Infostealers Weekly Report: 2019-04-29 – 2019-05-05
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,777
- #2 Indonesia 2,238
- #3 Brazil 2,212
- #4 Pakistan 977
- #5 Philippines 741
- #6 Bangladesh 488
- #7 Mexico 430
- #8 Algeria 379
- #9 Poland 359
- #10 Romania 316
- #11 Argentina 309
- #12 Morocco 300
- #13 Colombia 276
- #14 Malaysia 243
- #15 Sri Lanka 236
- #16 Peru 226
- #17 Hungary 221
- #18 Germany 209
- #19 Italy 199
- #20 Egypt 190
- #21 Nepal 189
- #22 Serbia 185
- #23 Greece 174
- #24 Iraq 173
- #25 United Kingdom 164
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 11,485 users
-
#2
facebook.com 9,975 users
-
#3
live.com 5,584 users
-
#4
twitter.com 2,962 users
-
#5
yahoo.com 2,467 users
-
#6
netflix.com 2,238 users
-
#7
2,236 users
-
#8
mega.nz 2,206 users
-
#9
paypal.com 2,062 users
-
#10
instagram.com 1,894 users
-
#11
linkedin.com 1,784 users
-
#12
amazon.com 1,604 users
-
#13
192.168.1.1 1,554 users
-
#14
dropbox.com 1,489 users
-
#15
apple.com 1,357 users
-
#16
discordapp.com 1,327 users
-
#17
steampowered.com 1,288 users
-
#18
epicgames.com 1,272 users
-
#19
steamcommunity.com 1,144 users
-
#20
twitch.tv 1,105 users
-
#21
roblox.com 1,105 users
-
#22
com.facebook.katana 1,056 users
-
#23
192.168.0.1 998 users
-
#24
aliexpress.com 994 users
-
#25
chrome://FirefoxAccounts 970 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 85 employees
-
#2
POP3://pop.gmail.com:995 73 employees
-
#3
icicibank.com 55 employees
-
#4
freemail.hu 54 employees
-
#5
o2.pl 43 employees
-
#6
interia.pl 40 employees
-
#7
digimail.in 39 employees
-
#8
26 employees
-
#9
secureserver.net 25 employees
-
#10
ig.com.br 23 employees
-
#11
onet.pl 22 employees
-
#12
telecom.pt 22 employees
-
#13
abv.bg 22 employees
-
#14
uol.com.br 19 employees
-
#15
tim.it 18 employees
-
#16
aruba.it 18 employees
-
#17
sapo.pt 18 employees
-
#18
accenture.com 17 employees
-
#19
onlinesbi.com 17 employees
-
#20
bni.co.id 16 employees
-
#21
citromail.hu 15 employees
-
#22
globo.com 15 employees
-
#23
netpnb.com 14 employees
-
#24
idbibank.co.in 14 employees
-
#25
confused.com 14 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 8 employees
-
#2
microsoft.com 6 employees
-
#3
rockwellautomation.com 4 employees
-
#4
mattel.com 2 employees
-
#5
amazon.com 2 employees
-
#6
hp.com 1 employees
-
#7
fedex.com 1 employees
-
#8
oracle.com 1 employees
-
#9
nike.com 1 employees
-
#10
netflix.com 1 employees
-
#11
apple.com 1 employees
-
#12
ibm.com 1 employees
-
#13
pge.com 1 employees
-
#14
pepsico.com 1 employees
-
#15
csc.com 1 employees
-
#16
google.com 1 employees
-
#17
johnsoncontrols.com 1 employees
Compromised users
-
#1
google.com 11,481 users
-
#2
facebook.com 9,975 users
-
#3
netflix.com 2,238 users
-
#4
paypal.com 2,062 users
-
#5
amazon.com 1,604 users
-
#6
apple.com 1,357 users
-
#7
ebay.com 768 users
-
#8
oracle.com 139 users
-
#9
hp.com 90 users
-
#10
microsoft.com 65 users
-
#11
westernunion.com 48 users
-
#12
ups.com 46 users
-
#13
ibm.com 41 users
-
#14
walmart.com 40 users
-
#15
americanexpress.com 32 users
-
#16
nike.com 31 users
-
#17
salesforce.com 31 users
-
#18
intel.com 29 users
-
#19
cisco.com 27 users
-
#20
visa.com 26 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 12,314hits
- #2 sso 4,653hits
- #3 webmail 1,704hits
- #4 imap 1,526hits
- #5 ftp 717hits
- #6 adfs 593hits
- #7 cpanel 523hits
- #8 github 504hits
- #9 sap 454hits
- #10 oracle 397hits
- #11 owa 377hits
- #12 zendesk 333hits
- #13 st 284hits
- #14 sts 226hits
- #15 extranet 203hits
- #16 kaspersky 175hits
- #17 zoom 133hits
- #18 salesforce 126hits
- #19 vpn 120hits
- #20 zimbra 117hits
- #21 roundcube 84hits
- #22 ping 83hits
- #23 webex 73hits
- #24 dana-na 67hits
- #25 bitbucket 52hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains