Infostealers Weekly Report: 2019-06-10 – 2019-06-16
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 1,282
- #2 Vietnam 457
- #3 Germany 342
- #4 Philippines 332
- #5 India 281
- #6 United Kingdom 212
- #7 Thailand 194
- #8 Brazil 193
- #9 Pakistan 171
- #10 Italy 164
- #11 Malaysia 142
- #12 Egypt 118
- #13 Bangladesh 85
- #14 Algeria 81
- #15 Canada 58
- #16 South Korea 54
- #17 Australia 51
- #18 Morocco 50
- #19 Mexico 47
- #20 Argentina 46
- #21 Romania 40
- #22 Japan 40
- #23 United States of America 35
- #24 Iraq 31
- #25 Nepal 30
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,220 users
-
#2
facebook.com 2,805 users
-
#3
live.com 1,359 users
-
#4
twitter.com 689 users
-
#5
yahoo.com 651 users
-
#6
paypal.com 543 users
-
#7
533 users
-
#8
instagram.com 529 users
-
#9
netflix.com 485 users
-
#10
roblox.com 459 users
-
#11
discordapp.com 446 users
-
#12
mega.nz 442 users
-
#13
epicgames.com 403 users
-
#14
amazon.com 364 users
-
#15
linkedin.com 360 users
-
#16
com.facebook.katana 360 users
-
#17
steampowered.com 348 users
-
#18
dropbox.com 333 users
-
#19
twitch.tv 329 users
-
#20
192.168.1.1 326 users
-
#21
apple.com 324 users
-
#22
steamcommunity.com 315 users
-
#23
chrome://FirefoxAccounts 290 users
-
#24
firefox.com 262 users
-
#25
minecraft.net 260 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
aruba.it 12 employees
-
#2
tim.it 12 employees
-
#3
mail.de 9 employees
-
#4
POP3://pop.gmail.com:995 9 employees
-
#5
pec.it 8 employees
-
#6
rediff.com 7 employees
-
#7
confused.com 6 employees
-
#8
freenet.de 6 employees
-
#9
tachyon.net.id 6 employees
-
#10
bni.co.id 6 employees
-
#11
ftp://hoanh.biz/ 6 employees
-
#12
deped.gov.ph 5 employees
-
#13
freemail.hu 5 employees
-
#14
icicibank.com 5 employees
-
#15
interia.pl 5 employees
-
#16
000webhostapp.com 5 employees
-
#17
cartooners.com 5 employees
-
#18
engelbert-strauss.de 5 employees
-
#19
o2.pl 5 employees
-
#20
pln.co.id 4 employees
-
#21
talktalk.co.uk 4 employees
-
#22
SMTP://mail.cgi-group.co.id:587 4 employees
-
#23
4 employees
-
#24
POP3://[email protected]:0 4 employees
-
#25
infocert.it 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
manpowergroup.com 1 employees
-
#2
twc.com 1 employees
-
#3
rockwellautomation.com 1 employees
-
#4
cognizant.com 1 employees
-
#5
google.com 1 employees
-
#6
amazon.com 1 employees
-
#7
starwoodhotels.com 1 employees
-
#8
interpublic.com 1 employees
Compromised users
-
#1
google.com 3,219 users
-
#2
facebook.com 2,805 users
-
#3
paypal.com 543 users
-
#4
netflix.com 485 users
-
#5
amazon.com 364 users
-
#6
apple.com 324 users
-
#7
ebay.com 132 users
-
#8
oracle.com 28 users
-
#9
hp.com 21 users
-
#10
ups.com 19 users
-
#11
microsoft.com 16 users
-
#12
nike.com 14 users
-
#13
americanexpress.com 12 users
-
#14
cisco.com 10 users
-
#15
walmart.com 10 users
-
#16
salesforce.com 10 users
-
#17
adp.com 9 users
-
#18
ti.com 8 users
-
#19
intel.com 8 users
-
#20
westernunion.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 2,963hits
- #2 sso 1,456hits
- #3 imap 510hits
- #4 webmail 332hits
- #5 adfs 149hits
- #6 github 113hits
- #7 ftp 102hits
- #8 owa 90hits
- #9 zendesk 85hits
- #10 sts 75hits
- #11 extranet 71hits
- #12 sap 70hits
- #13 cpanel 70hits
- #14 oracle 60hits
- #15 zoom 38hits
- #16 vpn 37hits
- #17 kaspersky 35hits
- #18 ping 33hits
- #19 salesforce 28hits
- #20 st 21hits
- #21 citrix 13hits
- #22 roundcube 13hits
- #23 gitlab 10hits
- #24 zimbra 9hits
- #25 webex 9hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains