Skip to content
Weekly intelligence Jun 10 – Jun 16, 2019 10 min read

Infostealers Weekly Report: 2019-06-10 – 2019-06-16

InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…

#1 0 Compromised Machines
#2 0 Compromised Employees
#3 0 Compromised Users
#4 0 Compromised Androids
#5 0 Compromised Domains

Threat Geography

Where infections came from

Compromised machines distributed by country of infection — hover any region to inspect.

Top 25 of 135
Infections by country

Top 25 countries

  1. #1 Indonesia 1,282
  2. #2 Vietnam 457
  3. #3 Germany 342
  4. #4 Philippines 332
  5. #5 India 281
  6. #6 United Kingdom 212
  7. #7 Thailand 194
  8. #8 Brazil 193
  9. #9 Pakistan 171
  10. #10 Italy 164
  11. #11 Malaysia 142
  12. #12 Egypt 118
  13. #13 Bangladesh 85
  14. #14 Algeria 81
  15. #15 Canada 58
  16. #16 South Korea 54
  17. #17 Australia 51
  18. #18 Morocco 50
  19. #19 Mexico 47
  20. #20 Argentina 46
  21. #21 Romania 40
  22. #22 Japan 40
  23. #23 United States of America 35
  24. #24 Iraq 31
  25. #25 Nepal 30

Top Compromised Domains

Where users had active sessions

Domains where infected users had active sessions and saved credentials at the time of infection.

Top 25
  1. #1 google.com 3,220 users
  2. #2 facebook.com 2,805 users
  3. #3 live.com 1,359 users
  4. #4 twitter.com 689 users
  5. #5 yahoo.com 651 users
  6. #6 paypal.com 543 users
  7. #7 533 users
  8. #8 instagram.com 529 users
  9. #9 netflix.com 485 users
  10. #10 roblox.com 459 users
  11. #11 discordapp.com 446 users
  12. #12 mega.nz 442 users
  13. #13 epicgames.com 403 users
  14. #14 amazon.com 364 users
  15. #15 linkedin.com 360 users
  16. #16 com.facebook.katana 360 users
  17. #17 steampowered.com 348 users
  18. #18 dropbox.com 333 users
  19. #19 twitch.tv 329 users
  20. #20 192.168.1.1 326 users
  21. #21 apple.com 324 users
  22. #22 steamcommunity.com 315 users
  23. #23 chrome://FirefoxAccounts 290 users
  24. #24 firefox.com 262 users
  25. #25 minecraft.net 260 users

Top Compromised Corporate Domains

Employees caught in the logs

Domains where compromised users were employees, surfaced via business email and credentials.

Top 25
  1. #1 aruba.it 12 employees
  2. #2 tim.it 12 employees
  3. #3 mail.de 9 employees
  4. #4 POP3://pop.gmail.com:995 9 employees
  5. #5 pec.it 8 employees
  6. #6 rediff.com 7 employees
  7. #7 confused.com 6 employees
  8. #8 freenet.de 6 employees
  9. #9 tachyon.net.id 6 employees
  10. #10 bni.co.id 6 employees
  11. #11 ftp://hoanh.biz/ 6 employees
  12. #12 deped.gov.ph 5 employees
  13. #13 freemail.hu 5 employees
  14. #14 icicibank.com 5 employees
  15. #15 interia.pl 5 employees
  16. #16 000webhostapp.com 5 employees
  17. #17 cartooners.com 5 employees
  18. #18 engelbert-strauss.de 5 employees
  19. #19 o2.pl 5 employees
  20. #20 pln.co.id 4 employees
  21. #21 talktalk.co.uk 4 employees
  22. #22 SMTP://mail.cgi-group.co.id:587 4 employees
  23. #23 4 employees
  24. #24 POP3://[email protected]:0 4 employees
  25. #25 infocert.it 4 employees

Fortune 500 Exposure

Top S&P companies hit this week

Top S&P companies with compromised employees and customers detected this week.

Compromised employees

  1. #1 manpowergroup.com 1 employees
  2. #2 twc.com 1 employees
  3. #3 rockwellautomation.com 1 employees
  4. #4 cognizant.com 1 employees
  5. #5 google.com 1 employees
  6. #6 amazon.com 1 employees
  7. #7 starwoodhotels.com 1 employees
  8. #8 interpublic.com 1 employees

Compromised users

  1. #1 google.com 3,219 users
  2. #2 facebook.com 2,805 users
  3. #3 paypal.com 543 users
  4. #4 netflix.com 485 users
  5. #5 amazon.com 364 users
  6. #6 apple.com 324 users
  7. #7 ebay.com 132 users
  8. #8 oracle.com 28 users
  9. #9 hp.com 21 users
  10. #10 ups.com 19 users
  11. #11 microsoft.com 16 users
  12. #12 nike.com 14 users
  13. #13 americanexpress.com 12 users
  14. #14 cisco.com 10 users
  15. #15 walmart.com 10 users
  16. #16 salesforce.com 10 users
  17. #17 adp.com 9 users
  18. #18 ti.com 8 users
  19. #19 intel.com 8 users
  20. #20 westernunion.com 7 users

Targeted Application Keywords

What attackers grep for

The most common application keywords seen across credential logs — auth, sso, vpn, and more.

Top 25
  1. #1 auth 2,963hits
  2. #2 sso 1,456hits
  3. #3 imap 510hits
  4. #4 webmail 332hits
  5. #5 adfs 149hits
  6. #6 github 113hits
  7. #7 ftp 102hits
  8. #8 owa 90hits
  9. #9 zendesk 85hits
  10. #10 sts 75hits
  11. #11 extranet 71hits
  12. #12 sap 70hits
  13. #13 cpanel 70hits
  14. #14 oracle 60hits
  15. #15 zoom 38hits
  16. #16 vpn 37hits
  17. #17 kaspersky 35hits
  18. #18 ping 33hits
  19. #19 salesforce 28hits
  20. #20 st 21hits
  21. #21 citrix 13hits
  22. #22 roundcube 13hits
  23. #23 gitlab 10hits
  24. #24 zimbra 9hits
  25. #25 webex 9hits

Cavalier · Continuous monitoring

Get this depth of insight on your own organization.

Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.

More reports

Previous weekly briefings

View archive →
Free Tools Check your exposure