Infostealers Weekly Report: 2019-04-01 – 2019-04-07
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 534
- #2 Brazil 534
- #3 Germany 434
- #4 United States of America 388
- #5 Canada 303
- #6 India 215
- #7 Mexico 167
- #8 Pakistan 141
- #9 Algeria 136
- #10 Egypt 120
- #11 Vietnam 106
- #12 Colombia 98
- #13 Argentina 96
- #14 Morocco 94
- #15 Philippines 76
- #16 Poland 74
- #17 Bangladesh 63
- #18 Romania 60
- #19 Italy 60
- #20 Chile 57
- #21 South Korea 52
- #22 Hungary 50
- #23 Turkey 49
- #24 United Kingdom 48
- #25 Malaysia 45
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,013 users
-
#2
facebook.com 2,643 users
-
#3
live.com 1,641 users
-
#4
twitter.com 818 users
-
#5
netflix.com 711 users
-
#6
paypal.com 665 users
-
#7
yahoo.com 640 users
-
#8
mega.nz 596 users
-
#9
discordapp.com 574 users
-
#10
574 users
-
#11
amazon.com 545 users
-
#12
instagram.com 540 users
-
#13
roblox.com 522 users
-
#14
epicgames.com 516 users
-
#15
steampowered.com 505 users
-
#16
twitch.tv 470 users
-
#17
steamcommunity.com 422 users
-
#18
dropbox.com 410 users
-
#19
linkedin.com 404 users
-
#20
apple.com 394 users
-
#21
192.168.1.1 348 users
-
#22
minecraft.net 304 users
-
#23
ea.com 288 users
-
#24
ebay.com 286 users
-
#25
spotify.com 283 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 19 employees
-
#2
o2.pl 13 employees
-
#3
freenet.de 11 employees
-
#4
onet.pl 9 employees
-
#5
freemail.hu 9 employees
-
#6
tim.it 8 employees
-
#7
icicibank.com 7 employees
-
#8
rediff.com 7 employees
-
#9
7 employees
-
#10
arcor.de 6 employees
-
#11
telecom.pt 6 employees
-
#12
interia.pl 6 employees
-
#13
emailn.de 5 employees
-
#14
POP3://pop.secureserver.net:995 5 employees
-
#15
ig.com.br 5 employees
-
#16
sapo.pt 4 employees
-
#17
twc.com 4 employees
-
#18
i-camz.com 4 employees
-
#19
hwdsb.on.ca 4 employees
-
#20
lifecentersofkansas.com 4 employees
-
#21
netzero.net 4 employees
-
#22
uol.com.br 4 employees
-
#23
hostinger.com 4 employees
-
#24
pdsb.org 4 employees
-
#25
sgcpanel.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
twc.com 4 employees
-
#2
bakerhughes.com 2 employees
-
#3
pepsico.com 2 employees
-
#4
citigroup.com 1 employees
-
#5
harman.com 1 employees
-
#6
google.com 1 employees
-
#7
xerox.com 1 employees
-
#8
jetblue.com 1 employees
Compromised users
-
#1
google.com 3,012 users
-
#2
facebook.com 2,643 users
-
#3
netflix.com 711 users
-
#4
paypal.com 665 users
-
#5
amazon.com 545 users
-
#6
apple.com 394 users
-
#7
ebay.com 286 users
-
#8
walmart.com 70 users
-
#9
adp.com 40 users
-
#10
oracle.com 38 users
-
#11
ups.com 34 users
-
#12
capitalone.com 34 users
-
#13
americanexpress.com 33 users
-
#14
hp.com 32 users
-
#15
target.com 28 users
-
#16
bankofamerica.com 23 users
-
#17
wellsfargo.com 22 users
-
#18
westernunion.com 20 users
-
#19
bestbuy.com 19 users
-
#20
att.com 18 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,731hits
- #2 sso 1,348hits
- #3 imap 654hits
- #4 webmail 415hits
- #5 adfs 250hits
- #6 github 159hits
- #7 owa 146hits
- #8 ftp 141hits
- #9 sap 111hits
- #10 cpanel 105hits
- #11 oracle 105hits
- #12 zendesk 74hits
- #13 sts 72hits
- #14 st 61hits
- #15 vpn 55hits
- #16 kaspersky 51hits
- #17 extranet 46hits
- #18 ping 37hits
- #19 roundcube 23hits
- #20 salesforce 23hits
- #21 zoom 20hits
- #22 webex 17hits
- #23 citrix 13hits
- #24 gitlab 12hits
- #25 bitbucket 9hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains