Infostealers Weekly Report: 2019-09-30 – 2019-10-06
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 463
- #2 Indonesia 291
- #3 Germany 244
- #4 India 212
- #5 France 184
- #6 Brazil 164
- #7 United States of America 157
- #8 United Kingdom 134
- #9 Spain 126
- #10 Canada 119
- #11 Pakistan 69
- #12 Poland 64
- #13 Turkey 60
- #14 Philippines 58
- #15 Bangladesh 58
- #16 Australia 52
- #17 Malaysia 43
- #18 South Africa 37
- #19 Thailand 31
- #20 Egypt 29
- #21 Italy 26
- #22 Portugal 24
- #23 Nepal 22
- #24 Sri Lanka 22
- #25 South Korea 20
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 1,989 users
-
#2
facebook.com 1,704 users
-
#3
live.com 988 users
-
#4
twitter.com 485 users
-
#5
paypal.com 472 users
-
#6
netflix.com 397 users
-
#7
yahoo.com 355 users
-
#8
354 users
-
#9
discordapp.com 351 users
-
#10
roblox.com 346 users
-
#11
amazon.com 316 users
-
#12
mega.nz 308 users
-
#13
instagram.com 304 users
-
#14
steampowered.com 296 users
-
#15
epicgames.com 293 users
-
#16
twitch.tv 291 users
-
#17
steamcommunity.com 273 users
-
#18
linkedin.com 254 users
-
#19
apple.com 249 users
-
#20
dropbox.com 230 users
-
#21
minecraft.net 222 users
-
#22
com.facebook.katana 212 users
-
#23
sonyentertainmentnetwork.com 194 users
-
#24
192.168.1.1 182 users
-
#25
spotify.com 179 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 11 employees
-
#2
confused.com 9 employees
-
#3
POP3://[email protected]:0 8 employees
-
#4
freenet.de 8 employees
-
#5
POP3://[email protected]:0 8 employees
-
#6
gwdg.de 7 employees
-
#7
secureserver.net 7 employees
-
#8
rediris.es 7 employees
-
#9
strato.com 7 employees
-
#10
interia.pl 7 employees
-
#11
6 employees
-
#12
o2.pl 6 employees
-
#13
iu.edu 6 employees
-
#14
heanet.ie 6 employees
-
#15
mail.de 5 employees
-
#16
icicibank.com 5 employees
-
#17
ig.com.br 5 employees
-
#18
onet.pl 5 employees
-
#19
ocb.com.vn 5 employees
-
#20
rediff.com 4 employees
-
#21
accenture.com 4 employees
-
#22
ovh.net 4 employees
-
#23
POP3://192.168.1.1:0 4 employees
-
#24
plus.net 4 employees
-
#25
POP3://pop.videotron.ca:0 3 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 2 employees
-
#2
netflix.com 1 employees
-
#3
microsoft.com 1 employees
-
#4
apple.com 1 employees
-
#5
johnsoncontrols.com 1 employees
-
#6
cognizant.com 1 employees
Compromised users
-
#1
google.com 1,989 users
-
#2
facebook.com 1,704 users
-
#3
paypal.com 472 users
-
#4
netflix.com 397 users
-
#5
amazon.com 316 users
-
#6
apple.com 249 users
-
#7
ebay.com 126 users
-
#8
oracle.com 30 users
-
#9
hp.com 23 users
-
#10
nike.com 19 users
-
#11
microsoft.com 18 users
-
#12
walmart.com 17 users
-
#13
ups.com 17 users
-
#14
att.com 16 users
-
#15
capitalone.com 15 users
-
#16
westernunion.com 11 users
-
#17
adp.com 10 users
-
#18
ibm.com 8 users
-
#19
wellsfargo.com 8 users
-
#20
visa.com 7 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 2,372hits
- #2 sso 1,090hits
- #3 imap 406hits
- #4 webmail 255hits
- #5 adfs 151hits
- #6 github 126hits
- #7 ftp 122hits
- #8 owa 99hits
- #9 zendesk 86hits
- #10 oracle 74hits
- #11 st 49hits
- #12 cpanel 44hits
- #13 sts 43hits
- #14 vpn 31hits
- #15 kaspersky 30hits
- #16 zoom 24hits
- #17 extranet 23hits
- #18 ping 23hits
- #19 sap 22hits
- #20 zimbra 22hits
- #21 roundcube 14hits
- #22 citrix 13hits
- #23 bitbucket 12hits
- #24 okta 12hits
- #25 salesforce 8hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains