Infostealers Weekly Report: 2022-05-16 – 2022-05-22
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 15,816
- #2 India 12,829
- #3 Indonesia 12,166
- #4 Philippines 5,574
- #5 Egypt 5,095
- #6 Vietnam 4,679
- #7 Pakistan 3,775
- #8 Mexico 3,584
- #9 United States of America 3,571
- #10 Thailand 3,280
- #11 Colombia 3,131
- #12 Peru 2,626
- #13 Argentina 2,606
- #14 Germany 2,187
- #15 Algeria 2,151
- #16 Morocco 1,914
- #17 Turkey 1,884
- #18 France 1,835
- #19 Bangladesh 1,767
- #20 Italy 1,767
- #21 Spain 1,737
- #22 Malaysia 1,559
- #23 Ecuador 1,538
- #24 Venezuela 1,394
- #25 Chile 1,348
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
65,485 users
-
#2
google.com 53,389 users
-
#3
facebook.com 45,215 users
-
#4
live.com 40,045 users
-
#5
discord.com 21,149 users
-
#6
instagram.com 20,429 users
-
#7
netflix.com 19,334 users
-
#8
com.facebook.katana 18,966 users
-
#9
roblox.com 18,795 users
-
#10
twitter.com 18,450 users
-
#11
amazon.com 16,815 users
-
#12
paypal.com 15,457 users
-
#13
steampowered.com 15,199 users
-
#14
twitch.tv 13,959 users
-
#15
mega.nz 13,413 users
-
#16
riotgames.com 12,734 users
-
#17
com.instagram.android 12,581 users
-
#18
microsoftonline.com 12,039 users
-
#19
com.netflix.mediaclient 11,723 users
-
#20
epicgames.com 11,481 users
-
#21
steamcommunity.com 10,545 users
-
#22
apple.com 10,118 users
-
#23
linkedin.com 10,086 users
-
#24
com.discord 9,749 users
-
#25
spotify.com 9,676 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
1,157 employees
-
#2
icicibank.com 269 employees
-
#3
rediff.com 168 employees
-
#4
163.com 134 employees
-
#5
qq.com 129 employees
-
#6
aruba.it 119 employees
-
#7
sp.gov.br 112 employees
-
#8
hostinger.com 95 employees
-
#9
pec.it 90 employees
-
#10
bni.co.id 85 employees
-
#11
bcb.gov.br 85 employees
-
#12
secureserver.net 82 employees
-
#13
tim.it 80 employees
-
#14
freemail.hu 75 employees
-
#15
netpnb.com 69 employees
-
#16
digimail.in 69 employees
-
#17
sempreser.com.br 68 employees
-
#18
aiou.edu.pk 65 employees
-
#19
accenture.com 65 employees
-
#20
laureate.net 65 employees
-
#21
uol.com.br 65 employees
-
#22
o2.pl 64 employees
-
#23
ovh.net 60 employees
-
#24
telecom.pt 59 employees
-
#25
interia.pl 59 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 57 employees
-
#2
rockwellautomation.com 30 employees
-
#3
amazon.com 12 employees
-
#4
oracle.com 12 employees
-
#5
cognizant.com 10 employees
-
#6
publix.com 9 employees
-
#7
netflix.com 8 employees
-
#8
ford.com 6 employees
-
#9
csc.com 6 employees
-
#10
intel.com 5 employees
-
#11
hp.com 4 employees
-
#12
ups.com 4 employees
-
#13
frontier.com 4 employees
-
#14
jpmorganchase.com 3 employees
-
#15
cisco.com 3 employees
-
#16
twc.com 3 employees
-
#17
ibm.com 2 employees
-
#18
fedex.com 2 employees
-
#19
pfizer.com 2 employees
-
#20
synnex.com 2 employees
Compromised users
-
#1
google.com 53,389 users
-
#2
facebook.com 45,215 users
-
#3
netflix.com 19,334 users
-
#4
amazon.com 16,815 users
-
#5
paypal.com 15,457 users
-
#6
apple.com 10,118 users
-
#7
ebay.com 2,600 users
-
#8
oracle.com 1,999 users
-
#9
cisco.com 1,381 users
-
#10
hp.com 1,273 users
-
#11
microsoft.com 1,098 users
-
#12
nike.com 987 users
-
#13
ibm.com 554 users
-
#14
walmart.com 547 users
-
#15
intel.com 529 users
-
#16
ups.com 405 users
-
#17
westernunion.com 400 users
-
#18
bestbuy.com 287 users
-
#19
fedex.com 237 users
-
#20
adp.com 193 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 190,646hits
- #2 sso 58,095hits
- #3 zoom 21,398hits
- #4 github 8,640hits
- #5 webmail 7,984hits
- #6 adfs 7,254hits
- #7 oracle 4,774hits
- #8 sap 3,405hits
- #9 owa 3,149hits
- #10 zendesk 2,870hits
- #11 cpanel 2,622hits
- #12 vpn 2,354hits
- #13 sts 2,129hits
- #14 ping 2,126hits
- #15 webex 2,090hits
- #16 ftp 1,416hits
- #17 kaspersky 1,400hits
- #18 st 1,312hits
- #19 extranet 1,151hits
- #20 roundcube 1,028hits
- #21 salesforce 673hits
- #22 gitlab 546hits
- #23 okta 520hits
- #24 twilio 441hits
- #25 zimbra 426hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains