Infostealers Weekly Report: 2019-12-23 – 2019-12-29
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 5,737
- #2 Vietnam 5,226
- #3 Indonesia 4,305
- #4 Brazil 3,774
- #5 Turkey 3,005
- #6 Pakistan 2,930
- #7 Egypt 2,439
- #8 Romania 1,845
- #9 Bangladesh 1,449
- #10 Thailand 1,405
- #11 Philippines 1,135
- #12 Hungary 1,068
- #13 Algeria 1,022
- #14 Argentina 815
- #15 Morocco 799
- #16 Serbia 763
- #17 Malaysia 696
- #18 Nepal 594
- #19 Portugal 535
- #20 Sri Lanka 493
- #21 Chile 487
- #22 Iran 473
- #23 South Africa 401
- #24 Bulgaria 380
- #25 United Arab Emirates 364
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 33,925 users
-
#2
facebook.com 24,857 users
-
#3
live.com 14,666 users
-
#4
twitter.com 7,426 users
-
#5
mega.nz 6,386 users
-
#6
yahoo.com 6,253 users
-
#7
instagram.com 5,781 users
-
#8
netflix.com 5,507 users
-
#9
roblox.com 5,333 users
-
#10
com.facebook.katana 5,146 users
-
#11
discordapp.com 5,041 users
-
#12
4,401 users
-
#13
paypal.com 4,113 users
-
#14
steampowered.com 4,099 users
-
#15
amazon.com 4,081 users
-
#16
linkedin.com 4,079 users
-
#17
192.168.1.1 3,891 users
-
#18
epicgames.com 3,717 users
-
#19
apple.com 3,369 users
-
#20
steamcommunity.com 3,241 users
-
#21
twitch.tv 2,937 users
-
#22
dropbox.com 2,802 users
-
#23
minecraft.net 2,621 users
-
#24
garena.com 2,376 users
-
#25
firefox.com 2,225 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
freemail.hu 217 employees
-
#2
rediff.com 176 employees
-
#3
icicibank.com 128 employees
-
#4
telecom.pt 93 employees
-
#5
abv.bg 81 employees
-
#6
yandex.com.tr 61 employees
-
#7
59 employees
-
#8
onlinesbi.com 57 employees
-
#9
digimail.in 55 employees
-
#10
secureserver.net 54 employees
-
#11
citromail.hu 41 employees
-
#12
sapo.pt 41 employees
-
#13
accenture.com 40 employees
-
#14
mail.bg 35 employees
-
#15
netpnb.com 34 employees
-
#16
ftp://hoanh.biz/ 33 employees
-
#17
idbibank.co.in 30 employees
-
#18
inbox.lv 29 employees
-
#19
uol.com.br 28 employees
-
#20
isacombank.com.vn 27 employees
-
#21
ig.com.br 26 employees
-
#22
bni.co.id 26 employees
-
#23
http://localhost/wordpress/wp-admin/install.php 25 employees
-
#24
indusind.com 23 employees
-
#25
jwpub.org 21 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 8 employees
-
#2
hp.com 5 employees
-
#3
rockwellautomation.com 5 employees
-
#4
csc.com 4 employees
-
#5
halliburton.com 4 employees
-
#6
cbre.com 3 employees
-
#7
thermofisher.com 3 employees
-
#8
oracle.com 3 employees
-
#9
microsoft.com 3 employees
-
#10
ncr.com 3 employees
-
#11
sanmina.com 2 employees
-
#12
jacobs.com 2 employees
-
#13
netapp.com 2 employees
-
#14
amazon.com 2 employees
-
#15
harman.com 2 employees
-
#16
expeditors.com 1 employees
-
#17
ford.com 1 employees
-
#18
pg.com 1 employees
-
#19
jnj.com 1 employees
-
#20
ecolab.com 1 employees
Compromised users
-
#1
google.com 33,919 users
-
#2
facebook.com 24,853 users
-
#3
netflix.com 5,504 users
-
#4
paypal.com 4,113 users
-
#5
amazon.com 4,081 users
-
#6
apple.com 3,369 users
-
#7
ebay.com 1,279 users
-
#8
oracle.com 453 users
-
#9
hp.com 226 users
-
#10
microsoft.com 167 users
-
#11
cisco.com 165 users
-
#12
ibm.com 119 users
-
#13
americanexpress.com 86 users
-
#14
intel.com 78 users
-
#15
westernunion.com 77 users
-
#16
salesforce.com 70 users
-
#17
walmart.com 67 users
-
#18
nike.com 64 users
-
#19
ups.com 48 users
-
#20
adp.com 44 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 37,192hits
- #2 sso 14,973hits
- #3 webmail 2,857hits
- #4 adfs 1,458hits
- #5 github 1,356hits
- #6 owa 1,267hits
- #7 cpanel 1,141hits
- #8 sap 1,079hits
- #9 oracle 1,061hits
- #10 zendesk 691hits
- #11 ftp 669hits
- #12 kaspersky 541hits
- #13 st 538hits
- #14 sts 460hits
- #15 salesforce 343hits
- #16 zoom 316hits
- #17 imap 314hits
- #18 ping 305hits
- #19 vpn 270hits
- #20 extranet 238hits
- #21 roundcube 209hits
- #22 webex 122hits
- #23 citrix 121hits
- #24 bitbucket 101hits
- #25 twilio 100hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains