Infostealers Weekly Report: 2019-07-22 – 2019-07-28
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 89
- #2 Spain 57
- #3 Germany 46
- #4 Brazil 44
- #5 France 43
- #6 Netherlands 28
- #7 Egypt 25
- #8 Philippines 23
- #9 Indonesia 23
- #10 Pakistan 21
- #11 Turkey 20
- #12 United Kingdom 19
- #13 Vietnam 19
- #14 Portugal 17
- #15 Thailand 17
- #16 Italy 15
- #17 South Korea 14
- #18 Argentina 14
- #19 Bangladesh 13
- #20 Israel 12
- #21 Czechia 11
- #22 Australia 10
- #23 Algeria 10
- #24 Romania 9
- #25 Hungary 9
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 468 users
-
#2
facebook.com 388 users
-
#3
live.com 262 users
-
#4
twitter.com 119 users
-
#5
instagram.com 103 users
-
#6
100 users
-
#7
amazon.com 93 users
-
#8
discordapp.com 92 users
-
#9
netflix.com 91 users
-
#10
paypal.com 90 users
-
#11
yahoo.com 87 users
-
#12
epicgames.com 80 users
-
#13
roblox.com 77 users
-
#14
mega.nz 72 users
-
#15
linkedin.com 69 users
-
#16
dropbox.com 69 users
-
#17
apple.com 64 users
-
#18
twitch.tv 64 users
-
#19
steampowered.com 63 users
-
#20
steamcommunity.com 60 users
-
#21
minecraft.net 57 users
-
#22
chrome://FirefoxAccounts 49 users
-
#23
sonyentertainmentnetwork.com 48 users
-
#24
com.netflix.mediaclient 48 users
-
#25
spotify.com 46 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
insearch.edu.au 3 employees
-
#2
rediff.com 3 employees
-
#3
icicibank.com 3 employees
-
#4
ig.com.br 3 employees
-
#5
tpg.com.au 2 employees
-
#6
gwdg.de 2 employees
-
#7
heanet.ie 2 employees
-
#8
tim.it 2 employees
-
#9
2 employees
-
#10
POP3://[email protected]:0 2 employees
-
#11
abv.bg 2 employees
-
#12
POP3://pop.gmail.com:995 2 employees
-
#13
POP3://[email protected]:0 2 employees
-
#14
freemail.hu 2 employees
-
#15
iu.edu 2 employees
-
#16
ftp://192.168.0.2 2 employees
-
#17
tu.ac.th 2 employees
-
#18
unitbv.ro 2 employees
-
#19
rediris.es 2 employees
-
#20
arcor.de 1 employees
-
#21
helicon.nl 1 employees
-
#22
orange.es 1 employees
-
#23
idcollege.nl 1 employees
-
#24
ftp://110.4.45.47/ 1 employees
-
#25
POP3://mail.concesionariosac.com:0 1 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
pepsico.com 1 employees
-
#2
rockwellautomation.com 1 employees
-
#3
oracle.com 1 employees
Compromised users
-
#1
google.com 468 users
-
#2
facebook.com 388 users
-
#3
amazon.com 93 users
-
#4
netflix.com 91 users
-
#5
paypal.com 90 users
-
#6
apple.com 64 users
-
#7
ebay.com 31 users
-
#8
oracle.com 11 users
-
#9
salesforce.com 6 users
-
#10
hp.com 5 users
-
#11
microsoft.com 3 users
-
#12
ups.com 3 users
-
#13
westernunion.com 2 users
-
#14
regions.com 2 users
-
#15
aecom.com 1 users
-
#16
fisglobal.com 1 users
-
#17
verizon.com 1 users
-
#18
marriott.com 1 users
-
#19
ralphlauren.com 1 users
-
#20
americanexpress.com 1 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 763hits
- #2 sso 247hits
- #3 imap 131hits
- #4 ftp 51hits
- #5 webmail 44hits
- #6 adfs 32hits
- #7 github 29hits
- #8 kaspersky 25hits
- #9 oracle 21hits
- #10 sap 19hits
- #11 roundcube 19hits
- #12 okta 14hits
- #13 salesforce 12hits
- #14 cpanel 10hits
- #15 sts 10hits
- #16 vpn 9hits
- #17 extranet 9hits
- #18 zendesk 9hits
- #19 owa 8hits
- #20 zoom 7hits
- #21 dana-na 5hits
- #22 jira 4hits
- #23 bitbucket 4hits
- #24 citrix 4hits
- #25 cscoe 3hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains