Infostealers Weekly Report: 2019-06-24 – 2019-06-30
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 739
- #2 United States of America 739
- #3 Indonesia 596
- #4 Germany 279
- #5 Canada 271
- #6 Brazil 242
- #7 Vietnam 223
- #8 Italy 187
- #9 United Kingdom 170
- #10 Pakistan 147
- #11 Philippines 139
- #12 Thailand 131
- #13 Bangladesh 99
- #14 Turkey 90
- #15 Australia 81
- #16 Egypt 67
- #17 Malaysia 57
- #18 South Korea 51
- #19 Iraq 51
- #20 Algeria 48
- #21 Nepal 40
- #22 Iran 35
- #23 Myanmar (Burma) 31
- #24 Romania 28
- #25 Sri Lanka 25
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,830 users
-
#2
facebook.com 2,472 users
-
#3
live.com 1,450 users
-
#4
roblox.com 769 users
-
#5
twitter.com 660 users
-
#6
yahoo.com 578 users
-
#7
paypal.com 572 users
-
#8
discordapp.com 564 users
-
#9
epicgames.com 561 users
-
#10
instagram.com 498 users
-
#11
495 users
-
#12
netflix.com 491 users
-
#13
amazon.com 486 users
-
#14
steampowered.com 404 users
-
#15
steamcommunity.com 382 users
-
#16
twitch.tv 361 users
-
#17
minecraft.net 350 users
-
#18
mega.nz 322 users
-
#19
linkedin.com 321 users
-
#20
chrome://FirefoxAccounts 304 users
-
#21
apple.com 291 users
-
#22
dropbox.com 276 users
-
#23
firefox.com 261 users
-
#24
sonyentertainmentnetwork.com 252 users
-
#25
com.facebook.katana 236 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 36 employees
-
#2
rediff.com 18 employees
-
#3
pec.it 13 employees
-
#4
tim.it 11 employees
-
#5
mail.de 10 employees
-
#6
icicibank.com 10 employees
-
#7
POP3://[email protected]:0 10 employees
-
#8
POP3://[email protected]:0 10 employees
-
#9
hcps.net 9 employees
-
#10
aruba.it 8 employees
-
#11
onlinesbi.com 7 employees
-
#12
spcollege.edu 7 employees
-
#13
baycare.org 7 employees
-
#14
engelbert-strauss.de 7 employees
-
#15
digimail.in 7 employees
-
#16
hccfl.edu 7 employees
-
#17
arcor.de 6 employees
-
#18
dccnet.com 6 employees
-
#19
eastlink.ca 6 employees
-
#20
freemail.hu 6 employees
-
#21
POP3://in.alice.it:0 6 employees
-
#22
zing.vn 6 employees
-
#23
costco.com 6 employees
-
#24
rediris.es 5 employees
-
#25
freenet.de 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
costco.com 6 employees
-
#2
twc.com 2 employees
-
#3
rockwellautomation.com 1 employees
-
#4
jetblue.com 1 employees
-
#5
goodyear.com 1 employees
-
#6
bnymellon.com 1 employees
-
#7
att.com 1 employees
-
#8
publix.com 1 employees
-
#9
netflix.com 1 employees
-
#10
hp.com 1 employees
Compromised users
-
#1
google.com 2,829 users
-
#2
facebook.com 2,471 users
-
#3
paypal.com 572 users
-
#4
netflix.com 491 users
-
#5
amazon.com 486 users
-
#6
apple.com 291 users
-
#7
ebay.com 146 users
-
#8
walmart.com 58 users
-
#9
wellsfargo.com 36 users
-
#10
oracle.com 35 users
-
#11
att.com 34 users
-
#12
adp.com 31 users
-
#13
capitalone.com 27 users
-
#14
ups.com 22 users
-
#15
westernunion.com 22 users
-
#16
target.com 19 users
-
#17
hp.com 17 users
-
#18
americanexpress.com 15 users
-
#19
progressive.com 12 users
-
#20
bankofamerica.com 11 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 2,622hits
- #2 sso 1,540hits
- #3 imap 504hits
- #4 webmail 445hits
- #5 adfs 218hits
- #6 ftp 125hits
- #7 github 107hits
- #8 cpanel 103hits
- #9 oracle 101hits
- #10 sap 81hits
- #11 owa 65hits
- #12 sts 65hits
- #13 st 63hits
- #14 kaspersky 42hits
- #15 salesforce 39hits
- #16 zendesk 36hits
- #17 ping 34hits
- #18 vpn 26hits
- #19 gitlab 23hits
- #20 zimbra 17hits
- #21 extranet 16hits
- #22 git 16hits
- #23 okta 15hits
- #24 twilio 13hits
- #25 citrix 11hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains