Infostealers Weekly Report: 2019-03-11 – 2019-03-17
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 975
- #2 India 459
- #3 Brazil 261
- #4 Germany 207
- #5 Pakistan 201
- #6 Bangladesh 201
- #7 Canada 193
- #8 Egypt 169
- #9 Algeria 114
- #10 Philippines 99
- #11 Russia 96
- #12 Vietnam 94
- #13 Morocco 77
- #14 Australia 62
- #15 Malaysia 58
- #16 Romania 54
- #17 Argentina 47
- #18 Myanmar (Burma) 46
- #19 Iraq 44
- #20 Nepal 43
- #21 Colombia 43
- #22 Mexico 39
- #23 Thailand 36
- #24 Hungary 34
- #25 Israel 32
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,127 users
-
#2
facebook.com 2,556 users
-
#3
live.com 1,421 users
-
#4
twitter.com 780 users
-
#5
yahoo.com 671 users
-
#6
paypal.com 567 users
-
#7
562 users
-
#8
instagram.com 552 users
-
#9
netflix.com 501 users
-
#10
mega.nz 491 users
-
#11
discordapp.com 474 users
-
#12
linkedin.com 465 users
-
#13
amazon.com 453 users
-
#14
roblox.com 412 users
-
#15
steampowered.com 412 users
-
#16
epicgames.com 399 users
-
#17
192.168.1.1 387 users
-
#18
dropbox.com 360 users
-
#19
apple.com 349 users
-
#20
com.facebook.katana 331 users
-
#21
twitch.tv 325 users
-
#22
steamcommunity.com 323 users
-
#23
chrome://FirefoxAccounts 274 users
-
#24
com.netflix.mediaclient 234 users
-
#25
adobe.com 233 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 16 employees
-
#2
POP3://pop.gmail.com:995 16 employees
-
#3
rediff.com 13 employees
-
#4
secureserver.net 11 employees
-
#5
freemail.hu 9 employees
-
#6
9 employees
-
#7
hostgator.com 8 employees
-
#8
syrahost.com 7 employees
-
#9
web-hosting.com 7 employees
-
#10
pdsb.org 6 employees
-
#11
telecom.pt 5 employees
-
#12
POP3://pop.mail.yahoo.com:995 5 employees
-
#13
strongvpn.com 5 employees
-
#14
epost.de 5 employees
-
#15
o2.pl 5 employees
-
#16
onlinesbi.com 5 employees
-
#17
justhost.com 5 employees
-
#18
rockwellautomation.com 5 employees
-
#19
ui.ac.id 4 employees
-
#20
netpnb.com 4 employees
-
#21
IMAP://mail.asmaircargo.com:993 4 employees
-
#22
mail.gov.in 4 employees
-
#23
POP3://mail.doreen.com:0 4 employees
-
#24
tcs.com 4 employees
-
#25
arcor.de 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 5 employees
-
#2
apple.com 2 employees
-
#3
hp.com 1 employees
-
#4
abbvie.com 1 employees
-
#5
frontier.com 1 employees
-
#6
ge.com 1 employees
-
#7
microsoft.com 1 employees
-
#8
publix.com 1 employees
-
#9
oracle.com 1 employees
Compromised users
-
#1
google.com 3,127 users
-
#2
facebook.com 2,556 users
-
#3
paypal.com 567 users
-
#4
netflix.com 501 users
-
#5
amazon.com 453 users
-
#6
apple.com 349 users
-
#7
ebay.com 195 users
-
#8
oracle.com 42 users
-
#9
ups.com 34 users
-
#10
hp.com 30 users
-
#11
walmart.com 21 users
-
#12
cisco.com 18 users
-
#13
microsoft.com 18 users
-
#14
nike.com 17 users
-
#15
westernunion.com 17 users
-
#16
ibm.com 16 users
-
#17
capitalone.com 10 users
-
#18
fedex.com 9 users
-
#19
salesforce.com 8 users
-
#20
visa.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,777hits
- #2 sso 1,585hits
- #3 imap 500hits
- #4 webmail 430hits
- #5 adfs 187hits
- #6 ftp 165hits
- #7 oracle 151hits
- #8 github 148hits
- #9 zendesk 115hits
- #10 cpanel 102hits
- #11 owa 95hits
- #12 sap 93hits
- #13 st 84hits
- #14 roundcube 75hits
- #15 kaspersky 54hits
- #16 sts 43hits
- #17 zoom 41hits
- #18 vpn 29hits
- #19 zimbra 26hits
- #20 ping 20hits
- #21 dana-na 19hits
- #22 salesforce 17hits
- #23 bitbucket 15hits
- #24 okta 15hits
- #25 extranet 14hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains