Infostealers Weekly Report: 2019-09-23 – 2019-09-29
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 726
- #2 India 134
- #3 Turkey 128
- #4 Italy 86
- #5 Brazil 71
- #6 France 63
- #7 Indonesia 63
- #8 Pakistan 62
- #9 Egypt 60
- #10 Spain 59
- #11 South Africa 48
- #12 Germany 47
- #13 Thailand 34
- #14 Algeria 30
- #15 Philippines 26
- #16 Poland 24
- #17 Portugal 24
- #18 Morocco 23
- #19 South Korea 22
- #20 United States of America 21
- #21 United Kingdom 21
- #22 Mexico 20
- #23 Malaysia 18
- #24 Romania 18
- #25 Colombia 18
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,550 users
-
#2
facebook.com 1,236 users
-
#3
live.com 618 users
-
#4
twitter.com 266 users
-
#5
paypal.com 254 users
-
#6
roblox.com 231 users
-
#7
yahoo.com 229 users
-
#8
discordapp.com 214 users
-
#9
208 users
-
#10
instagram.com 197 users
-
#11
mega.nz 194 users
-
#12
garena.com 181 users
-
#13
netflix.com 180 users
-
#14
192.168.1.1 171 users
-
#15
amazon.com 165 users
-
#16
com.facebook.katana 165 users
-
#17
epicgames.com 162 users
-
#18
linkedin.com 162 users
-
#19
zing.vn 159 users
-
#20
apple.com 156 users
-
#21
twitch.tv 149 users
-
#22
steampowered.com 149 users
-
#23
minecraft.net 132 users
-
#24
steamcommunity.com 116 users
-
#25
dropbox.com 114 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 10 employees
-
#2
tim.it 9 employees
-
#3
viettel.com.vn 6 employees
-
#4
icicibank.com 5 employees
-
#5
aruba.it 5 employees
-
#6
isacombank.com.vn 5 employees
-
#7
rediff.com 5 employees
-
#8
POP3://[email protected]:0 4 employees
-
#9
POP3://[email protected]:0 4 employees
-
#10
pec.it 4 employees
-
#11
o2.pl 4 employees
-
#12
4 employees
-
#13
digimail.in 3 employees
-
#14
mail.bg 3 employees
-
#15
freenet.de 3 employees
-
#16
telecom.pt 3 employees
-
#17
easycruit.com 3 employees
-
#18
ua.pt 2 employees
-
#19
unict.it 2 employees
-
#20
seeu.edu.mk 2 employees
-
#21
POP3://pop3.telefonica.net:0 2 employees
-
#22
unionbankonline.co.in 2 employees
-
#23
interia.pl 2 employees
-
#24
POP3://pop.rediffmailpro.com:0 2 employees
-
#25
sigma.net.vn 2 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cummins.com 2 employees
-
#2
nov.com 1 employees
-
#3
cognizant.com 1 employees
-
#4
adm.com 1 employees
-
#5
pg.com 1 employees
-
#6
microsoft.com 1 employees
Compromised users
-
#1
google.com 1,548 users
-
#2
facebook.com 1,235 users
-
#3
paypal.com 254 users
-
#4
netflix.com 180 users
-
#5
amazon.com 165 users
-
#6
apple.com 156 users
-
#7
ebay.com 66 users
-
#8
oracle.com 22 users
-
#9
hp.com 19 users
-
#10
ups.com 12 users
-
#11
microsoft.com 8 users
-
#12
westernunion.com 7 users
-
#13
cisco.com 6 users
-
#14
ibm.com 6 users
-
#15
nike.com 5 users
-
#16
walmart.com 4 users
-
#17
americanexpress.com 4 users
-
#18
southwest.com 2 users
-
#19
bestbuy.com 2 users
-
#20
wellsfargo.com 2 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 1,611hits
- #2 sso 930hits
- #3 imap 171hits
- #4 webmail 157hits
- #5 adfs 80hits
- #6 github 60hits
- #7 owa 57hits
- #8 oracle 47hits
- #9 sap 39hits
- #10 extranet 38hits
- #11 st 28hits
- #12 zendesk 26hits
- #13 ftp 25hits
- #14 zimbra 25hits
- #15 sts 20hits
- #16 vpn 19hits
- #17 cpanel 17hits
- #18 zoom 12hits
- #19 kaspersky 8hits
- #20 ping 7hits
- #21 dana-na 6hits
- #22 roundcube 5hits
- #23 pentaho 5hits
- #24 bitbucket 4hits
- #25 salesforce 4hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains