Infostealers Weekly Report: 2022-07-25 – 2022-07-31
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 10,941
- #2 Indonesia 7,456
- #3 Brazil 6,904
- #4 Vietnam 5,395
- #5 Mexico 3,175
- #6 Egypt 2,795
- #7 Philippines 2,677
- #8 Thailand 2,670
- #9 Pakistan 2,632
- #10 United States of America 2,541
- #11 Argentina 2,255
- #12 Colombia 2,127
- #13 Peru 2,046
- #14 Turkey 1,575
- #15 Algeria 1,293
- #16 Bangladesh 1,143
- #17 Germany 1,134
- #18 Morocco 1,124
- #19 Ecuador 1,027
- #20 Chile 1,008
- #21 France 916
- #22 Malaysia 912
- #23 Poland 897
- #24 Spain 893
- #25 Bolivia 891
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 38,290 users
-
#2
facebook.com 33,528 users
-
#3
31,189 users
-
#4
live.com 29,851 users
-
#5
instagram.com 15,413 users
-
#6
discord.com 14,756 users
-
#7
com.facebook.katana 14,620 users
-
#8
netflix.com 14,523 users
-
#9
twitter.com 13,537 users
-
#10
roblox.com 13,477 users
-
#11
amazon.com 12,468 users
-
#12
steampowered.com 10,696 users
-
#13
paypal.com 10,329 users
-
#14
com.instagram.android 9,886 users
-
#15
twitch.tv 9,589 users
-
#16
mega.nz 9,136 users
-
#17
com.netflix.mediaclient 9,132 users
-
#18
microsoftonline.com 9,002 users
-
#19
riotgames.com 8,816 users
-
#20
linkedin.com 8,202 users
-
#21
epicgames.com 7,882 users
-
#22
com.spotify.music 7,395 users
-
#23
apple.com 7,355 users
-
#24
com.discord 7,312 users
-
#25
steamcommunity.com 7,054 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
944 employees
-
#2
icicibank.com 200 employees
-
#3
rediff.com 176 employees
-
#4
hostinger.com 104 employees
-
#5
netpnb.com 88 employees
-
#6
163.com 83 employees
-
#7
qq.com 80 employees
-
#8
aruba.it 73 employees
-
#9
digimail.in 71 employees
-
#10
accenture.com 66 employees
-
#11
o2.pl 64 employees
-
#12
bcb.gov.br 63 employees
-
#13
freemail.hu 62 employees
-
#14
secureserver.net 60 employees
-
#15
laureate.net 59 employees
-
#16
sp.gov.br 56 employees
-
#17
bobibanking.com 55 employees
-
#18
unionbankonline.co.in 53 employees
-
#19
interia.pl 52 employees
-
#20
jwpub.org 52 employees
-
#21
uol.com.br 48 employees
-
#22
naver.com 46 employees
-
#23
bluehost.com 46 employees
-
#24
secop.gov.co 44 employees
-
#25
pec.it 43 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 39 employees
-
#2
microsoft.com 36 employees
-
#3
cognizant.com 13 employees
-
#4
publix.com 11 employees
-
#5
amazon.com 7 employees
-
#6
apple.com 7 employees
-
#7
netflix.com 5 employees
-
#8
twc.com 4 employees
-
#9
ibm.com 4 employees
-
#10
hp.com 4 employees
-
#11
oracle.com 3 employees
-
#12
gm.com 3 employees
-
#13
honeywell.com 3 employees
-
#14
interpublic.com 2 employees
-
#15
sandisk.com 2 employees
-
#16
morganstanley.com 2 employees
-
#17
ch2m.com 2 employees
-
#18
ups.com 2 employees
-
#19
paypal.com 2 employees
-
#20
cisco.com 2 employees
Compromised users
-
#1
google.com 38,290 users
-
#2
facebook.com 33,528 users
-
#3
netflix.com 14,523 users
-
#4
amazon.com 12,468 users
-
#5
paypal.com 10,329 users
-
#6
apple.com 7,355 users
-
#7
ebay.com 1,899 users
-
#8
oracle.com 1,310 users
-
#9
cisco.com 1,126 users
-
#10
microsoft.com 961 users
-
#11
hp.com 880 users
-
#12
nike.com 807 users
-
#13
ibm.com 427 users
-
#14
walmart.com 424 users
-
#15
intel.com 337 users
-
#16
westernunion.com 293 users
-
#17
ups.com 281 users
-
#18
bestbuy.com 229 users
-
#19
fedex.com 216 users
-
#20
target.com 182 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 162,474hits
- #2 sso 50,410hits
- #3 zoom 19,004hits
- #4 github 7,266hits
- #5 webmail 6,914hits
- #6 adfs 6,322hits
- #7 oracle 3,598hits
- #8 cpanel 3,462hits
- #9 sap 3,015hits
- #10 zendesk 2,599hits
- #11 owa 2,556hits
- #12 ping 1,993hits
- #13 sts 1,813hits
- #14 vpn 1,707hits
- #15 webex 1,643hits
- #16 ftp 1,441hits
- #17 kaspersky 1,116hits
- #18 st 1,031hits
- #19 extranet 907hits
- #20 roundcube 697hits
- #21 salesforce 615hits
- #22 okta 523hits
- #23 gitlab 435hits
- #24 twilio 386hits
- #25 jira 283hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains