Infostealers Weekly Report: 2019-04-15 – 2019-04-21
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Russia 1,406
- #2 India 1,130
- #3 Brazil 713
- #4 Indonesia 496
- #5 Germany 444
- #6 United Kingdom 423
- #7 United States of America 326
- #8 Canada 219
- #9 Pakistan 166
- #10 Romania 105
- #11 Poland 104
- #12 Mexico 101
- #13 Kazakhstan 101
- #14 Australia 97
- #15 Egypt 94
- #16 Philippines 88
- #17 Portugal 76
- #18 Sri Lanka 73
- #19 Bangladesh 63
- #20 Argentina 48
- #21 Hungary 46
- #22 Serbia 43
- #23 Peru 39
- #24 Ecuador 38
- #25 Belarus 37
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,529 users
-
#2
facebook.com 3,660 users
-
#3
live.com 2,308 users
-
#4
twitter.com 1,187 users
-
#5
vk.com 1,160 users
-
#6
mail.ru 1,000 users
-
#7
paypal.com 953 users
-
#8
instagram.com 883 users
-
#9
867 users
-
#10
yahoo.com 826 users
-
#11
netflix.com 792 users
-
#12
steampowered.com 784 users
-
#13
discordapp.com 713 users
-
#14
steamcommunity.com 703 users
-
#15
amazon.com 702 users
-
#16
mega.nz 689 users
-
#17
aliexpress.com 644 users
-
#18
linkedin.com 631 users
-
#19
twitch.tv 630 users
-
#20
epicgames.com 621 users
-
#21
yandex.ru 597 users
-
#22
apple.com 588 users
-
#23
dropbox.com 571 users
-
#24
192.168.1.1 569 users
-
#25
roblox.com 556 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 37 employees
-
#2
icicibank.com 25 employees
-
#3
POP3://pop.gmail.com:995 19 employees
-
#4
confused.com 16 employees
-
#5
interia.pl 15 employees
-
#6
freenet.de 14 employees
-
#7
secureserver.net 14 employees
-
#8
freemail.hu 12 employees
-
#9
telecom.pt 12 employees
-
#10
POP3://goodpostoffice.com:1240028 11 employees
-
#11
ig.com.br 11 employees
-
#12
tut.by 10 employees
-
#13
o2.pl 10 employees
-
#14
9 employees
-
#15
mail.gov.in 9 employees
-
#16
sapo.pt 9 employees
-
#17
1and1.co.uk 9 employees
-
#18
idbibank.co.in 8 employees
-
#19
onet.pl 8 employees
-
#20
mail.de 8 employees
-
#21
bsnl.in 7 employees
-
#22
netpnb.com 7 employees
-
#23
accenture.com 7 employees
-
#24
digimail.in 6 employees
-
#25
one.com 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 2 employees
-
#2
microsoft.com 2 employees
-
#3
rockwellautomation.com 1 employees
-
#4
crowncork.com 1 employees
-
#5
apple.com 1 employees
-
#6
publix.com 1 employees
-
#7
morganstanley.com 1 employees
-
#8
gm.com 1 employees
-
#9
amazon.com 1 employees
-
#10
ford.com 1 employees
-
#11
lear.com 1 employees
Compromised users
-
#1
google.com 4,529 users
-
#2
facebook.com 3,660 users
-
#3
paypal.com 953 users
-
#4
netflix.com 792 users
-
#5
amazon.com 702 users
-
#6
apple.com 588 users
-
#7
ebay.com 351 users
-
#8
oracle.com 49 users
-
#9
hp.com 32 users
-
#10
westernunion.com 28 users
-
#11
ups.com 25 users
-
#12
americanexpress.com 24 users
-
#13
nike.com 21 users
-
#14
microsoft.com 20 users
-
#15
walmart.com 18 users
-
#16
salesforce.com 17 users
-
#17
capitalone.com 16 users
-
#18
fedex.com 15 users
-
#19
cisco.com 14 users
-
#20
adp.com 13 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 6,179hits
- #2 sso 1,808hits
- #3 imap 747hits
- #4 webmail 676hits
- #5 rlogin 444hits
- #6 st 372hits
- #7 adfs 338hits
- #8 ftp 303hits
- #9 github 228hits
- #10 cpanel 215hits
- #11 owa 208hits
- #12 oracle 194hits
- #13 sts 168hits
- #14 zendesk 141hits
- #15 sap 138hits
- #16 kaspersky 134hits
- #17 vpn 70hits
- #18 extranet 58hits
- #19 ping 57hits
- #20 roundcube 49hits
- #21 zoom 37hits
- #22 bitbucket 27hits
- #23 salesforce 27hits
- #24 citrix 20hits
- #25 jira 18hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains