Infostealers Weekly Report: 2019-10-21 – 2019-10-27
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 467
- #2 India 364
- #3 Indonesia 296
- #4 Brazil 280
- #5 Turkey 227
- #6 Egypt 217
- #7 Pakistan 168
- #8 Romania 110
- #9 Bangladesh 103
- #10 South Korea 102
- #11 Spain 102
- #12 Colombia 95
- #13 Poland 90
- #14 Mexico 88
- #15 Thailand 79
- #16 Philippines 75
- #17 Argentina 59
- #18 Morocco 56
- #19 Italy 52
- #20 Chile 51
- #21 Georgia 49
- #22 Hungary 44
- #23 United Arab Emirates 41
- #24 Algeria 41
- #25 Serbia 37
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,005 users
-
#2
facebook.com 2,435 users
-
#3
live.com 1,475 users
-
#4
twitter.com 710 users
-
#5
mega.nz 573 users
-
#6
netflix.com 554 users
-
#7
544 users
-
#8
instagram.com 535 users
-
#9
yahoo.com 527 users
-
#10
paypal.com 467 users
-
#11
discordapp.com 467 users
-
#12
roblox.com 456 users
-
#13
com.facebook.katana 417 users
-
#14
amazon.com 413 users
-
#15
steampowered.com 412 users
-
#16
linkedin.com 409 users
-
#17
apple.com 387 users
-
#18
steamcommunity.com 358 users
-
#19
epicgames.com 358 users
-
#20
192.168.1.1 347 users
-
#21
dropbox.com 339 users
-
#22
twitch.tv 324 users
-
#23
aliexpress.com 260 users
-
#24
minecraft.net 246 users
-
#25
com.netflix.mediaclient 245 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 16 employees
-
#2
rediff.com 14 employees
-
#3
abv.bg 11 employees
-
#4
secureserver.net 10 employees
-
#5
o2.pl 10 employees
-
#6
9 employees
-
#7
interia.pl 8 employees
-
#8
tim.it 8 employees
-
#9
skole.hr 7 employees
-
#10
onlinesbi.com 6 employees
-
#11
accenture.com 6 employees
-
#12
http://localhost/wordpress/wp-admin/install.php 5 employees
-
#13
hostgator.com 5 employees
-
#14
freemail.hu 5 employees
-
#15
nbg.gr 4 employees
-
#16
isacombank.com.vn 4 employees
-
#17
bni.co.id 4 employees
-
#18
ionos.es 4 employees
-
#19
icicibank.com 4 employees
-
#20
citromail.hu 4 employees
-
#21
digimail.in 4 employees
-
#22
gmx.at 4 employees
-
#23
mail.bg 4 employees
-
#24
ig.com.br 3 employees
-
#25
one.com 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
jnj.com 1 employees
-
#2
borgwarner.com 1 employees
-
#3
oracle.com 1 employees
-
#4
rockwellautomation.com 1 employees
-
#5
morganstanley.com 1 employees
-
#6
microsoft.com 1 employees
Compromised users
-
#1
google.com 3,004 users
-
#2
facebook.com 2,435 users
-
#3
netflix.com 554 users
-
#4
paypal.com 466 users
-
#5
amazon.com 413 users
-
#6
apple.com 387 users
-
#7
ebay.com 164 users
-
#8
oracle.com 40 users
-
#9
hp.com 30 users
-
#10
microsoft.com 18 users
-
#11
cisco.com 14 users
-
#12
ibm.com 14 users
-
#13
americanexpress.com 11 users
-
#14
westernunion.com 9 users
-
#15
salesforce.com 8 users
-
#16
ups.com 8 users
-
#17
nike.com 7 users
-
#18
intel.com 6 users
-
#19
att.com 5 users
-
#20
walmart.com 5 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 4,255hits
- #2 sso 1,673hits
- #3 webmail 519hits
- #4 imap 326hits
- #5 cpanel 193hits
- #6 adfs 171hits
- #7 owa 166hits
- #8 github 164hits
- #9 roundcube 155hits
- #10 zendesk 122hits
- #11 ftp 118hits
- #12 sap 102hits
- #13 oracle 89hits
- #14 sts 79hits
- #15 kaspersky 69hits
- #16 zoom 45hits
- #17 extranet 42hits
- #18 st 42hits
- #19 vpn 31hits
- #20 ping 30hits
- #21 gitlab 15hits
- #22 citrix 14hits
- #23 webex 14hits
- #24 zimbra 14hits
- #25 salesforce 14hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains