argus scan --domain
How many of your company's machines have already been infected?
Infostealers harvest credentials from real machines — employees, customers and vendors. Look up your company domain and see what is already circulating.
The scale of exposure
Exposure leaves traces. We connect the data.
The same data infrastructure that powers Argus, behind this page.
- Compromised machines
- 36M
- Employees with exposed credentials
- 5,698,026
- Domains in the dataset
- 15,839,002
- Compromised passwords
- 500M+
- Compromised session cookies
- 25B+
- Cookie records in the global dataset. This does not mean these sessions are still valid.
data as of 08/05/2026 · Argus intelligence base
Attack infrastructure tracked right now
measured at 10/05, 12:59 AM- 25,514
- C2 servers
- 49,854
- PhaaS hosts
- 5,029
- ClickFix sites
active infostealers
phishing as a service
clipboard hijacking
The path to exposure
From an infected machine to unauthorized access.
Explore four steps that can turn one person’s exposure into a doorway to the company.
Process illustration · 01/04
It starts with one person
A tampered installer or an attachment can infect a machine. It may belong to an employee, customer or vendor, including outside the corporate network.
Process illustration · 02/04
The browser becomes a data source
An infostealer can collect saved passwords, history and session cookies. A machine outside the monitored environment can put this activity beyond the company’s visibility.
Process illustration · 03/04
The stolen data begins to circulate
The collected data becomes a log that may be sold or published on forums and closed channels. The same file may reach multiple buyers.
Process illustration · 04/04
A session can become a way in
If the service accepts a stolen cookie, an attacker may reuse a session without a new login. This depends on session validity and the service’s controls; the cookie date alone does not confirm access.
An exposed session may remain at risk after a password change. Investigating the machine and revoking sessions are separate steps.
Threat intelligence
Behind every record, a threat.
When the source identifies a family, its name accompanies the record. Meet some of the families in this ecosystem.
- Lumma
- Sold as a service. Targets browsers, 2FA extensions and wallets.
- Acreed
- Identified in Brazilian samples in the intelligence dataset.
- RedLine
- One of the most widespread of the decade. Credentials, cookies and wallets.
- Vidar
- Derived from Arkei. Steals credentials, cookies and screenshots.
- StealC
- Modular, sold as a service; mimics the behaviour of its predecessors.
- Rhadamanthys
- More sophisticated and modular, focused on crypto and credentials.
Some logs arrive with no family attributed by the source — those show up as generic, and the chart in the result reports that share honestly.
From signal to investigation
Context for your next decision.
From the scale of exposure to the sample details, in a single domain lookup.
Illustrative masking example. This is not a real record.
Masked data for an initial assessment.
Start with our own domain.
Look up huge-networks.com and see what the dataset returns.
Explore the real report- Compromised machines
- How many, with employee and customer credentials counted separately.
- Sessions in the sample
- Services and dates recorded in cookies, without testing whether access still works.
- Identity surface
- VPN, ADFS, Citrix, webmail and portals found in the URLs.
- Related assets
- Domains and apps found through name matching. A starting point for validating the connection.
- Sample forensics
- Password strength, the antivirus that was installed, programs on the machine.
- Credential sample
- Real rows, masked — password as an abstract shape, machine partially hidden.