Infostealers Weekly Report: 2022-11-21 – 2022-11-27
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 8,562
- #2 Egypt 7,383
- #3 India 7,370
- #4 Indonesia 5,804
- #5 Pakistan 4,184
- #6 Algeria 4,009
- #7 Philippines 3,709
- #8 Mexico 3,434
- #9 Spain 3,250
- #10 Vietnam 3,223
- #11 Morocco 3,100
- #12 Argentina 2,903
- #13 Poland 2,850
- #14 Colombia 2,815
- #15 Peru 2,737
- #16 United States of America 2,589
- #17 Thailand 2,345
- #18 Turkey 2,340
- #19 Venezuela 1,976
- #20 Italy 1,939
- #21 Bangladesh 1,870
- #22 Germany 1,566
- #23 France 1,556
- #24 Ecuador 1,491
- #25 Chile 1,486
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 47,608 users
-
#2
facebook.com 43,573 users
-
#3
live.com 37,640 users
-
#4
instagram.com 19,428 users
-
#5
com.facebook.katana 18,383 users
-
#6
netflix.com 17,761 users
-
#7
discord.com 17,675 users
-
#8
roblox.com 15,522 users
-
#9
twitter.com 15,241 users
-
#10
amazon.com 14,716 users
-
#11
steampowered.com 13,010 users
-
#12
paypal.com 13,005 users
-
#13
com.instagram.android 12,423 users
-
#14
microsoftonline.com 11,971 users
-
#15
twitch.tv 11,784 users
-
#16
com.netflix.mediaclient 11,454 users
-
#17
mega.nz 11,348 users
-
#18
riotgames.com 10,357 users
-
#19
linkedin.com 9,915 users
-
#20
epicgames.com 9,799 users
-
#21
com.spotify.music 9,341 users
-
#22
apple.com 9,006 users
-
#23
spotify.com 8,852 users
-
#24
steamcommunity.com 8,820 users
-
#25
com.discord 8,392 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 342 employees
-
#2
aruba.it 173 employees
-
#3
icicibank.com 160 employees
-
#4
o2.pl 149 employees
-
#5
tim.it 132 employees
-
#6
pec.it 127 employees
-
#7
163.com 125 employees
-
#8
freemail.hu 123 employees
-
#9
abv.bg 115 employees
-
#10
hostinger.com 114 employees
-
#11
interia.pl 112 employees
-
#12
onet.pl 109 employees
-
#13
rediff.com 93 employees
-
#14
laureate.net 87 employees
-
#15
jwpub.org 83 employees
-
#16
qq.com 83 employees
-
#17
skole.hr 77 employees
-
#18
rockwellautomation.com 76 employees
-
#19
bcb.gov.br 74 employees
-
#20
buenosaires.gob.ar 69 employees
-
#21
utp.edu.pe 67 employees
-
#22
inacap.cl 64 employees
-
#23
accenture.com 58 employees
-
#24
secureserver.net 57 employees
-
#25
ovh.net 56 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 76 employees
-
#2
microsoft.com 45 employees
-
#3
facebook.com 14 employees
-
#4
netflix.com 11 employees
-
#5
publix.com 8 employees
-
#6
ford.com 6 employees
-
#7
oracle.com 5 employees
-
#8
google.com 5 employees
-
#9
harman.com 5 employees
-
#10
ups.com 4 employees
-
#11
tenethealth.com 4 employees
-
#12
henryschein.com 3 employees
-
#13
disney.com 3 employees
-
#14
borgwarner.com 3 employees
-
#15
amazon.com 2 employees
-
#16
ibm.com 2 employees
-
#17
hp.com 2 employees
-
#18
gm.com 2 employees
-
#19
jetblue.com 2 employees
-
#20
cognizant.com 2 employees
Compromised users
-
#1
google.com 47,608 users
-
#2
facebook.com 43,573 users
-
#3
netflix.com 17,761 users
-
#4
amazon.com 14,716 users
-
#5
paypal.com 13,005 users
-
#6
apple.com 9,006 users
-
#7
ebay.com 2,293 users
-
#8
oracle.com 1,555 users
-
#9
microsoft.com 1,294 users
-
#10
cisco.com 1,282 users
-
#11
hp.com 1,280 users
-
#12
nike.com 1,134 users
-
#13
walmart.com 551 users
-
#14
ibm.com 516 users
-
#15
ups.com 468 users
-
#16
westernunion.com 378 users
-
#17
intel.com 369 users
-
#18
bestbuy.com 245 users
-
#19
fedex.com 228 users
-
#20
adp.com 227 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 143,104hits
- #2 sso 40,541hits
- #3 zoom 16,446hits
- #4 github 6,288hits
- #5 webmail 5,639hits
- #6 adfs 5,069hits
- #7 oracle 2,906hits
- #8 zendesk 2,032hits
- #9 sap 1,891hits
- #10 owa 1,840hits
- #11 vpn 1,622hits
- #12 ping 1,591hits
- #13 sts 1,497hits
- #14 cpanel 1,488hits
- #15 webex 1,263hits
- #16 ftp 1,068hits
- #17 kaspersky 1,036hits
- #18 extranet 977hits
- #19 st 934hits
- #20 roundcube 846hits
- #21 salesforce 610hits
- #22 okta 522hits
- #23 gitlab 420hits
- #24 twilio 371hits
- #25 zimbra 238hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains