Infostealers Weekly Report: 2022-12-05 – 2022-12-11
InfoStealers Weekly Report - In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in complexity and scale, our mission is to equip you with the knowledge and tools needed to safeguard your sensitive information. Join us as we analyze the top compromised domains, identify trends in compromised employees and users, and examine the global impact of InfoStealer infections. Stay informed, stay protected, and stay one step ahead of cyber threats with our weekly report.
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 4,158
- #2 Egypt 4,020
- #3 Pakistan 2,787
- #4 Philippines 2,737
- #5 India 2,653
- #6 Algeria 2,651
- #7 Indonesia 2,006
- #8 Morocco 1,869
- #9 Vietnam 1,861
- #10 Spain 1,780
- #11 Turkey 1,746
- #12 Thailand 1,669
- #13 Argentina 1,600
- #14 Colombia 1,573
- #15 Poland 1,498
- #16 Mexico 1,485
- #17 Bangladesh 1,449
- #18 Peru 1,448
- #19 United States of America 1,288
- #20 Venezuela 1,081
- #21 Ecuador 1,017
- #22 Italy 993
- #23 Iraq 882
- #24 South Korea 858
- #25 Germany 855
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 29,783 users
-
#2
facebook.com 27,282 users
-
#3
live.com 23,645 users
-
#4
discord.com 12,161 users
-
#5
instagram.com 11,969 users
-
#6
com.facebook.katana 11,745 users
-
#7
roblox.com 11,654 users
-
#8
netflix.com 11,352 users
-
#9
twitter.com 9,851 users
-
#10
amazon.com 9,211 users
-
#11
steampowered.com 8,924 users
-
#12
paypal.com 8,589 users
-
#13
com.instagram.android 7,771 users
-
#14
twitch.tv 7,564 users
-
#15
microsoftonline.com 7,184 users
-
#16
com.netflix.mediaclient 7,144 users
-
#17
mega.nz 7,117 users
-
#18
riotgames.com 6,827 users
-
#19
epicgames.com 6,305 users
-
#20
linkedin.com 6,041 users
-
#21
com.discord 5,829 users
-
#22
apple.com 5,703 users
-
#23
steamcommunity.com 5,604 users
-
#24
spotify.com 5,313 users
-
#25
com.roblox.client 5,079 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
wp.pl 220 employees
-
#2
tim.it 91 employees
-
#3
freemail.hu 87 employees
-
#4
interia.pl 79 employees
-
#5
aruba.it 79 employees
-
#6
hostinger.com 78 employees
-
#7
pec.it 75 employees
-
#8
abv.bg 73 employees
-
#9
o2.pl 63 employees
-
#10
qq.com 63 employees
-
#11
163.com 62 employees
-
#12
onet.pl 61 employees
-
#13
icicibank.com 58 employees
-
#14
aiou.edu.pk 55 employees
-
#15
rediff.com 50 employees
-
#16
naver.com 50 employees
-
#17
skole.hr 50 employees
-
#18
secureserver.net 47 employees
-
#19
jwpub.org 44 employees
-
#20
telecom.pt 43 employees
-
#21
bcb.gov.br 40 employees
-
#22
ovh.net 38 employees
-
#23
laureate.net 35 employees
-
#24
login.sp.gov.br 35 employees
-
#25
rockwellautomation.com 35 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
rockwellautomation.com 35 employees
-
#2
publix.com 11 employees
-
#3
facebook.com 7 employees
-
#4
microsoft.com 7 employees
-
#5
cognizant.com 5 employees
-
#6
marriott.com 4 employees
-
#7
netflix.com 4 employees
-
#8
ups.com 3 employees
-
#9
ibm.com 3 employees
-
#10
paypal.com 3 employees
-
#11
cbre.com 3 employees
-
#12
bakerhughes.com 2 employees
-
#13
amazon.com 2 employees
-
#14
ford.com 2 employees
-
#15
apple.com 2 employees
-
#16
fedex.com 1 employees
-
#17
frontier.com 1 employees
-
#18
johnsoncontrols.com 1 employees
-
#19
salesforce.com 1 employees
-
#20
csc.com 1 employees
Compromised users
-
#1
google.com 29,783 users
-
#2
facebook.com 27,282 users
-
#3
netflix.com 11,352 users
-
#4
amazon.com 9,211 users
-
#5
paypal.com 8,589 users
-
#6
apple.com 5,703 users
-
#7
ebay.com 1,541 users
-
#8
oracle.com 985 users
-
#9
cisco.com 821 users
-
#10
microsoft.com 817 users
-
#11
hp.com 775 users
-
#12
nike.com 750 users
-
#13
ibm.com 327 users
-
#14
walmart.com 290 users
-
#15
ups.com 286 users
-
#16
westernunion.com 252 users
-
#17
intel.com 201 users
-
#18
fedex.com 179 users
-
#19
bestbuy.com 132 users
-
#20
adp.com 115 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 94,843hits
- #2 sso 22,432hits
- #3 zoom 9,399hits
- #4 github 4,390hits
- #5 webmail 3,778hits
- #6 adfs 3,142hits
- #7 oracle 2,456hits
- #8 zendesk 1,511hits
- #9 sap 1,356hits
- #10 owa 1,297hits
- #11 vpn 1,180hits
- #12 ping 898hits
- #13 cpanel 878hits
- #14 sts 803hits
- #15 kaspersky 785hits
- #16 webex 771hits
- #17 salesforce 693hits
- #18 extranet 683hits
- #19 st 674hits
- #20 ftp 669hits
- #21 roundcube 485hits
- #22 okta 272hits
- #23 gitlab 244hits
- #24 imap 227hits
- #25 twilio 222hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains