Infostealers Weekly Report: 2019-11-25 – 2019-12-01
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 97
- #2 Germany 25
- #3 Spain 21
- #4 Venezuela 11
- #5 Belgium 10
- #6 Morocco 10
- #7 Saudi Arabia 7
- #8 Egypt 6
- #9 Turkey 5
- #10 Switzerland 5
- #11 Sweden 4
- #12 Thailand 4
- #13 Brazil 4
- #14 Indonesia 4
- #15 Bangladesh 3
- #16 Czechia 3
- #17 Canada 3
- #18 Philippines 3
- #19 United Kingdom 2
- #20 Gambia 2
- #21 Greece 2
- #22 South Africa 2
- #23 Nigeria 2
- #24 United States of America 2
- #25 India 2
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 244 users
-
#2
facebook.com 223 users
-
#3
live.com 144 users
-
#4
paypal.com 130 users
-
#5
twitter.com 87 users
-
#6
netflix.com 74 users
-
#7
amazon.com 74 users
-
#8
discordapp.com 67 users
-
#9
instagram.com 66 users
-
#10
dropbox.com 65 users
-
#11
twitch.tv 62 users
-
#12
57 users
-
#13
epicgames.com 56 users
-
#14
aliexpress.com 55 users
-
#15
steampowered.com 54 users
-
#16
steamcommunity.com 52 users
-
#17
yahoo.com 49 users
-
#18
minecraft.net 48 users
-
#19
ebay.com 47 users
-
#20
apple.com 46 users
-
#21
mega.nz 45 users
-
#22
com.facebook.katana 44 users
-
#23
linkedin.com 39 users
-
#24
spotify.com 37 users
-
#25
ea.com 36 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
taqat.sa 7 employees
-
#2
ksu.edu.sa 7 employees
-
#3
fhws.de 4 employees
-
#4
nbg.gr 2 employees
-
#5
icnex.com 2 employees
-
#6
emailemnuvem.com.br 2 employees
-
#7
secureserver.net 2 employees
-
#8
bpost.be 2 employees
-
#9
sebrae.com.br 2 employees
-
#10
ombudsman.gm 2 employees
-
#11
grupompleo.com 1 employees
-
#12
dargiv-construct.com 1 employees
-
#13
asuscomm.com 1 employees
-
#14
tyfon.net 1 employees
-
#15
hoasenholdings.vn 1 employees
-
#16
altengroup.com 1 employees
-
#17
ftp://localhost/ 1 employees
-
#18
ovh.com 1 employees
-
#19
sausd.us 1 employees
-
#20
vse.cz 1 employees
-
#21
uva.es 1 employees
-
#22
POP3://pop.gmail.com:995 1 employees
-
#23
mail.de 1 employees
-
#24
bacninh.gov.vn 1 employees
-
#25
eunet.rs 1 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
pg.com 1 employees
Compromised users
-
#1
google.com 244 users
-
#2
facebook.com 223 users
-
#3
paypal.com 130 users
-
#4
amazon.com 74 users
-
#5
netflix.com 74 users
-
#6
ebay.com 47 users
-
#7
apple.com 46 users
-
#8
walmart.com 13 users
-
#9
ups.com 8 users
-
#10
target.com 7 users
-
#11
westernunion.com 7 users
-
#12
att.com 6 users
-
#13
bestbuy.com 6 users
-
#14
wellsfargo.com 5 users
-
#15
microsoft.com 5 users
-
#16
nike.com 5 users
-
#17
americanexpress.com 5 users
-
#18
hp.com 4 users
-
#19
capitalone.com 4 users
-
#20
fedex.com 4 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 629hits
- #2 sso 262hits
- #3 webmail 68hits
- #4 imap 53hits
- #5 owa 50hits
- #6 sap 50hits
- #7 adfs 35hits
- #8 github 25hits
- #9 ftp 20hits
- #10 zendesk 16hits
- #11 cpanel 15hits
- #12 sts 14hits
- #13 st 13hits
- #14 zoom 10hits
- #15 kaspersky 9hits
- #16 oracle 9hits
- #17 okta 6hits
- #18 dana-na 5hits
- #19 extranet 4hits
- #20 vpn 2hits
- #21 cscoe 1hits
- #22 ping 1hits
- #23 hipchat 1hits
- #24 gitlab 1hits
- #25 bitbucket 1hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains