Infostealers Weekly Report: 2019-01-21 – 2019-01-27
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 497
- #2 Indonesia 228
- #3 United States of America 179
- #4 Italy 158
- #5 Germany 146
- #6 United Kingdom 103
- #7 France 103
- #8 India 94
- #9 Canada 79
- #10 Netherlands 71
- #11 Iran 53
- #12 Nigeria 45
- #13 Japan 34
- #14 Vietnam 26
- #15 South Korea 25
- #16 Philippines 24
- #17 Austria 24
- #18 Hong Kong SAR China 16
- #19 Malaysia 15
- #20 Mexico 14
- #21 Thailand 14
- #22 Spain 10
- #23 Hungary 9
- #24 Russia 9
- #25 China 8
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,210 users
-
#2
facebook.com 1,041 users
-
#3
live.com 772 users
-
#4
twitter.com 400 users
-
#5
paypal.com 369 users
-
#6
netflix.com 363 users
-
#7
317 users
-
#8
discordapp.com 279 users
-
#9
steampowered.com 267 users
-
#10
yahoo.com 258 users
-
#11
instagram.com 252 users
-
#12
epicgames.com 250 users
-
#13
steamcommunity.com 249 users
-
#14
mega.nz 234 users
-
#15
twitch.tv 232 users
-
#16
amazon.com 221 users
-
#17
roblox.com 219 users
-
#18
linkedin.com 216 users
-
#19
apple.com 212 users
-
#20
dropbox.com 207 users
-
#21
spotify.com 161 users
-
#22
minecraft.net 156 users
-
#23
com.netflix.mediaclient 156 users
-
#24
sonyentertainmentnetwork.com 148 users
-
#25
192.168.1.1 145 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
tim.it 19 employees
-
#2
aruba.it 9 employees
-
#3
pec.it 8 employees
-
#4
ig.com.br 6 employees
-
#5
infocert.it 5 employees
-
#6
globo.com 5 employees
-
#7
POP3://pop.gmail.com:995 5 employees
-
#8
one.com 5 employees
-
#9
gmx.at 5 employees
-
#10
4 employees
-
#11
ziggo.nl 4 employees
-
#12
sgcpanel.com 4 employees
-
#13
a1.net 3 employees
-
#14
sparkasse.at 3 employees
-
#15
nhs.net 3 employees
-
#16
POP3://pop.gmx.net:995 3 employees
-
#17
talktalk.co.uk 3 employees
-
#18
uol.com.br 3 employees
-
#19
icicibank.com 2 employees
-
#20
univ-nantes.fr 2 employees
-
#21
http://localhost/wordpress/wp-admin/install.php 2 employees
-
#22
truro-penwith.ac.uk 2 employees
-
#23
POP3://pop.vodafone.it:995 2 employees
-
#24
POP3://pop.aikawatk.co.jp:0 2 employees
-
#25
vodafone.it 2 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 1 employees
-
#2
oracle.com 1 employees
-
#3
xerox.com 1 employees
Compromised users
-
#1
google.com 1,210 users
-
#2
facebook.com 1,041 users
-
#3
paypal.com 369 users
-
#4
netflix.com 363 users
-
#5
amazon.com 221 users
-
#6
apple.com 212 users
-
#7
ebay.com 85 users
-
#8
nike.com 13 users
-
#9
americanexpress.com 12 users
-
#10
microsoft.com 11 users
-
#11
oracle.com 11 users
-
#12
walmart.com 10 users
-
#13
hp.com 10 users
-
#14
ups.com 10 users
-
#15
fedex.com 8 users
-
#16
westernunion.com 7 users
-
#17
visa.com 7 users
-
#18
target.com 7 users
-
#19
capitalone.com 7 users
-
#20
bankofamerica.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 1,983hits
- #2 sso 659hits
- #3 imap 473hits
- #4 webmail 303hits
- #5 adfs 156hits
- #6 ftp 85hits
- #7 owa 73hits
- #8 cpanel 65hits
- #9 sts 64hits
- #10 zendesk 64hits
- #11 github 60hits
- #12 st 41hits
- #13 extranet 33hits
- #14 oracle 29hits
- #15 zimbra 23hits
- #16 sap 20hits
- #17 vpn 20hits
- #18 zoom 19hits
- #19 ping 12hits
- #20 kaspersky 12hits
- #21 roundcube 12hits
- #22 bitbucket 10hits
- #23 cscoe 9hits
- #24 salesforce 7hits
- #25 citrix 7hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains