Infostealers Weekly Report: 2019-12-16 – 2019-12-22
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Vietnam 850
- #2 Indonesia 700
- #3 Turkey 658
- #4 Brazil 466
- #5 Egypt 422
- #6 Pakistan 414
- #7 India 413
- #8 Thailand 266
- #9 Bangladesh 215
- #10 Philippines 211
- #11 Romania 197
- #12 Algeria 191
- #13 Morocco 141
- #14 Argentina 138
- #15 Malaysia 131
- #16 United States of America 116
- #17 Sri Lanka 103
- #18 Nepal 95
- #19 Serbia 94
- #20 Hungary 93
- #21 Peru 85
- #22 Italy 78
- #23 United Arab Emirates 66
- #24 Chile 66
- #25 South Africa 65
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 5,067 users
-
#2
facebook.com 3,903 users
-
#3
live.com 2,246 users
-
#4
twitter.com 1,177 users
-
#5
roblox.com 1,041 users
-
#6
yahoo.com 974 users
-
#7
mega.nz 951 users
-
#8
instagram.com 866 users
-
#9
netflix.com 836 users
-
#10
discordapp.com 814 users
-
#11
com.facebook.katana 751 users
-
#12
192.168.1.1 740 users
-
#13
steampowered.com 692 users
-
#14
paypal.com 681 users
-
#15
epicgames.com 641 users
-
#16
linkedin.com 621 users
-
#17
amazon.com 584 users
-
#18
apple.com 528 users
-
#19
twitch.tv 520 users
-
#20
steamcommunity.com 513 users
-
#21
minecraft.net 471 users
-
#22
garena.com 420 users
-
#23
dropbox.com 420 users
-
#24
396 users
-
#25
192.168.0.1 346 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
yandex.com.tr 17 employees
-
#2
abv.bg 14 employees
-
#3
freemail.hu 14 employees
-
#4
telecom.pt 10 employees
-
#5
mail.bg 9 employees
-
#6
rediff.com 7 employees
-
#7
globo.com 7 employees
-
#8
nbg.gr 7 employees
-
#9
icicibank.com 7 employees
-
#10
tim.it 6 employees
-
#11
secureserver.net 6 employees
-
#12
sapo.pt 6 employees
-
#13
mail.com.tr 6 employees
-
#14
http://localhost/wordpress/wp-admin/install.php 6 employees
-
#15
ig.com.br 6 employees
-
#16
bex.net 5 employees
-
#17
accenture.com 5 employees
-
#18
digimail.in 5 employees
-
#19
citromail.hu 5 employees
-
#20
isacombank.com.vn 4 employees
-
#21
sempreser.com.br 4 employees
-
#22
cpmail.in.th 4 employees
-
#23
usat.edu.pe 4 employees
-
#24
bni.co.id 4 employees
-
#25
rediffmailpro.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
emc.com 1 employees
-
#2
nov.com 1 employees
-
#3
cisco.com 1 employees
-
#4
ibm.com 1 employees
Compromised users
-
#1
google.com 5,066 users
-
#2
facebook.com 3,902 users
-
#3
netflix.com 836 users
-
#4
paypal.com 681 users
-
#5
amazon.com 583 users
-
#6
apple.com 528 users
-
#7
ebay.com 222 users
-
#8
oracle.com 80 users
-
#9
hp.com 34 users
-
#10
walmart.com 29 users
-
#11
microsoft.com 29 users
-
#12
cisco.com 24 users
-
#13
ups.com 16 users
-
#14
att.com 15 users
-
#15
intel.com 14 users
-
#16
fedex.com 12 users
-
#17
westernunion.com 11 users
-
#18
nike.com 11 users
-
#19
salesforce.com 10 users
-
#20
bestbuy.com 10 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 5,164hits
- #2 sso 2,570hits
- #3 webmail 357hits
- #4 adfs 226hits
- #5 github 193hits
- #6 oracle 183hits
- #7 owa 179hits
- #8 cpanel 129hits
- #9 sap 112hits
- #10 sts 97hits
- #11 st 83hits
- #12 zendesk 83hits
- #13 ftp 80hits
- #14 vpn 65hits
- #15 ping 63hits
- #16 zoom 44hits
- #17 kaspersky 35hits
- #18 extranet 33hits
- #19 gitlab 27hits
- #20 salesforce 27hits
- #21 roundcube 19hits
- #22 citrix 18hits
- #23 twilio 14hits
- #24 bitbucket 13hits
- #25 webex 11hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains