Infostealers Weekly Report: 2022-10-10 – 2022-10-16
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 13,049
- #2 Brazil 12,612
- #3 Egypt 8,891
- #4 Indonesia 8,702
- #5 Turkey 5,623
- #6 United States of America 5,546
- #7 Vietnam 5,190
- #8 Philippines 4,972
- #9 Mexico 4,773
- #10 Algeria 3,900
- #11 Thailand 3,686
- #12 Spain 3,667
- #13 Morocco 3,514
- #14 Pakistan 3,462
- #15 France 3,325
- #16 Italy 3,180
- #17 Colombia 3,027
- #18 Peru 3,013
- #19 Argentina 2,946
- #20 Bangladesh 2,683
- #21 Germany 2,639
- #22 Poland 2,614
- #23 Chile 2,058
- #24 Iraq 1,703
- #25 Ecuador 1,551
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 71,542 users
-
#2
facebook.com 62,338 users
-
#3
live.com 56,811 users
-
#4
instagram.com 29,923 users
-
#5
netflix.com 28,218 users
-
#6
discord.com 27,187 users
-
#7
com.facebook.katana 25,550 users
-
#8
twitter.com 24,426 users
-
#9
amazon.com 23,641 users
-
#10
roblox.com 22,107 users
-
#11
paypal.com 20,800 users
-
#12
steampowered.com 20,752 users
-
#13
twitch.tv 19,598 users
-
#14
microsoftonline.com 18,490 users
-
#15
com.instagram.android 18,232 users
-
#16
riotgames.com 16,813 users
-
#17
mega.nz 16,524 users
-
#18
com.netflix.mediaclient 16,520 users
-
#19
linkedin.com 15,805 users
-
#20
epicgames.com 15,542 users
-
#21
com.spotify.music 14,978 users
-
#22
apple.com 14,794 users
-
#23
spotify.com 14,327 users
-
#24
steamcommunity.com 14,205 users
-
#25
com.discord 12,480 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
1,408 employees
-
#2
aruba.it 299 employees
-
#3
icicibank.com 293 employees
-
#4
wp.pl 293 employees
-
#5
163.com 217 employees
-
#6
rediff.com 186 employees
-
#7
qq.com 186 employees
-
#8
tim.it 185 employees
-
#9
pec.it 184 employees
-
#10
hostinger.com 177 employees
-
#11
interia.pl 163 employees
-
#12
o2.pl 130 employees
-
#13
freemail.hu 126 employees
-
#14
laureate.net 117 employees
-
#15
onet.pl 117 employees
-
#16
sempreser.com.br 116 employees
-
#17
telecom.pt 110 employees
-
#18
secureserver.net 101 employees
-
#19
netpnb.com 100 employees
-
#20
abv.bg 99 employees
-
#21
banquemisr.com 92 employees
-
#22
unionbankonline.co.in 89 employees
-
#23
ovh.net 88 employees
-
#24
bluehost.com 87 employees
-
#25
secop.gov.co 80 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 70 employees
-
#2
rockwellautomation.com 34 employees
-
#3
publix.com 25 employees
-
#4
apple.com 12 employees
-
#5
oracle.com 12 employees
-
#6
cognizant.com 11 employees
-
#7
ups.com 11 employees
-
#8
netflix.com 11 employees
-
#9
google.com 8 employees
-
#10
ibm.com 8 employees
-
#11
paypal.com 8 employees
-
#12
walmart.com 7 employees
-
#13
facebook.com 6 employees
-
#14
ge.com 6 employees
-
#15
cisco.com 6 employees
-
#16
hp.com 6 employees
-
#17
target.com 5 employees
-
#18
csc.com 5 employees
-
#19
ford.com 4 employees
-
#20
pg.com 4 employees
Compromised users
-
#1
google.com 71,542 users
-
#2
facebook.com 62,338 users
-
#3
netflix.com 28,218 users
-
#4
amazon.com 23,641 users
-
#5
paypal.com 20,800 users
-
#6
apple.com 14,794 users
-
#7
ebay.com 3,789 users
-
#8
oracle.com 2,791 users
-
#9
microsoft.com 2,085 users
-
#10
cisco.com 2,055 users
-
#11
nike.com 1,882 users
-
#12
hp.com 1,878 users
-
#13
walmart.com 947 users
-
#14
ibm.com 824 users
-
#15
ups.com 777 users
-
#16
intel.com 605 users
-
#17
westernunion.com 529 users
-
#18
bestbuy.com 499 users
-
#19
fedex.com 439 users
-
#20
att.com 396 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 262,510hits
- #2 sso 73,065hits
- #3 zoom 28,308hits
- #4 github 13,297hits
- #5 webmail 11,146hits
- #6 adfs 11,071hits
- #7 oracle 6,078hits
- #8 zendesk 3,900hits
- #9 sap 3,873hits
- #10 owa 3,794hits
- #11 ping 3,386hits
- #12 sts 3,303hits
- #13 vpn 3,042hits
- #14 cpanel 2,889hits
- #15 webex 2,609hits
- #16 ftp 2,229hits
- #17 extranet 2,194hits
- #18 kaspersky 2,124hits
- #19 st 1,730hits
- #20 salesforce 1,380hits
- #21 roundcube 1,368hits
- #22 okta 1,081hits
- #23 rlogin 773hits
- #24 gitlab 709hits
- #25 twilio 687hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains