Infostealers Weekly Report: 2019-08-19 – 2019-08-25
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 3,550
- #2 Indonesia 1,038
- #3 United States of America 289
- #4 South Africa 261
- #5 Thailand 233
- #6 Philippines 197
- #7 South Korea 79
- #8 Malaysia 73
- #9 Venezuela 52
- #10 Uruguay 48
- #11 Hungary 27
- #12 Yemen 26
- #13 Romania 25
- #14 Mongolia 23
- #15 Pakistan 22
- #16 India 21
- #17 Brazil 18
- #18 Singapore 18
- #19 Serbia 17
- #20 Portugal 17
- #21 Zimbabwe 16
- #22 Bulgaria 13
- #23 Egypt 11
- #24 Algeria 10
- #25 Argentina 9
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,304 users
-
#2
facebook.com 3,469 users
-
#3
live.com 1,117 users
-
#4
garena.com 817 users
-
#5
zing.vn 703 users
-
#6
yahoo.com 702 users
-
#7
roblox.com 633 users
-
#8
twitter.com 546 users
-
#9
zalo.me 506 users
-
#10
com.facebook.katana 465 users
-
#11
360game.vn 446 users
-
#12
vtcmobile.vn 435 users
-
#13
instagram.com 426 users
-
#14
shopee.vn 421 users
-
#15
mega.nz 417 users
-
#16
discordapp.com 410 users
-
#17
390 users
-
#18
apple.com 366 users
-
#19
192.168.1.1 342 users
-
#20
minecraft.net 280 users
-
#21
lazada.vn 276 users
-
#22
violet.vn 274 users
-
#23
linkedin.com 272 users
-
#24
vtcgame.vn 267 users
-
#25
steampowered.com 264 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
isacombank.com.vn 23 employees
-
#2
hust.edu.vn 13 employees
-
#3
POP3://[email protected]:0 9 employees
-
#4
SMTP://mail.ddec.com.vn:0 9 employees
-
#5
fecredit.com.vn 9 employees
-
#6
POP3://mail.ddec.com.vn:0 9 employees
-
#7
POP3://[email protected]:0 9 employees
-
#8
heanet.ie 7 employees
-
#9
iu.edu 7 employees
-
#10
techcombank.com.vn 7 employees
-
#11
POP3://pop.gmail.com:995 7 employees
-
#12
viettel.com.vn 7 employees
-
#13
rediris.es 7 employees
-
#14
fpt.com.vn 7 employees
-
#15
gwdg.de 7 employees
-
#16
uct.ac.za 6 employees
-
#17
telkomsa.net 6 employees
-
#18
webmail.co.za 6 employees
-
#19
6 employees
-
#20
enteos.it 6 employees
-
#21
tphcm.gov.vn 5 employees
-
#22
phutho.gov.vn 4 employees
-
#23
ftp://10.33.41.35 4 employees
-
#24
vietjetair.com 4 employees
-
#25
telkomakses.co.id 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
twc.com 2 employees
-
#2
netflix.com 2 employees
-
#3
csc.com 2 employees
-
#4
publix.com 1 employees
-
#5
staples.com 1 employees
-
#6
rockwellautomation.com 1 employees
-
#7
textron.com 1 employees
Compromised users
-
#1
google.com 4,304 users
-
#2
facebook.com 3,469 users
-
#3
apple.com 366 users
-
#4
netflix.com 224 users
-
#5
paypal.com 222 users
-
#6
amazon.com 217 users
-
#7
ebay.com 64 users
-
#8
oracle.com 23 users
-
#9
microsoft.com 15 users
-
#10
nike.com 13 users
-
#11
walmart.com 9 users
-
#12
cisco.com 9 users
-
#13
ups.com 9 users
-
#14
hp.com 7 users
-
#15
ibm.com 7 users
-
#16
att.com 5 users
-
#17
fedex.com 4 users
-
#18
symantec.com 3 users
-
#19
adp.com 3 users
-
#20
homedepot.com 3 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,236hits
- #2 sso 2,946hits
- #3 webmail 193hits
- #4 owa 164hits
- #5 adfs 162hits
- #6 cpanel 146hits
- #7 imap 118hits
- #8 sap 99hits
- #9 github 97hits
- #10 ftp 91hits
- #11 oracle 47hits
- #12 kaspersky 47hits
- #13 zendesk 38hits
- #14 sts 33hits
- #15 ping 24hits
- #16 roundcube 23hits
- #17 zoom 21hits
- #18 st 20hits
- #19 vpn 18hits
- #20 webex 14hits
- #21 citrix 12hits
- #22 zimbra 10hits
- #23 jira 8hits
- #24 dana-na 7hits
- #25 bitbucket 6hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains