Infostealers Weekly Report: 2022-10-03 – 2022-10-09
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 10,307
- #2 Egypt 5,043
- #3 Vietnam 4,100
- #4 Mexico 3,552
- #5 Thailand 3,464
- #6 Philippines 3,401
- #7 United States of America 3,252
- #8 Colombia 2,990
- #9 Germany 2,711
- #10 Algeria 2,647
- #11 Spain 2,442
- #12 India 2,415
- #13 Argentina 2,238
- #14 Turkey 2,217
- #15 Indonesia 2,186
- #16 Peru 2,173
- #17 Morocco 1,882
- #18 Italy 1,768
- #19 Chile 1,746
- #20 Poland 1,551
- #21 France 1,536
- #22 Ecuador 1,495
- #23 Bangladesh 1,421
- #24 Iraq 1,115
- #25 Bolivia 978
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 42,943 users
-
#2
facebook.com 38,354 users
-
#3
live.com 34,834 users
-
#4
netflix.com 17,910 users
-
#5
instagram.com 17,788 users
-
#6
discord.com 17,234 users
-
#7
com.facebook.katana 16,151 users
-
#8
roblox.com 16,036 users
-
#9
twitter.com 15,052 users
-
#10
amazon.com 14,556 users
-
#11
paypal.com 13,622 users
-
#12
steampowered.com 12,999 users
-
#13
twitch.tv 12,141 users
-
#14
microsoftonline.com 11,539 users
-
#15
com.netflix.mediaclient 11,254 users
-
#16
com.instagram.android 11,211 users
-
#17
mega.nz 10,953 users
-
#18
riotgames.com 10,524 users
-
#19
epicgames.com 9,826 users
-
#20
linkedin.com 9,387 users
-
#21
apple.com 9,050 users
-
#22
spotify.com 8,958 users
-
#23
steamcommunity.com 8,783 users
-
#24
com.spotify.music 8,769 users
-
#25
com.discord 8,198 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
792 employees
-
#2
aruba.it 161 employees
-
#3
wp.pl 143 employees
-
#4
pec.it 128 employees
-
#5
hostinger.com 124 employees
-
#6
tim.it 120 employees
-
#7
o2.pl 104 employees
-
#8
163.com 99 employees
-
#9
qq.com 90 employees
-
#10
freemail.hu 88 employees
-
#11
bcb.gov.br 88 employees
-
#12
interia.pl 83 employees
-
#13
secureserver.net 82 employees
-
#14
abv.bg 77 employees
-
#15
laureate.net 72 employees
-
#16
hostgator.com.br 72 employees
-
#17
secop.gov.co 71 employees
-
#18
bluehost.com 69 employees
-
#19
telecom.pt 68 employees
-
#20
ovh.net 67 employees
-
#21
login.sp.gov.br 65 employees
-
#22
globo.com 61 employees
-
#23
sempreser.com.br 61 employees
-
#24
icicibank.com 58 employees
-
#25
uol.com.br 56 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 41 employees
-
#2
rockwellautomation.com 36 employees
-
#3
facebook.com 10 employees
-
#4
netflix.com 10 employees
-
#5
ford.com 9 employees
-
#6
google.com 9 employees
-
#7
paypal.com 8 employees
-
#8
publix.com 8 employees
-
#9
zimmerbiomet.com 6 employees
-
#10
charter.com 5 employees
-
#11
newmont.com 5 employees
-
#12
ups.com 4 employees
-
#13
hp.com 4 employees
-
#14
sanmina.com 4 employees
-
#15
windstream.com 3 employees
-
#16
goodyear.com 3 employees
-
#17
amazon.com 3 employees
-
#18
gm.com 3 employees
-
#19
metlife.com 3 employees
-
#20
henryschein.com 2 employees
Compromised users
-
#1
google.com 42,943 users
-
#2
facebook.com 38,354 users
-
#3
netflix.com 17,910 users
-
#4
amazon.com 14,556 users
-
#5
paypal.com 13,622 users
-
#6
apple.com 9,050 users
-
#7
ebay.com 2,366 users
-
#8
oracle.com 1,539 users
-
#9
microsoft.com 1,226 users
-
#10
nike.com 1,206 users
-
#11
hp.com 1,203 users
-
#12
cisco.com 1,196 users
-
#13
walmart.com 520 users
-
#14
ups.com 508 users
-
#15
ibm.com 453 users
-
#16
intel.com 383 users
-
#17
westernunion.com 374 users
-
#18
fedex.com 278 users
-
#19
bestbuy.com 253 users
-
#20
adp.com 222 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 165,882hits
- #2 sso 46,805hits
- #3 zoom 17,775hits
- #4 webmail 8,644hits
- #5 adfs 7,936hits
- #6 github 7,599hits
- #7 oracle 3,438hits
- #8 sap 2,792hits
- #9 zendesk 2,572hits
- #10 owa 2,556hits
- #11 sts 2,303hits
- #12 vpn 2,114hits
- #13 cpanel 2,070hits
- #14 ping 1,940hits
- #15 extranet 1,509hits
- #16 roundcube 1,448hits
- #17 webex 1,405hits
- #18 ftp 1,298hits
- #19 kaspersky 1,256hits
- #20 st 1,044hits
- #21 salesforce 881hits
- #22 okta 537hits
- #23 imap 526hits
- #24 gitlab 477hits
- #25 twilio 340hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains