Infostealers Weekly Report: 2022-08-15 – 2022-08-21
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 5,055
- #2 Vietnam 4,979
- #3 India 3,708
- #4 Egypt 3,120
- #5 Indonesia 2,619
- #6 Thailand 2,446
- #7 Philippines 2,230
- #8 Mexico 2,155
- #9 Turkey 1,946
- #10 Poland 1,808
- #11 Colombia 1,711
- #12 Peru 1,709
- #13 United States of America 1,638
- #14 Argentina 1,479
- #15 Algeria 1,383
- #16 Spain 1,341
- #17 Pakistan 1,018
- #18 Morocco 998
- #19 Bangladesh 971
- #20 Germany 932
- #21 Malaysia 868
- #22 Italy 821
- #23 France 805
- #24 Ecuador 800
- #25 Venezuela 705
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 27,352 users
-
#2
facebook.com 25,262 users
-
#3
23,648 users
-
#4
live.com 21,626 users
-
#5
discord.com 11,858 users
-
#6
roblox.com 11,699 users
-
#7
instagram.com 10,574 users
-
#8
netflix.com 10,327 users
-
#9
com.facebook.katana 10,304 users
-
#10
twitter.com 8,868 users
-
#11
steampowered.com 8,136 users
-
#12
amazon.com 8,028 users
-
#13
twitch.tv 7,428 users
-
#14
paypal.com 6,953 users
-
#15
riotgames.com 6,811 users
-
#16
com.instagram.android 6,429 users
-
#17
microsoftonline.com 6,386 users
-
#18
epicgames.com 6,367 users
-
#19
mega.nz 6,299 users
-
#20
com.netflix.mediaclient 6,264 users
-
#21
steamcommunity.com 5,687 users
-
#22
com.discord 5,248 users
-
#23
com.roblox.client 5,112 users
-
#24
com.spotify.music 4,946 users
-
#25
apple.com 4,861 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
448 employees
-
#2
o2.pl 104 employees
-
#3
interia.pl 96 employees
-
#4
rediff.com 78 employees
-
#5
freemail.hu 72 employees
-
#6
163.com 68 employees
-
#7
icicibank.com 60 employees
-
#8
laureate.net 59 employees
-
#9
aruba.it 59 employees
-
#10
pec.it 58 employees
-
#11
hostinger.com 56 employees
-
#12
tim.it 55 employees
-
#13
onet.pl 55 employees
-
#14
utp.edu.pe 50 employees
-
#15
qq.com 49 employees
-
#16
skole.hr 40 employees
-
#17
bcb.gov.br 40 employees
-
#18
telecom.pt 40 employees
-
#19
sp.gov.br 39 employees
-
#20
secureserver.net 39 employees
-
#21
taqat.sa 32 employees
-
#22
abv.bg 31 employees
-
#23
ig.com.br 30 employees
-
#24
cibertec.edu.pe 30 employees
-
#25
isacombank.com.vn 29 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 18 employees
-
#2
rockwellautomation.com 10 employees
-
#3
amazon.com 5 employees
-
#4
publix.com 5 employees
-
#5
google.com 5 employees
-
#6
ncr.com 4 employees
-
#7
facebook.com 4 employees
-
#8
ibm.com 3 employees
-
#9
cisco.com 3 employees
-
#10
cognizant.com 2 employees
-
#11
abbott.com 2 employees
-
#12
netflix.com 2 employees
-
#13
salesforce.com 2 employees
-
#14
bakerhughes.com 2 employees
-
#15
jacobs.com 2 employees
-
#16
johnsoncontrols.com 2 employees
-
#17
oracle.com 2 employees
-
#18
insight.com 1 employees
-
#19
manpowergroup.com 1 employees
-
#20
vfc.com 1 employees
Compromised users
-
#1
google.com 27,352 users
-
#2
facebook.com 25,262 users
-
#3
netflix.com 10,327 users
-
#4
amazon.com 8,028 users
-
#5
paypal.com 6,953 users
-
#6
apple.com 4,861 users
-
#7
ebay.com 1,113 users
-
#8
oracle.com 840 users
-
#9
cisco.com 641 users
-
#10
hp.com 605 users
-
#11
nike.com 531 users
-
#12
microsoft.com 525 users
-
#13
walmart.com 275 users
-
#14
ibm.com 227 users
-
#15
intel.com 212 users
-
#16
ups.com 205 users
-
#17
bestbuy.com 147 users
-
#18
westernunion.com 144 users
-
#19
fedex.com 139 users
-
#20
adp.com 110 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 103,957hits
- #2 sso 29,440hits
- #3 zoom 11,578hits
- #4 github 4,220hits
- #5 webmail 4,187hits
- #6 adfs 3,649hits
- #7 oracle 2,146hits
- #8 zendesk 1,579hits
- #9 sap 1,547hits
- #10 owa 1,421hits
- #11 vpn 1,338hits
- #12 sts 1,020hits
- #13 cpanel 974hits
- #14 ping 956hits
- #15 webex 942hits
- #16 st 747hits
- #17 kaspersky 702hits
- #18 ftp 603hits
- #19 extranet 588hits
- #20 roundcube 499hits
- #21 salesforce 453hits
- #22 okta 282hits
- #23 twilio 274hits
- #24 gitlab 240hits
- #25 zimbra 180hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains