Infostealers Weekly Report: 2019-09-02 – 2019-09-08
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 655
- #2 India 498
- #3 Indonesia 445
- #4 Germany 359
- #5 United States of America 255
- #6 Canada 144
- #7 Italy 119
- #8 Philippines 117
- #9 United Kingdom 105
- #10 Pakistan 103
- #11 Bangladesh 96
- #12 Algeria 91
- #13 Egypt 75
- #14 Thailand 60
- #15 Poland 51
- #16 Nigeria 51
- #17 Turkey 47
- #18 Romania 47
- #19 Peru 37
- #20 Argentina 36
- #21 Vietnam 36
- #22 Morocco 36
- #23 France 35
- #24 Netherlands 33
- #25 Nepal 31
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 2,583 users
-
#2
facebook.com 2,176 users
-
#3
live.com 1,397 users
-
#4
twitter.com 682 users
-
#5
netflix.com 623 users
-
#6
paypal.com 572 users
-
#7
548 users
-
#8
yahoo.com 530 users
-
#9
instagram.com 476 users
-
#10
amazon.com 470 users
-
#11
mega.nz 439 users
-
#12
discordapp.com 425 users
-
#13
epicgames.com 414 users
-
#14
linkedin.com 376 users
-
#15
roblox.com 376 users
-
#16
dropbox.com 370 users
-
#17
twitch.tv 347 users
-
#18
steampowered.com 343 users
-
#19
apple.com 331 users
-
#20
steamcommunity.com 318 users
-
#21
192.168.1.1 289 users
-
#22
com.facebook.katana 282 users
-
#23
com.netflix.mediaclient 281 users
-
#24
sonyentertainmentnetwork.com 254 users
-
#25
chrome://FirefoxAccounts 244 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
icicibank.com 16 employees
-
#2
rediff.com 15 employees
-
#3
POP3://pop.gmail.com:995 13 employees
-
#4
aruba.it 9 employees
-
#5
digimail.in 8 employees
-
#6
secureserver.net 7 employees
-
#7
freemail.hu 7 employees
-
#8
freenet.de 7 employees
-
#9
6 employees
-
#10
interia.pl 6 employees
-
#11
tim.it 6 employees
-
#12
sempreser.com.br 6 employees
-
#13
pec.it 6 employees
-
#14
accenture.com 5 employees
-
#15
abv.bg 5 employees
-
#16
o2.pl 5 employees
-
#17
ig.com.br 5 employees
-
#18
hostgator.com.br 5 employees
-
#19
iu.edu 4 employees
-
#20
idbibank.co.in 4 employees
-
#21
dpcdsb.org 4 employees
-
#22
netpnb.com 4 employees
-
#23
publix.com 4 employees
-
#24
POP3://[email protected]:0 4 employees
-
#25
telus.net 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 4 employees
-
#2
twc.com 2 employees
-
#3
mosaicco.com 1 employees
-
#4
netflix.com 1 employees
-
#5
att.com 1 employees
-
#6
paypal.com 1 employees
-
#7
jacobs.com 1 employees
-
#8
cognizant.com 1 employees
-
#9
celgene.com 1 employees
-
#10
bestbuy.com 1 employees
-
#11
starbucks.com 1 employees
Compromised users
-
#1
google.com 2,582 users
-
#2
facebook.com 2,175 users
-
#3
netflix.com 623 users
-
#4
paypal.com 572 users
-
#5
amazon.com 470 users
-
#6
apple.com 331 users
-
#7
ebay.com 183 users
-
#8
oracle.com 49 users
-
#9
walmart.com 33 users
-
#10
hp.com 29 users
-
#11
ups.com 24 users
-
#12
adp.com 22 users
-
#13
americanexpress.com 22 users
-
#14
capitalone.com 20 users
-
#15
att.com 20 users
-
#16
cisco.com 18 users
-
#17
bestbuy.com 17 users
-
#18
westernunion.com 16 users
-
#19
bankofamerica.com 15 users
-
#20
wellsfargo.com 14 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,296hits
- #2 sso 1,394hits
- #3 webmail 469hits
- #4 imap 423hits
- #5 adfs 243hits
- #6 ftp 201hits
- #7 github 148hits
- #8 owa 131hits
- #9 oracle 115hits
- #10 sap 99hits
- #11 cpanel 95hits
- #12 zendesk 88hits
- #13 sts 64hits
- #14 st 52hits
- #15 kaspersky 45hits
- #16 extranet 44hits
- #17 vpn 30hits
- #18 ping 30hits
- #19 zimbra 28hits
- #20 zoom 27hits
- #21 gitlab 12hits
- #22 bitbucket 12hits
- #23 webex 12hits
- #24 dana-na 12hits
- #25 jira 9hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains