Infostealers Weekly Report: 2019-02-04 – 2019-02-10
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 981
- #2 India 750
- #3 United States of America 346
- #4 Brazil 298
- #5 Canada 218
- #6 Pakistan 178
- #7 Malaysia 156
- #8 Bangladesh 136
- #9 Algeria 112
- #10 Romania 106
- #11 Germany 102
- #12 Mexico 99
- #13 Turkey 98
- #14 Morocco 83
- #15 Poland 73
- #16 Argentina 72
- #17 Philippines 69
- #18 Colombia 68
- #19 Iraq 63
- #20 Serbia 50
- #21 South Korea 47
- #22 Chile 47
- #23 Egypt 46
- #24 Myanmar (Burma) 46
- #25 Thailand 44
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,074 users
-
#2
facebook.com 2,688 users
-
#3
live.com 1,509 users
-
#4
twitter.com 850 users
-
#5
yahoo.com 688 users
-
#6
paypal.com 591 users
-
#7
575 users
-
#8
netflix.com 572 users
-
#9
instagram.com 550 users
-
#10
mega.nz 514 users
-
#11
discordapp.com 471 users
-
#12
amazon.com 469 users
-
#13
epicgames.com 461 users
-
#14
roblox.com 444 users
-
#15
linkedin.com 443 users
-
#16
steampowered.com 413 users
-
#17
dropbox.com 401 users
-
#18
steamcommunity.com 387 users
-
#19
apple.com 368 users
-
#20
twitch.tv 352 users
-
#21
192.168.1.1 352 users
-
#22
com.facebook.katana 284 users
-
#23
chrome://FirefoxAccounts 261 users
-
#24
firefox.com 251 users
-
#25
adobe.com 234 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 21 employees
-
#2
icicibank.com 20 employees
-
#3
rediff.com 19 employees
-
#4
digimail.in 14 employees
-
#5
POP3://[email protected]:0 10 employees
-
#6
POP3://[email protected]:0 10 employees
-
#7
o2.pl 8 employees
-
#8
onlinesbi.com 8 employees
-
#9
interia.pl 7 employees
-
#10
7 employees
-
#11
accenture.com 7 employees
-
#12
secureserver.net 6 employees
-
#13
bni.co.id 6 employees
-
#14
onet.pl 5 employees
-
#15
abv.bg 5 employees
-
#16
sapo.pt 5 employees
-
#17
unionbankonline.co.in 4 employees
-
#18
mail.gov.in 4 employees
-
#19
1govuc.gov.my 4 employees
-
#20
hgps.edu.hk 4 employees
-
#21
syrahost.com 4 employees
-
#22
cognizant.com 4 employees
-
#23
telecom.pt 4 employees
-
#24
freemail.hu 4 employees
-
#25
POP3://pop.mail.yahoo.com:995 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 4 employees
-
#2
owenscorning.com 1 employees
-
#3
netflix.com 1 employees
-
#4
ncr.com 1 employees
-
#5
harman.com 1 employees
-
#6
citigroup.com 1 employees
-
#7
lear.com 1 employees
-
#8
ingrammicro.com 1 employees
-
#9
microsoft.com 1 employees
Compromised users
-
#1
google.com 3,074 users
-
#2
facebook.com 2,687 users
-
#3
paypal.com 591 users
-
#4
netflix.com 572 users
-
#5
amazon.com 469 users
-
#6
apple.com 368 users
-
#7
ebay.com 197 users
-
#8
oracle.com 47 users
-
#9
walmart.com 33 users
-
#10
hp.com 32 users
-
#11
ups.com 22 users
-
#12
nike.com 18 users
-
#13
adp.com 17 users
-
#14
att.com 17 users
-
#15
americanexpress.com 16 users
-
#16
capitalone.com 15 users
-
#17
microsoft.com 15 users
-
#18
salesforce.com 13 users
-
#19
visa.com 12 users
-
#20
ibm.com 11 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,561hits
- #2 sso 1,492hits
- #3 webmail 388hits
- #4 imap 339hits
- #5 adfs 206hits
- #6 cpanel 159hits
- #7 ftp 159hits
- #8 github 150hits
- #9 owa 140hits
- #10 zendesk 111hits
- #11 sap 97hits
- #12 oracle 96hits
- #13 vpn 84hits
- #14 st 62hits
- #15 sts 48hits
- #16 jira 47hits
- #17 extranet 45hits
- #18 roundcube 44hits
- #19 salesforce 42hits
- #20 zoom 37hits
- #21 kaspersky 37hits
- #22 confluence 30hits
- #23 bitbucket 25hits
- #24 ping 25hits
- #25 gitlab 14hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains