Infostealers Weekly Report: 2019-12-02 – 2019-12-08
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Turkey 5,572
- #2 Pakistan 4,529
- #3 Egypt 4,085
- #4 Brazil 3,796
- #5 Indonesia 3,421
- #6 Vietnam 2,965
- #7 Philippines 2,159
- #8 Thailand 2,108
- #9 Algeria 1,846
- #10 Romania 1,500
- #11 Bangladesh 1,443
- #12 Morocco 1,169
- #13 Serbia 990
- #14 Argentina 863
- #15 Malaysia 845
- #16 United States of America 780
- #17 Nepal 758
- #18 Sri Lanka 757
- #19 Hungary 628
- #20 Kenya 627
- #21 Nigeria 620
- #22 United Arab Emirates 569
- #23 Peru 562
- #24 Iraq 506
- #25 Chile 498
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 38,179 users
-
#2
facebook.com 30,558 users
-
#3
live.com 17,510 users
-
#4
twitter.com 9,490 users
-
#5
roblox.com 8,139 users
-
#6
mega.nz 7,797 users
-
#7
yahoo.com 7,165 users
-
#8
instagram.com 6,868 users
-
#9
discordapp.com 6,805 users
-
#10
netflix.com 6,273 users
-
#11
com.facebook.katana 6,003 users
-
#12
192.168.1.1 5,813 users
-
#13
steampowered.com 5,363 users
-
#14
epicgames.com 5,149 users
-
#15
paypal.com 4,865 users
-
#16
linkedin.com 4,856 users
-
#17
amazon.com 4,188 users
-
#18
apple.com 4,014 users
-
#19
twitch.tv 3,946 users
-
#20
steamcommunity.com 3,938 users
-
#21
minecraft.net 3,781 users
-
#22
dropbox.com 3,203 users
-
#23
3,044 users
-
#24
192.168.0.1 2,710 users
-
#25
com.netflix.mediaclient 2,649 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 157 employees
-
#2
yandex.com.tr 122 employees
-
#3
abv.bg 82 employees
-
#4
telecom.pt 60 employees
-
#5
56 employees
-
#6
secureserver.net 49 employees
-
#7
bluehost.com 43 employees
-
#8
sp.gov.br 42 employees
-
#9
nbg.gr 37 employees
-
#10
hostgator.com 34 employees
-
#11
citromail.hu 33 employees
-
#12
ig.com.br 31 employees
-
#13
mail.bg 29 employees
-
#14
moe.gov.ae 28 employees
-
#15
uol.com.br 27 employees
-
#16
sapo.pt 26 employees
-
#17
nusebel.com 25 employees
-
#18
sgcpanel.com 25 employees
-
#19
matraindonesia.com 25 employees
-
#20
rionegro.gov.ar 24 employees
-
#21
ktmb.com.my 24 employees
-
#22
wasabi88bistro.com 23 employees
-
#23
vendasbb.com.br 23 employees
-
#24
khoschk.com 23 employees
-
#25
pemfmatsreviewed.com 23 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
broadcom.com 10 employees
-
#2
amazon.com 9 employees
-
#3
twc.com 7 employees
-
#4
hp.com 5 employees
-
#5
rockwellautomation.com 4 employees
-
#6
google.com 4 employees
-
#7
humana.com 3 employees
-
#8
microsoft.com 3 employees
-
#9
frontier.com 2 employees
-
#10
netflix.com 2 employees
-
#11
halliburton.com 2 employees
-
#12
xerox.com 1 employees
-
#13
costco.com 1 employees
-
#14
pg.com 1 employees
-
#15
bestbuy.com 1 employees
-
#16
mmc.com 1 employees
-
#17
bakerhughes.com 1 employees
-
#18
ibm.com 1 employees
-
#19
publix.com 1 employees
-
#20
charter.com 1 employees
Compromised users
-
#1
google.com 38,173 users
-
#2
facebook.com 30,551 users
-
#3
netflix.com 6,273 users
-
#4
paypal.com 4,865 users
-
#5
amazon.com 4,188 users
-
#6
apple.com 4,014 users
-
#7
ebay.com 1,588 users
-
#8
oracle.com 503 users
-
#9
hp.com 213 users
-
#10
walmart.com 190 users
-
#11
cisco.com 174 users
-
#12
microsoft.com 168 users
-
#13
westernunion.com 132 users
-
#14
ibm.com 117 users
-
#15
ups.com 111 users
-
#16
nike.com 110 users
-
#17
adp.com 84 users
-
#18
capitalone.com 78 users
-
#19
salesforce.com 76 users
-
#20
fedex.com 73 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 41,037hits
- #2 sso 15,465hits
- #3 webmail 3,646hits
- #4 adfs 1,500hits
- #5 github 1,446hits
- #6 oracle 1,362hits
- #7 owa 1,259hits
- #8 sap 1,217hits
- #9 cpanel 1,079hits
- #10 ftp 960hits
- #11 zendesk 812hits
- #12 sts 603hits
- #13 extranet 464hits
- #14 ping 450hits
- #15 st 448hits
- #16 zoom 428hits
- #17 kaspersky 424hits
- #18 roundcube 352hits
- #19 vpn 339hits
- #20 imap 318hits
- #21 webex 174hits
- #22 salesforce 157hits
- #23 gitlab 118hits
- #24 twilio 101hits
- #25 citrix 88hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains