Infostealers Weekly Report: 2019-05-06 – 2019-05-12
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 901
- #2 United States of America 726
- #3 India 680
- #4 Brazil 627
- #5 Indonesia 471
- #6 United Kingdom 318
- #7 Germany 306
- #8 Pakistan 258
- #9 Canada 188
- #10 Philippines 157
- #11 Mexico 146
- #12 Egypt 145
- #13 South Africa 144
- #14 Bangladesh 133
- #15 Thailand 110
- #16 Colombia 108
- #17 Argentina 108
- #18 Turkey 106
- #19 Australia 105
- #20 Poland 104
- #21 France 96
- #22 Algeria 94
- #23 Morocco 91
- #24 Italy 91
- #25 Venezuela 85
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,134 users
-
#2
facebook.com 4,360 users
-
#3
live.com 2,483 users
-
#4
twitter.com 1,233 users
-
#5
netflix.com 1,039 users
-
#6
paypal.com 947 users
-
#7
yahoo.com 934 users
-
#8
discordapp.com 883 users
-
#9
roblox.com 879 users
-
#10
instagram.com 848 users
-
#11
811 users
-
#12
epicgames.com 794 users
-
#13
mega.nz 794 users
-
#14
amazon.com 757 users
-
#15
linkedin.com 648 users
-
#16
steampowered.com 646 users
-
#17
twitch.tv 615 users
-
#18
apple.com 590 users
-
#19
steamcommunity.com 579 users
-
#20
dropbox.com 578 users
-
#21
com.facebook.katana 576 users
-
#22
192.168.1.1 511 users
-
#23
minecraft.net 453 users
-
#24
ea.com 422 users
-
#25
spotify.com 389 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 22 employees
-
#2
POP3://pop.gmail.com:995 21 employees
-
#3
o2.pl 17 employees
-
#4
icicibank.com 16 employees
-
#5
confused.com 13 employees
-
#6
ig.com.br 13 employees
-
#7
tim.it 13 employees
-
#8
12 employees
-
#9
freenet.de 12 employees
-
#10
POP3://[email protected]:0 11 employees
-
#11
POP3://[email protected]:0 11 employees
-
#12
abv.bg 10 employees
-
#13
interia.pl 10 employees
-
#14
secureserver.net 10 employees
-
#15
digimail.in 10 employees
-
#16
onet.pl 9 employees
-
#17
rmunify.com 9 employees
-
#18
aruba.it 8 employees
-
#19
http://localhost/wordpress/wp-admin/install.php 7 employees
-
#20
webmail.co.za 7 employees
-
#21
telecom.pt 7 employees
-
#22
bigpond.com 7 employees
-
#23
freemail.hu 6 employees
-
#24
sapo.pt 6 employees
-
#25
POP3://pop.gmx.net:995 6 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 3 employees
-
#2
publix.com 3 employees
-
#3
rockwellautomation.com 1 employees
-
#4
aetna.com 1 employees
-
#5
csc.com 1 employees
-
#6
morganstanley.com 1 employees
-
#7
interpublic.com 1 employees
-
#8
bakerhughes.com 1 employees
-
#9
jbhunt.com 1 employees
-
#10
lilly.com 1 employees
-
#11
frontier.com 1 employees
-
#12
spiritaero.com 1 employees
-
#13
kiewit.com 1 employees
-
#14
netflix.com 1 employees
-
#15
cisco.com 1 employees
-
#16
amazon.com 1 employees
Compromised users
-
#1
google.com 5,134 users
-
#2
facebook.com 4,360 users
-
#3
netflix.com 1,039 users
-
#4
paypal.com 947 users
-
#5
amazon.com 757 users
-
#6
apple.com 590 users
-
#7
ebay.com 304 users
-
#8
oracle.com 76 users
-
#9
walmart.com 59 users
-
#10
hp.com 46 users
-
#11
adp.com 39 users
-
#12
ups.com 35 users
-
#13
capitalone.com 33 users
-
#14
americanexpress.com 29 users
-
#15
microsoft.com 28 users
-
#16
att.com 26 users
-
#17
nike.com 25 users
-
#18
westernunion.com 22 users
-
#19
wellsfargo.com 19 users
-
#20
cisco.com 18 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 5,857hits
- #2 sso 2,649hits
- #3 imap 748hits
- #4 webmail 624hits
- #5 adfs 357hits
- #6 github 243hits
- #7 ftp 214hits
- #8 owa 210hits
- #9 oracle 181hits
- #10 sts 154hits
- #11 zendesk 141hits
- #12 cpanel 123hits
- #13 sap 101hits
- #14 st 82hits
- #15 extranet 65hits
- #16 vpn 62hits
- #17 salesforce 61hits
- #18 kaspersky 55hits
- #19 zoom 48hits
- #20 roundcube 42hits
- #21 ping 36hits
- #22 bitbucket 24hits
- #23 gitlab 23hits
- #24 dana-na 21hits
- #25 citrix 19hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains