Infostealers Weekly Report: 2019-02-11 – 2019-02-17
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 487
- #2 Brazil 475
- #3 India 224
- #4 United Kingdom 213
- #5 Mexico 186
- #6 Canada 183
- #7 Germany 170
- #8 Vietnam 159
- #9 France 118
- #10 Egypt 115
- #11 Bangladesh 110
- #12 Morocco 110
- #13 Romania 102
- #14 Turkey 96
- #15 Philippines 93
- #16 Algeria 90
- #17 Poland 83
- #18 Russia 82
- #19 South Korea 77
- #20 Argentina 76
- #21 Hungary 73
- #22 Malaysia 73
- #23 Colombia 66
- #24 Chile 64
- #25 Portugal 55
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,146 users
-
#2
facebook.com 2,764 users
-
#3
live.com 1,658 users
-
#4
twitter.com 796 users
-
#5
netflix.com 639 users
-
#6
paypal.com 635 users
-
#7
yahoo.com 600 users
-
#8
mega.nz 597 users
-
#9
580 users
-
#10
instagram.com 574 users
-
#11
roblox.com 545 users
-
#12
epicgames.com 524 users
-
#13
discordapp.com 518 users
-
#14
steampowered.com 500 users
-
#15
linkedin.com 462 users
-
#16
steamcommunity.com 429 users
-
#17
dropbox.com 421 users
-
#18
amazon.com 417 users
-
#19
twitch.tv 412 users
-
#20
apple.com 381 users
-
#21
192.168.1.1 345 users
-
#22
com.facebook.katana 292 users
-
#23
minecraft.net 285 users
-
#24
chrome://FirefoxAccounts 270 users
-
#25
com.netflix.mediaclient 268 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 14 employees
-
#2
confused.com 12 employees
-
#3
onet.pl 10 employees
-
#4
ig.com.br 9 employees
-
#5
interia.pl 9 employees
-
#6
8 employees
-
#7
freemail.hu 8 employees
-
#8
secureserver.net 6 employees
-
#9
enteos.it 6 employees
-
#10
o2.pl 6 employees
-
#11
pdsb.org 6 employees
-
#12
sapo.pt 6 employees
-
#13
telecom.pt 5 employees
-
#14
citromail.hu 5 employees
-
#15
bluehost.com 5 employees
-
#16
nbg.gr 5 employees
-
#17
rediff.com 5 employees
-
#18
POP3://goodpostoffice.com:0 5 employees
-
#19
globo.com 4 employees
-
#20
sempreser.com.br 4 employees
-
#21
freenet.de 4 employees
-
#22
abv.bg 4 employees
-
#23
http://localhost/wordpress/wp-admin/install.php 4 employees
-
#24
POP3://outlook.office365.com:995 4 employees
-
#25
heanet.ie 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
hp.com 3 employees
-
#2
rockwellautomation.com 2 employees
-
#3
oracle.com 2 employees
-
#4
citigroup.com 1 employees
-
#5
ppg.com 1 employees
-
#6
aramark.com 1 employees
-
#7
microsoft.com 1 employees
-
#8
sherwin.com 1 employees
-
#9
ibm.com 1 employees
-
#10
csc.com 1 employees
-
#11
unitedrentals.com 1 employees
-
#12
pfizer.com 1 employees
-
#13
techdata.com 1 employees
Compromised users
-
#1
google.com 3,146 users
-
#2
facebook.com 2,764 users
-
#3
netflix.com 639 users
-
#4
paypal.com 635 users
-
#5
amazon.com 417 users
-
#6
apple.com 381 users
-
#7
ebay.com 195 users
-
#8
oracle.com 36 users
-
#9
hp.com 27 users
-
#10
ups.com 27 users
-
#11
capitalone.com 21 users
-
#12
ibm.com 17 users
-
#13
microsoft.com 16 users
-
#14
westernunion.com 15 users
-
#15
cisco.com 14 users
-
#16
adp.com 11 users
-
#17
walmart.com 11 users
-
#18
intel.com 10 users
-
#19
salesforce.com 8 users
-
#20
americanexpress.com 8 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,448hits
- #2 sso 1,493hits
- #3 imap 427hits
- #4 webmail 379hits
- #5 adfs 206hits
- #6 ftp 164hits
- #7 cpanel 159hits
- #8 sap 150hits
- #9 github 141hits
- #10 owa 133hits
- #11 oracle 114hits
- #12 st 96hits
- #13 sts 95hits
- #14 zendesk 72hits
- #15 extranet 54hits
- #16 vpn 47hits
- #17 zimbra 40hits
- #18 ping 37hits
- #19 kaspersky 32hits
- #20 zoom 31hits
- #21 roundcube 26hits
- #22 webex 20hits
- #23 citrix 20hits
- #24 salesforce 19hits
- #25 bitbucket 18hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-15 – 2026-06-22
- 16K machines
- 3K users
- 216K domains
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains