twitter.com 325 users
-
#5
yahoo.com 263 users
-
#6
roblox.com 243 users
-
#7
225 users
-
#8
discordapp.com 221 users
-
#9
instagram.com 220 users
-
#10
mega.nz 215 users
-
#11
paypal.com 212 users
-
#12
com.facebook.katana 211 users
-
#13
netflix.com 202 users
-
#14
amazon.com 192 users
-
#15
garena.com 186 users
-
#16
epicgames.com 175 users
-
#17
linkedin.com 173 users
-
#18
192.168.1.1 151 users
-
#19
steampowered.com 146 users
-
#20
apple.com 146 users
-
#21
minecraft.net 142 users
-
#22
chrome://FirefoxAccounts 127 users
-
#23
firefox.com 120 users
-
#24
zing.vn 120 users
-
#25
twitch.tv 117 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://[email protected]:0 12 employees
-
#2
POP3://[email protected]:0 12 employees
-
#3
rediff.com 7 employees
-
#4
icicibank.com 7 employees
-
#5
secureserver.net 6 employees
-
#6
gwdg.de 5 employees
-
#7
netpnb.com 5 employees
-
#8
rediris.es 5 employees
-
#9
iu.edu 5 employees
-
#10
heanet.ie 5 employees
-
#11
freemail.hu 5 employees
-
#12
abv.bg 4 employees
-
#13
isacombank.com.vn 4 employees
-
#14
ftp://hoanh.biz/ 4 employees
-
#15
POP3://pop.gmail.com:995 4 employees
-
#16
idbibank.co.in 3 employees
-
#17
rediffmailpro.com 3 employees
-
#18
webmail.co.za 3 employees
-
#19
hust.edu.vn 3 employees
-
#20
unionbankonline.co.in 3 employees
-
#21
esy.es 2 employees
-
#22
POP3://pop.gmx.net:995 2 employees
-
#23
hathway.com 2 employees
-
#24
hostinger.in 2 employees
-
#25
confused.com 2 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 1 employees
Compromised users
-
#1
google.com 1,604 users
-
#2
facebook.com 1,271 users
-
#3
paypal.com 212 users
-
#4
netflix.com 202 users
-
#5
amazon.com 192 users
-
#6
apple.com 146 users
-
#7
ebay.com 54 users
-
#8
oracle.com 22 users
-
#9
ibm.com 10 users
-
#10
hp.com 9 users
-
#11
cisco.com 9 users
-
#12
microsoft.com 6 users
-
#13
walmart.com 5 users
-
#14
nike.com 5 users
-
#15
ups.com 5 users
-
#16
intel.com 3 users
-
#17
visa.com 3 users
-
#18
westernunion.com 2 users
-
#19
ford.com 2 users
-
#20
salesforce.com 2 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 1,707hits
- #2 sso 865hits
- #3 imap 138hits
- #4 webmail 83hits
- #5 adfs 68hits
- #6 zendesk 59hits
- #7 github 59hits
- #8 ftp 58hits
- #9 oracle 47hits
- #10 cpanel 46hits
- #11 owa 43hits
- #12 kaspersky 34hits
- #13 st 25hits
- #14 sap 23hits
- #15 sts 18hits
- #16 ping 15hits
- #17 vpn 14hits
- #18 zoom 13hits
- #19 jira 9hits
- #20 salesforce 9hits
- #21 extranet 8hits
- #22 twilio 6hits
- #23 zimbra 5hits
- #24 webex 5hits
- #25 bitbucket 5hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains