Infostealers Weekly Report: 2022-05-09 – 2022-05-15
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report and info-stealers statistics.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 12,350
- #2 Indonesia 9,026
- #3 India 7,756
- #4 Egypt 4,899
- #5 Vietnam 4,129
- #6 Philippines 3,831
- #7 United States of America 3,770
- #8 Mexico 3,423
- #9 Colombia 3,135
- #10 Thailand 3,025
- #11 Argentina 2,707
- #12 Pakistan 2,457
- #13 Peru 2,348
- #14 Algeria 2,282
- #15 Turkey 2,122
- #16 Morocco 1,895
- #17 Germany 1,840
- #18 Spain 1,735
- #19 France 1,662
- #20 Chile 1,577
- #21 Bangladesh 1,538
- #22 Italy 1,537
- #23 Ecuador 1,485
- #24 Poland 1,439
- #25 Venezuela 1,183
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 48,251 users
-
#2
facebook.com 41,921 users
-
#3
40,546 users
-
#4
live.com 37,441 users
-
#5
discord.com 20,817 users
-
#6
instagram.com 19,612 users
-
#7
netflix.com 18,824 users
-
#8
roblox.com 17,800 users
-
#9
twitter.com 17,285 users
-
#10
com.facebook.katana 17,242 users
-
#11
amazon.com 15,951 users
-
#12
paypal.com 15,005 users
-
#13
steampowered.com 14,898 users
-
#14
twitch.tv 14,650 users
-
#15
riotgames.com 12,953 users
-
#16
mega.nz 12,144 users
-
#17
com.instagram.android 11,722 users
-
#18
epicgames.com 11,507 users
-
#19
microsoftonline.com 11,264 users
-
#20
com.netflix.mediaclient 11,241 users
-
#21
steamcommunity.com 10,796 users
-
#22
com.spotify.music 10,170 users
-
#23
spotify.com 9,728 users
-
#24
apple.com 9,500 users
-
#25
linkedin.com 9,361 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
766 employees
-
#2
icicibank.com 159 employees
-
#3
rediff.com 141 employees
-
#4
aruba.it 128 employees
-
#5
163.com 119 employees
-
#6
o2.pl 100 employees
-
#7
qq.com 99 employees
-
#8
pec.it 93 employees
-
#9
hostinger.com 88 employees
-
#10
freemail.hu 88 employees
-
#11
tim.it 82 employees
-
#12
laureate.net 82 employees
-
#13
wp.pl 78 employees
-
#14
secureserver.net 76 employees
-
#15
bcb.gov.br 74 employees
-
#16
interia.pl 73 employees
-
#17
secop.gov.co 70 employees
-
#18
telecom.pt 68 employees
-
#19
accenture.com 62 employees
-
#20
ovh.net 62 employees
-
#21
abv.bg 60 employees
-
#22
utp.edu.pe 59 employees
-
#23
inacap.cl 58 employees
-
#24
onet.pl 57 employees
-
#25
uol.com.br 56 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 31 employees
-
#2
rockwellautomation.com 27 employees
-
#3
publix.com 15 employees
-
#4
netflix.com 10 employees
-
#5
cognizant.com 9 employees
-
#6
frontier.com 5 employees
-
#7
amazon.com 5 employees
-
#8
bakerhughes.com 4 employees
-
#9
gm.com 4 employees
-
#10
cbre.com 4 employees
-
#11
ibm.com 3 employees
-
#12
att.com 3 employees
-
#13
jpmorganchase.com 3 employees
-
#14
ups.com 2 employees
-
#15
pfizer.com 2 employees
-
#16
harman.com 2 employees
-
#17
hp.com 2 employees
-
#18
google.com 2 employees
-
#19
spglobal.com 2 employees
-
#20
aecom.com 2 employees
Compromised users
-
#1
google.com 48,251 users
-
#2
facebook.com 41,921 users
-
#3
netflix.com 18,824 users
-
#4
amazon.com 15,951 users
-
#5
paypal.com 15,005 users
-
#6
apple.com 9,500 users
-
#7
ebay.com 2,396 users
-
#8
oracle.com 1,753 users
-
#9
cisco.com 1,273 users
-
#10
hp.com 1,217 users
-
#11
microsoft.com 1,155 users
-
#12
nike.com 1,138 users
-
#13
walmart.com 517 users
-
#14
ibm.com 465 users
-
#15
intel.com 458 users
-
#16
ups.com 445 users
-
#17
westernunion.com 341 users
-
#18
bestbuy.com 311 users
-
#19
fedex.com 251 users
-
#20
target.com 217 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 174,916hits
- #2 sso 49,529hits
- #3 zoom 18,499hits
- #4 github 7,606hits
- #5 adfs 6,972hits
- #6 webmail 6,763hits
- #7 oracle 3,739hits
- #8 zendesk 2,647hits
- #9 sap 2,603hits
- #10 cpanel 2,442hits
- #11 owa 2,350hits
- #12 sts 2,101hits
- #13 vpn 1,843hits
- #14 webex 1,729hits
- #15 ping 1,712hits
- #16 ftp 1,343hits
- #17 kaspersky 1,295hits
- #18 extranet 1,164hits
- #19 st 1,114hits
- #20 salesforce 969hits
- #21 roundcube 802hits
- #22 okta 496hits
- #23 gitlab 435hits
- #24 citrix 420hits
- #25 rlogin 397hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains