Infostealers Weekly Report: 2019-08-26 – 2019-09-01
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 177
- #2 Canada 40
- #3 Indonesia 4
- #4 Thailand 3
- #5 Vietnam 3
- #6 Malaysia 2
- #7 Syria 2
- #8 Philippines 2
- #9 Nepal 2
- #10 Colombia 2
- #11 South Korea 2
- #12 Pakistan 2
- #13 Argentina 2
- #14 India 1
- #15 Mexico 1
- #16 Brazil 1
- #17 Mongolia 1
- #18 Bangladesh 1
- #19 Peru 1
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 148 users
-
#2
live.com 112 users
-
#3
facebook.com 104 users
-
#4
amazon.com 61 users
-
#5
twitter.com 59 users
-
#6
netflix.com 58 users
-
#7
paypal.com 56 users
-
#8
roblox.com 48 users
-
#9
yahoo.com 47 users
-
#10
discordapp.com 45 users
-
#11
ebay.com 43 users
-
#12
twitch.tv 41 users
-
#13
apple.com 36 users
-
#14
instagram.com 33 users
-
#15
steampowered.com 32 users
-
#16
steamcommunity.com 31 users
-
#17
microsoftonline.com 31 users
-
#18
epicgames.com 30 users
-
#19
hulu.com 29 users
-
#20
spotify.com 29 users
-
#21
adobe.com 28 users
-
#22
minecraft.net 28 users
-
#23
mega.nz 27 users
-
#24
com.netflix.mediaclient 27 users
-
#25
sonyentertainmentnetwork.com 26 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://[email protected]:0 2 employees
-
#2
secop.gov.co 2 employees
-
#3
publix.com 2 employees
-
#4
2 employees
-
#5
POP3://[email protected]:0 2 employees
-
#6
valentus.com 1 employees
-
#7
perfora.net 1 employees
-
#8
ciplima.org.pe 1 employees
-
#9
imagineschools.com 1 employees
-
#10
darkkittenstudio.com 1 employees
-
#11
lilworlds.ga/ 1 employees
-
#12
SMTP://mail.s-e-n.ca:0 1 employees
-
#13
secureserver.net 1 employees
-
#14
newmarketinc.com 1 employees
-
#15
k12.fl.us 1 employees
-
#16
mohawkcollege.ca 1 employees
-
#17
confused.com 1 employees
-
#18
collierschools.com 1 employees
-
#19
mju.ac.th 1 employees
-
#20
darkkittengames.ga 1 employees
-
#21
ky.gov 1 employees
-
#22
gordon.edu 1 employees
-
#23
clinton.edu 1 employees
-
#24
att.com 1 employees
-
#25
ftp://64.233.156.34/ 1 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 2 employees
-
#2
att.com 1 employees
-
#3
sherwin.com 1 employees
-
#4
rockwellautomation.com 1 employees
Compromised users
-
#1
google.com 148 users
-
#2
facebook.com 104 users
-
#3
amazon.com 61 users
-
#4
netflix.com 58 users
-
#5
paypal.com 56 users
-
#6
ebay.com 43 users
-
#7
apple.com 36 users
-
#8
walmart.com 24 users
-
#9
capitalone.com 19 users
-
#10
wellsfargo.com 11 users
-
#11
adp.com 11 users
-
#12
att.com 11 users
-
#13
ups.com 11 users
-
#14
bestbuy.com 9 users
-
#15
progressive.com 9 users
-
#16
fedex.com 8 users
-
#17
bankofamerica.com 8 users
-
#18
target.com 7 users
-
#19
westernunion.com 6 users
-
#20
hp.com 6 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 420hits
- #2 sso 184hits
- #3 adfs 35hits
- #4 webmail 31hits
- #5 github 26hits
- #6 owa 15hits
- #7 ping 14hits
- #8 zendesk 13hits
- #9 imap 13hits
- #10 sts 12hits
- #11 zoom 12hits
- #12 oracle 11hits
- #13 git 9hits
- #14 ftp 7hits
- #15 sap 6hits
- #16 vpn 6hits
- #17 roundcube 4hits
- #18 gitlab 3hits
- #19 cpanel 2hits
- #20 citrix 2hits
- #21 kaspersky 2hits
- #22 extranet 2hits
- #23 bitbucket 2hits
- #24 dana-na 1hits
- #25 okta 1hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains