Infostealers Weekly Report: 2019-11-11 – 2019-11-17
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 968
- #2 India 884
- #3 Brazil 666
- #4 Pakistan 423
- #5 Vietnam 339
- #6 Mexico 223
- #7 Spain 215
- #8 Philippines 205
- #9 Romania 194
- #10 Argentina 194
- #11 Bangladesh 184
- #12 Colombia 183
- #13 Italy 172
- #14 Morocco 168
- #15 Poland 157
- #16 Hungary 130
- #17 Chile 121
- #18 Peru 116
- #19 South Korea 108
- #20 France 93
- #21 Serbia 92
- #22 United Arab Emirates 91
- #23 Germany 89
- #24 Canada 79
- #25 Portugal 79
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,073 users
-
#2
facebook.com 3,818 users
-
#3
live.com 2,573 users
-
#4
twitter.com 1,327 users
-
#5
mega.nz 1,113 users
-
#6
netflix.com 1,045 users
-
#7
1,028 users
-
#8
paypal.com 990 users
-
#9
instagram.com 944 users
-
#10
yahoo.com 896 users
-
#11
discordapp.com 825 users
-
#12
amazon.com 793 users
-
#13
com.facebook.katana 774 users
-
#14
linkedin.com 764 users
-
#15
steampowered.com 732 users
-
#16
epicgames.com 726 users
-
#17
roblox.com 703 users
-
#18
dropbox.com 627 users
-
#19
twitch.tv 618 users
-
#20
steamcommunity.com 601 users
-
#21
apple.com 567 users
-
#22
192.168.1.1 509 users
-
#23
com.netflix.mediaclient 476 users
-
#24
aliexpress.com 456 users
-
#25
minecraft.net 451 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 30 employees
-
#2
enteos.it 29 employees
-
#3
freemail.hu 24 employees
-
#4
POP3://pop.gmail.com:995 24 employees
-
#5
icicibank.com 23 employees
-
#6
rediris.es 22 employees
-
#7
heanet.ie 22 employees
-
#8
iu.edu 22 employees
-
#9
gwdg.de 22 employees
-
#10
o2.pl 20 employees
-
#11
interia.pl 17 employees
-
#12
16 employees
-
#13
abv.bg 15 employees
-
#14
POP3://[email protected]:0 15 employees
-
#15
tim.it 15 employees
-
#16
POP3://[email protected]:0 15 employees
-
#17
onlinesbi.com 11 employees
-
#18
onet.pl 10 employees
-
#19
telecom.pt 10 employees
-
#20
citromail.hu 10 employees
-
#21
digimail.in 10 employees
-
#22
aruba.it 9 employees
-
#23
bni.co.id 8 employees
-
#24
secureserver.net 8 employees
-
#25
POP3://pop.mail.yahoo.com:995 7 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 5 employees
-
#2
netflix.com 4 employees
-
#3
sanmina.com 1 employees
-
#4
pg.com 1 employees
-
#5
johnsoncontrols.com 1 employees
-
#6
rockwellautomation.com 1 employees
-
#7
amazon.com 1 employees
Compromised users
-
#1
google.com 5,073 users
-
#2
facebook.com 3,818 users
-
#3
netflix.com 1,045 users
-
#4
paypal.com 990 users
-
#5
amazon.com 793 users
-
#6
apple.com 567 users
-
#7
ebay.com 311 users
-
#8
oracle.com 94 users
-
#9
hp.com 48 users
-
#10
microsoft.com 31 users
-
#11
ups.com 27 users
-
#12
walmart.com 26 users
-
#13
ibm.com 26 users
-
#14
cisco.com 22 users
-
#15
nike.com 19 users
-
#16
americanexpress.com 19 users
-
#17
intel.com 14 users
-
#18
salesforce.com 13 users
-
#19
westernunion.com 12 users
-
#20
bestbuy.com 9 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 5,968hits
- #2 sso 2,335hits
- #3 imap 608hits
- #4 webmail 554hits
- #5 adfs 269hits
- #6 ftp 251hits
- #7 github 246hits
- #8 sap 212hits
- #9 cpanel 205hits
- #10 oracle 194hits
- #11 owa 190hits
- #12 zendesk 144hits
- #13 sts 121hits
- #14 st 116hits
- #15 kaspersky 87hits
- #16 zoom 86hits
- #17 vpn 84hits
- #18 extranet 74hits
- #19 ping 67hits
- #20 roundcube 41hits
- #21 zimbra 33hits
- #22 salesforce 28hits
- #23 bitbucket 27hits
- #24 webex 23hits
- #25 citrix 21hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains