Infostealers Weekly Report: 2019-11-04 – 2019-11-10
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 849
- #2 India 802
- #3 Vietnam 648
- #4 Turkey 385
- #5 Egypt 337
- #6 Thailand 301
- #7 Pakistan 274
- #8 Brazil 267
- #9 Bangladesh 193
- #10 Philippines 167
- #11 Romania 156
- #12 Germany 134
- #13 Algeria 127
- #14 Malaysia 115
- #15 South Korea 110
- #16 Hungary 106
- #17 United Kingdom 93
- #18 Mexico 88
- #19 Morocco 85
- #20 Portugal 74
- #21 Peru 74
- #22 South Africa 72
- #23 Serbia 68
- #24 Nepal 67
- #25 Iran 64
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,895 users
-
#2
facebook.com 3,726 users
-
#3
live.com 2,404 users
-
#4
twitter.com 1,181 users
-
#5
1,070 users
-
#6
yahoo.com 959 users
-
#7
mega.nz 913 users
-
#8
netflix.com 866 users
-
#9
instagram.com 853 users
-
#10
linkedin.com 773 users
-
#11
paypal.com 756 users
-
#12
amazon.com 649 users
-
#13
discordapp.com 618 users
-
#14
192.168.1.1 547 users
-
#15
dropbox.com 538 users
-
#16
apple.com 531 users
-
#17
steampowered.com 528 users
-
#18
roblox.com 507 users
-
#19
epicgames.com 463 users
-
#20
twitch.tv 457 users
-
#21
adobe.com 428 users
-
#22
steamcommunity.com 403 users
-
#23
firefox.com 349 users
-
#24
ea.com 323 users
-
#25
ul 310 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
24 employees
-
#2
icicibank.com 19 employees
-
#3
rediff.com 17 employees
-
#4
freemail.hu 17 employees
-
#5
secureserver.net 15 employees
-
#6
digimail.in 13 employees
-
#7
accenture.com 12 employees
-
#8
gwdg.de 10 employees
-
#9
heanet.ie 10 employees
-
#10
rediris.es 10 employees
-
#11
iu.edu 10 employees
-
#12
POP3://pop.gmail.com:995 9 employees
-
#13
mail.bg 8 employees
-
#14
POP3://[email protected]:0 8 employees
-
#15
POP3://[email protected]:0 8 employees
-
#16
interia.pl 8 employees
-
#17
o2.pl 7 employees
-
#18
nbg.gr 7 employees
-
#19
isacombank.com.vn 7 employees
-
#20
telecom.pt 6 employees
-
#21
ig.com.br 6 employees
-
#22
sapo.pt 6 employees
-
#23
ktmb.com.my 6 employees
-
#24
onlinesbi.com 6 employees
-
#25
taqat.sa 5 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 3 employees
-
#2
microsoft.com 2 employees
-
#3
oxy.com 1 employees
-
#4
hp.com 1 employees
-
#5
starwoodhotels.com 1 employees
-
#6
assurant.com 1 employees
-
#7
marriott.com 1 employees
-
#8
techdata.com 1 employees
-
#9
netflix.com 1 employees
-
#10
visteon.com 1 employees
-
#11
johnsoncontrols.com 1 employees
Compromised users
-
#1
google.com 4,894 users
-
#2
facebook.com 3,726 users
-
#3
netflix.com 866 users
-
#4
paypal.com 756 users
-
#5
amazon.com 649 users
-
#6
apple.com 531 users
-
#7
ebay.com 238 users
-
#8
oracle.com 114 users
-
#9
hp.com 43 users
-
#10
cisco.com 43 users
-
#11
microsoft.com 32 users
-
#12
ibm.com 28 users
-
#13
ups.com 17 users
-
#14
salesforce.com 15 users
-
#15
westernunion.com 14 users
-
#16
intel.com 13 users
-
#17
americanexpress.com 11 users
-
#18
walmart.com 11 users
-
#19
visa.com 10 users
-
#20
nike.com 8 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 6,844hits
- #2 sso 2,800hits
- #3 webmail 558hits
- #4 owa 367hits
- #5 adfs 322hits
- #6 oracle 280hits
- #7 imap 271hits
- #8 github 257hits
- #9 cpanel 175hits
- #10 ftp 167hits
- #11 sap 148hits
- #12 zendesk 141hits
- #13 sts 120hits
- #14 ping 102hits
- #15 st 85hits
- #16 kaspersky 84hits
- #17 extranet 53hits
- #18 roundcube 43hits
- #19 vpn 37hits
- #20 gitlab 33hits
- #21 salesforce 32hits
- #22 zimbra 28hits
- #23 webex 24hits
- #24 jira 23hits
- #25 bitbucket 21hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains