Infostealers Weekly Report: 2019-01-14 – 2019-01-20
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 805
- #2 Italy 455
- #3 United Kingdom 385
- #4 India 347
- #5 France 337
- #6 Germany 311
- #7 Canada 290
- #8 United States of America 286
- #9 Netherlands 181
- #10 Japan 102
- #11 Nigeria 72
- #12 China 69
- #13 Austria 53
- #14 Hong Kong SAR China 40
- #15 Iran 32
- #16 Spain 19
- #17 Belgium 9
- #18 Bulgaria 6
- #19 Australia 5
- #20 Thailand 3
- #21 Chile 2
- #22 Argentina 2
- #23 Czechia 2
- #24 Norway 2
- #25 Ireland 2
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,219 users
-
#2
facebook.com 2,008 users
-
#3
live.com 1,678 users
-
#4
paypal.com 918 users
-
#5
netflix.com 812 users
-
#6
twitter.com 792 users
-
#7
613 users
-
#8
amazon.com 604 users
-
#9
discordapp.com 563 users
-
#10
epicgames.com 546 users
-
#11
steampowered.com 507 users
-
#12
roblox.com 478 users
-
#13
twitch.tv 476 users
-
#14
yahoo.com 474 users
-
#15
instagram.com 459 users
-
#16
dropbox.com 459 users
-
#17
steamcommunity.com 458 users
-
#18
linkedin.com 429 users
-
#19
apple.com 429 users
-
#20
mega.nz 421 users
-
#21
sonyentertainmentnetwork.com 379 users
-
#22
minecraft.net 348 users
-
#23
spotify.com 339 users
-
#24
com.netflix.mediaclient 313 users
-
#25
ea.com 279 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
aruba.it 34 employees
-
#2
tim.it 31 employees
-
#3
pec.it 27 employees
-
#4
confused.com 25 employees
-
#5
POP3://pop.gmail.com:995 17 employees
-
#6
rediff.com 13 employees
-
#7
POP3://in.alice.it:0 11 employees
-
#8
9 employees
-
#9
docomo.ne.jp 8 employees
-
#10
uol.com.br 8 employees
-
#11
ovh.net 7 employees
-
#12
ziggo.nl 7 employees
-
#13
gmx.at 7 employees
-
#14
freenet.de 6 employees
-
#15
icicibank.com 6 employees
-
#16
digimail.in 6 employees
-
#17
alberta.ca 6 employees
-
#18
qq.com 5 employees
-
#19
talktalk.co.uk 5 employees
-
#20
epost.de 5 employees
-
#21
netpnb.com 5 employees
-
#22
infocert.it 5 employees
-
#23
pdsb.org 5 employees
-
#24
register.it 5 employees
-
#25
ok.de 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
hp.com 2 employees
-
#2
cbre.com 2 employees
-
#3
cognizant.com 2 employees
-
#4
aa.com 1 employees
-
#5
publix.com 1 employees
-
#6
twc.com 1 employees
-
#7
oracle.com 1 employees
-
#8
emc.com 1 employees
-
#9
charter.com 1 employees
Compromised users
-
#1
google.com 2,219 users
-
#2
facebook.com 2,008 users
-
#3
paypal.com 918 users
-
#4
netflix.com 812 users
-
#5
amazon.com 604 users
-
#6
apple.com 429 users
-
#7
ebay.com 245 users
-
#8
ups.com 51 users
-
#9
hp.com 43 users
-
#10
walmart.com 42 users
-
#11
oracle.com 38 users
-
#12
americanexpress.com 35 users
-
#13
capitalone.com 32 users
-
#14
westernunion.com 32 users
-
#15
adp.com 31 users
-
#16
att.com 26 users
-
#17
bankofamerica.com 25 users
-
#18
wellsfargo.com 24 users
-
#19
nike.com 24 users
-
#20
microsoft.com 24 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 4,374hits
- #2 sso 1,426hits
- #3 webmail 908hits
- #4 imap 728hits
- #5 adfs 377hits
- #6 owa 186hits
- #7 ftp 186hits
- #8 github 175hits
- #9 sts 142hits
- #10 zendesk 123hits
- #11 extranet 111hits
- #12 oracle 92hits
- #13 sap 88hits
- #14 kaspersky 84hits
- #15 zimbra 79hits
- #16 cpanel 63hits
- #17 vpn 50hits
- #18 st 35hits
- #19 ping 35hits
- #20 webex 30hits
- #21 roundcube 27hits
- #22 dana-na 20hits
- #23 bitbucket 17hits
- #24 zoom 16hits
- #25 citrix 16hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains