Infostealers Weekly Report: 2022-10-31 – 2022-11-06
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Indonesia 26,985
- #2 Egypt 13,324
- #3 Brazil 10,261
- #4 India 9,664
- #5 Algeria 6,652
- #6 Vietnam 5,469
- #7 Morocco 4,913
- #8 Philippines 4,612
- #9 Turkey 3,710
- #10 Spain 3,682
- #11 Poland 3,411
- #12 Argentina 3,222
- #13 Colombia 3,116
- #14 Mexico 2,962
- #15 Pakistan 2,872
- #16 Bangladesh 2,723
- #17 Thailand 2,720
- #18 Peru 2,638
- #19 Venezuela 2,508
- #20 Iraq 2,416
- #21 United States of America 2,288
- #22 France 2,187
- #23 Italy 2,165
- #24 Germany 2,088
- #25 Tunisia 1,822
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 63,566 users
-
#2
facebook.com 58,363 users
-
#3
live.com 49,024 users
-
#4
instagram.com 25,493 users
-
#5
com.facebook.katana 25,079 users
-
#6
discord.com 22,598 users
-
#7
netflix.com 22,058 users
-
#8
roblox.com 20,924 users
-
#9
twitter.com 19,592 users
-
#10
com.instagram.android 17,393 users
-
#11
amazon.com 17,101 users
-
#12
steampowered.com 16,571 users
-
#13
paypal.com 15,189 users
-
#14
microsoftonline.com 14,786 users
-
#15
twitch.tv 14,190 users
-
#16
com.netflix.mediaclient 14,048 users
-
#17
riotgames.com 13,324 users
-
#18
mega.nz 13,233 users
-
#19
linkedin.com 12,305 users
-
#20
epicgames.com 11,895 users
-
#21
com.spotify.music 11,810 users
-
#22
com.discord 11,186 users
-
#23
apple.com 11,029 users
-
#24
spotify.com 10,707 users
-
#25
steamcommunity.com 10,639 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
691 employees
-
#2
wp.pl 462 employees
-
#3
o2.pl 186 employees
-
#4
freemail.hu 177 employees
-
#5
interia.pl 165 employees
-
#6
icicibank.com 165 employees
-
#7
abv.bg 162 employees
-
#8
rediff.com 152 employees
-
#9
aruba.it 137 employees
-
#10
hostinger.com 127 employees
-
#11
pec.it 123 employees
-
#12
163.com 117 employees
-
#13
tim.it 112 employees
-
#14
onet.pl 112 employees
-
#15
qq.com 110 employees
-
#16
banquemisr.com 98 employees
-
#17
telecom.pt 93 employees
-
#18
bni.co.id 87 employees
-
#19
secureserver.net 85 employees
-
#20
sempreser.com.br 84 employees
-
#21
laureate.net 83 employees
-
#22
netpnb.com 70 employees
-
#23
utp.edu.pe 70 employees
-
#24
ovh.net 70 employees
-
#25
bcb.gov.br 66 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 38 employees
-
#2
microsoft.com 30 employees
-
#3
facebook.com 13 employees
-
#4
ibm.com 12 employees
-
#5
hp.com 11 employees
-
#6
cognizant.com 11 employees
-
#7
paypal.com 8 employees
-
#8
pg.com 7 employees
-
#9
publix.com 6 employees
-
#10
netflix.com 6 employees
-
#11
oracle.com 5 employees
-
#12
csc.com 5 employees
-
#13
ups.com 5 employees
-
#14
amazon.com 5 employees
-
#15
stryker.com 4 employees
-
#16
chsinc.com 3 employees
-
#17
aa.com 3 employees
-
#18
gm.com 3 employees
-
#19
firstam.com 2 employees
-
#20
adp.com 2 employees
Compromised users
-
#1
google.com 63,566 users
-
#2
facebook.com 58,363 users
-
#3
netflix.com 22,058 users
-
#4
amazon.com 17,101 users
-
#5
paypal.com 15,189 users
-
#6
apple.com 11,029 users
-
#7
ebay.com 2,496 users
-
#8
oracle.com 2,001 users
-
#9
cisco.com 1,701 users
-
#10
microsoft.com 1,584 users
-
#11
hp.com 1,422 users
-
#12
nike.com 1,316 users
-
#13
ibm.com 658 users
-
#14
intel.com 460 users
-
#15
walmart.com 448 users
-
#16
ups.com 433 users
-
#17
westernunion.com 380 users
-
#18
bestbuy.com 217 users
-
#19
adp.com 214 users
-
#20
salesforce.com 203 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 181,594hits
- #2 sso 55,238hits
- #3 zoom 22,383hits
- #4 github 8,466hits
- #5 webmail 7,509hits
- #6 adfs 5,710hits
- #7 oracle 3,701hits
- #8 owa 3,129hits
- #9 zendesk 2,706hits
- #10 ping 2,523hits
- #11 sap 2,517hits
- #12 vpn 2,143hits
- #13 webex 1,921hits
- #14 cpanel 1,821hits
- #15 sts 1,521hits
- #16 kaspersky 1,464hits
- #17 ftp 1,270hits
- #18 extranet 1,237hits
- #19 st 1,089hits
- #20 roundcube 1,021hits
- #21 salesforce 712hits
- #22 okta 637hits
- #23 gitlab 507hits
- #24 twilio 406hits
- #25 jira 378hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains