Infostealers Weekly Report: 2022-07-18 – 2022-07-24
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 10,500
- #2 Brazil 6,555
- #3 Indonesia 6,079
- #4 Vietnam 5,304
- #5 United States of America 4,887
- #6 Mexico 3,347
- #7 Egypt 3,278
- #8 Philippines 2,941
- #9 Pakistan 2,808
- #10 Thailand 2,418
- #11 Turkey 2,371
- #12 Peru 2,064
- #13 Argentina 2,047
- #14 Colombia 1,886
- #15 France 1,841
- #16 Italy 1,522
- #17 Germany 1,404
- #18 Algeria 1,397
- #19 Poland 1,396
- #20 Spain 1,329
- #21 Morocco 1,286
- #22 Chile 1,131
- #23 Sri Lanka 1,113
- #24 Ecuador 1,070
- #25 Malaysia 1,039
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 44,621 users
-
#2
44,018 users
-
#3
facebook.com 37,291 users
-
#4
live.com 34,580 users
-
#5
discord.com 20,450 users
-
#6
instagram.com 18,884 users
-
#7
roblox.com 18,777 users
-
#8
netflix.com 17,368 users
-
#9
twitter.com 15,781 users
-
#10
amazon.com 15,483 users
-
#11
com.facebook.katana 15,430 users
-
#12
twitch.tv 14,483 users
-
#13
steampowered.com 14,457 users
-
#14
paypal.com 13,182 users
-
#15
riotgames.com 12,685 users
-
#16
epicgames.com 12,011 users
-
#17
com.instagram.android 11,024 users
-
#18
mega.nz 10,664 users
-
#19
microsoftonline.com 10,612 users
-
#20
steamcommunity.com 10,412 users
-
#21
com.netflix.mediaclient 10,187 users
-
#22
spotify.com 9,395 users
-
#23
com.discord 8,779 users
-
#24
com.spotify.music 8,715 users
-
#25
apple.com 8,653 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
946 employees
-
#2
icicibank.com 227 employees
-
#3
rediff.com 147 employees
-
#4
163.com 140 employees
-
#5
aruba.it 112 employees
-
#6
hostinger.com 111 employees
-
#7
qq.com 89 employees
-
#8
interia.pl 85 employees
-
#9
secureserver.net 79 employees
-
#10
digimail.in 75 employees
-
#11
accenture.com 73 employees
-
#12
pec.it 69 employees
-
#13
o2.pl 67 employees
-
#14
tim.it 65 employees
-
#15
bcb.gov.br 64 employees
-
#16
onet.pl 60 employees
-
#17
sp.gov.br 60 employees
-
#18
netpnb.com 59 employees
-
#19
aiou.edu.pk 58 employees
-
#20
telecom.pt 58 employees
-
#21
mail.tm 56 employees
-
#22
laureate.net 54 employees
-
#23
onlinesbi.com 53 employees
-
#24
freemail.hu 50 employees
-
#25
unionbankonline.co.in 49 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 33 employees
-
#2
rockwellautomation.com 25 employees
-
#3
publix.com 24 employees
-
#4
cognizant.com 9 employees
-
#5
ford.com 7 employees
-
#6
att.com 5 employees
-
#7
netflix.com 5 employees
-
#8
apple.com 5 employees
-
#9
ibm.com 4 employees
-
#10
ups.com 4 employees
-
#11
oracle.com 4 employees
-
#12
jacobs.com 3 employees
-
#13
kindermorgan.com 3 employees
-
#14
gm.com 3 employees
-
#15
twc.com 3 employees
-
#16
aa.com 3 employees
-
#17
ge.com 3 employees
-
#18
amazon.com 3 employees
-
#19
salesforce.com 3 employees
-
#20
johnsoncontrols.com 3 employees
Compromised users
-
#1
google.com 44,621 users
-
#2
facebook.com 37,291 users
-
#3
netflix.com 17,368 users
-
#4
amazon.com 15,483 users
-
#5
paypal.com 13,182 users
-
#6
apple.com 8,653 users
-
#7
ebay.com 2,085 users
-
#8
oracle.com 1,584 users
-
#9
nike.com 1,119 users
-
#10
microsoft.com 1,100 users
-
#11
cisco.com 1,076 users
-
#12
hp.com 954 users
-
#13
walmart.com 622 users
-
#14
intel.com 510 users
-
#15
ibm.com 449 users
-
#16
ups.com 409 users
-
#17
bestbuy.com 360 users
-
#18
westernunion.com 331 users
-
#19
fedex.com 309 users
-
#20
target.com 271 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 183,595hits
- #2 sso 51,390hits
- #3 zoom 19,473hits
- #4 github 8,602hits
- #5 adfs 7,946hits
- #6 webmail 6,697hits
- #7 oracle 4,022hits
- #8 sap 3,279hits
- #9 zendesk 2,747hits
- #10 owa 2,553hits
- #11 cpanel 2,356hits
- #12 sts 2,163hits
- #13 vpn 1,953hits
- #14 ping 1,852hits
- #15 webex 1,739hits
- #16 ftp 1,340hits
- #17 kaspersky 1,164hits
- #18 extranet 1,151hits
- #19 st 1,101hits
- #20 roundcube 688hits
- #21 salesforce 658hits
- #22 okta 571hits
- #23 twilio 522hits
- #24 citrix 508hits
- #25 gitlab 439hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains