Infostealers Weekly Report: 2019-04-22 – 2019-04-28
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,247
- #2 Indonesia 895
- #3 Brazil 820
- #4 Germany 494
- #5 United Kingdom 385
- #6 Pakistan 318
- #7 Italy 257
- #8 Philippines 239
- #9 Algeria 191
- #10 Mexico 188
- #11 Canada 158
- #12 Hungary 155
- #13 Romania 148
- #14 Bangladesh 138
- #15 Colombia 138
- #16 Morocco 131
- #17 Poland 129
- #18 Australia 107
- #19 Argentina 93
- #20 Chile 91
- #21 Israel 91
- #22 Portugal 90
- #23 Peru 80
- #24 Iraq 80
- #25 Serbia 72
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,342 users
-
#2
facebook.com 4,803 users
-
#3
live.com 2,718 users
-
#4
twitter.com 1,351 users
-
#5
paypal.com 1,212 users
-
#6
netflix.com 1,127 users
-
#7
1,103 users
-
#8
yahoo.com 1,039 users
-
#9
mega.nz 975 users
-
#10
instagram.com 920 users
-
#11
epicgames.com 793 users
-
#12
amazon.com 793 users
-
#13
linkedin.com 792 users
-
#14
discordapp.com 775 users
-
#15
dropbox.com 741 users
-
#16
steampowered.com 702 users
-
#17
roblox.com 701 users
-
#18
apple.com 685 users
-
#19
steamcommunity.com 668 users
-
#20
192.168.1.1 658 users
-
#21
twitch.tv 640 users
-
#22
chrome://FirefoxAccounts 489 users
-
#23
spotify.com 471 users
-
#24
com.netflix.mediaclient 465 users
-
#25
ea.com 458 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 43 employees
-
#2
rediff.com 37 employees
-
#3
aruba.it 26 employees
-
#4
freemail.hu 26 employees
-
#5
tim.it 25 employees
-
#6
pec.it 25 employees
-
#7
icicibank.com 22 employees
-
#8
o2.pl 18 employees
-
#9
freenet.de 17 employees
-
#10
abv.bg 15 employees
-
#11
secureserver.net 14 employees
-
#12
interia.pl 13 employees
-
#13
onet.pl 12 employees
-
#14
12 employees
-
#15
tut.by 11 employees
-
#16
telecom.pt 11 employees
-
#17
digimail.in 10 employees
-
#18
confused.com 10 employees
-
#19
arcor.de 10 employees
-
#20
accenture.com 10 employees
-
#21
mail.de 10 employees
-
#22
maccabi4u.co.il 9 employees
-
#23
sapo.pt 9 employees
-
#24
netpnb.com 8 employees
-
#25
register.it 8 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 6 employees
-
#2
hp.com 2 employees
-
#3
microsoft.com 1 employees
-
#4
sealedair.com 1 employees
-
#5
marriott.com 1 employees
-
#6
aa.com 1 employees
-
#7
publix.com 1 employees
-
#8
apple.com 1 employees
Compromised users
-
#1
google.com 5,342 users
-
#2
facebook.com 4,803 users
-
#3
paypal.com 1,212 users
-
#4
netflix.com 1,127 users
-
#5
amazon.com 793 users
-
#6
apple.com 685 users
-
#7
ebay.com 371 users
-
#8
oracle.com 70 users
-
#9
hp.com 41 users
-
#10
microsoft.com 29 users
-
#11
westernunion.com 28 users
-
#12
americanexpress.com 27 users
-
#13
nike.com 22 users
-
#14
ibm.com 20 users
-
#15
salesforce.com 19 users
-
#16
ups.com 15 users
-
#17
cisco.com 15 users
-
#18
walmart.com 15 users
-
#19
intel.com 13 users
-
#20
adp.com 12 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 5,985hits
- #2 sso 2,274hits
- #3 imap 1,034hits
- #4 webmail 981hits
- #5 adfs 366hits
- #6 ftp 297hits
- #7 st 294hits
- #8 cpanel 237hits
- #9 owa 229hits
- #10 github 214hits
- #11 oracle 179hits
- #12 zendesk 176hits
- #13 sap 173hits
- #14 sts 130hits
- #15 vpn 102hits
- #16 kaspersky 91hits
- #17 extranet 64hits
- #18 salesforce 42hits
- #19 dana-na 40hits
- #20 roundcube 38hits
- #21 zoom 37hits
- #22 ping 37hits
- #23 bitbucket 35hits
- #24 jira 32hits
- #25 okta 29hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains