Infostealers Weekly Report: 2019-09-09 – 2019-09-15
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 496
- #2 Italy 350
- #3 France 190
- #4 United States of America 179
- #5 Germany 158
- #6 United Kingdom 101
- #7 Netherlands 60
- #8 Nigeria 46
- #9 Canada 27
- #10 Hong Kong SAR China 20
- #11 Spain 18
- #12 Japan 17
- #13 Austria 15
- #14 Australia 11
- #15 India 11
- #16 Philippines 6
- #17 Morocco 5
- #18 Egypt 4
- #19 Vietnam 4
- #20 Belgium 3
- #21 Colombia 3
- #22 Bangladesh 3
- #23 Argentina 3
- #24 Pakistan 3
- #25 Algeria 3
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,182 users
-
#2
facebook.com 1,005 users
-
#3
live.com 873 users
-
#4
paypal.com 449 users
-
#5
netflix.com 420 users
-
#6
twitter.com 396 users
-
#7
308 users
-
#8
amazon.com 294 users
-
#9
mega.nz 276 users
-
#10
twitch.tv 273 users
-
#11
instagram.com 271 users
-
#12
discordapp.com 250 users
-
#13
epicgames.com 234 users
-
#14
apple.com 228 users
-
#15
steampowered.com 224 users
-
#16
ea.com 219 users
-
#17
com.netflix.mediaclient 217 users
-
#18
linkedin.com 215 users
-
#19
steamcommunity.com 208 users
-
#20
yahoo.com 202 users
-
#21
sonyentertainmentnetwork.com 202 users
-
#22
dropbox.com 188 users
-
#23
spotify.com 186 users
-
#24
minecraft.net 185 users
-
#25
roblox.com 177 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
tim.it 23 employees
-
#2
aruba.it 17 employees
-
#3
pec.it 16 employees
-
#4
POP3://in.alice.it:0 10 employees
-
#5
ig.com.br 7 employees
-
#6
confused.com 6 employees
-
#7
ziggo.nl 5 employees
-
#8
freenet.de 5 employees
-
#9
postecert.it 5 employees
-
#10
POP3://pop.gmail.com:995 5 employees
-
#11
landstedegroep.net 4 employees
-
#12
heanet.ie 4 employees
-
#13
postacertificata.gov.it 4 employees
-
#14
4 employees
-
#15
POP3://192.168.241.21:0 4 employees
-
#16
microgame.it 4 employees
-
#17
gwdg.de 4 employees
-
#18
iu.edu 4 employees
-
#19
rediris.es 4 employees
-
#20
globo.com 4 employees
-
#21
uol.com.br 3 employees
-
#22
POP3://email-ssl.com.br:995 3 employees
-
#23
hidemyass.com 3 employees
-
#24
rmunify.com 3 employees
-
#25
fontys.nl 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 1 employees
-
#2
twc.com 1 employees
Compromised users
-
#1
google.com 1,182 users
-
#2
facebook.com 1,005 users
-
#3
paypal.com 449 users
-
#4
netflix.com 420 users
-
#5
amazon.com 294 users
-
#6
apple.com 228 users
-
#7
ebay.com 91 users
-
#8
oracle.com 28 users
-
#9
ups.com 27 users
-
#10
hp.com 19 users
-
#11
adp.com 18 users
-
#12
westernunion.com 15 users
-
#13
microsoft.com 13 users
-
#14
walmart.com 12 users
-
#15
intel.com 11 users
-
#16
capitalone.com 9 users
-
#17
nike.com 9 users
-
#18
americanexpress.com 9 users
-
#19
wellsfargo.com 8 users
-
#20
cisco.com 8 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 2,366hits
- #2 sso 806hits
- #3 imap 424hits
- #4 webmail 310hits
- #5 adfs 178hits
- #6 sts 93hits
- #7 zimbra 81hits
- #8 ftp 77hits
- #9 github 74hits
- #10 owa 74hits
- #11 extranet 73hits
- #12 oracle 73hits
- #13 zendesk 67hits
- #14 cpanel 59hits
- #15 sap 35hits
- #16 vpn 34hits
- #17 kaspersky 32hits
- #18 citrix 26hits
- #19 zoom 24hits
- #20 st 18hits
- #21 roundcube 14hits
- #22 ping 11hits
- #23 dana-na 9hits
- #24 salesforce 9hits
- #25 okta 4hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains