A watering hole attack is a computer attack strategy in which an attacker guesses or observes which websites members of a targeted organization frequently visit, then compromises one or more of those legitimate sites to distribute malware to visitors from the organization; some attackers narrow the attack further to target only visitors from a specific IP address, which makes both detection and research into the attack more difficult. The term derives from the way a predator lies in wait near a watering hole to ambush prey that must eventually visit it; the RSA Blog formally named the attack strategy in 2012. Because the attack relies on compromising websites that are already legitimate and trusted by the target, standard blacklisting cannot easily block it, and the malware and scripts used are often carefully engineered to evade detection by antivirus software.
Facts
Elements of OffenseAttacker observes which sites an organization's users frequent, then compromises those sites to distribute malware 1 Notable Example2019 Holy Water campaign against Asian religious and charity groups 1 Classification
Offense GradeSerious or Indictable Offense 1 Connections
Has Offense Grade
Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.
Sources
1. Watering hole attack, Wikipedia
Definition
an attacker guesses or observes which websites an organization's users frequent and then uses one or more of the websites to distribute malware
Notable examples, Holy Water
targeted Asian religious and charity groups
View the SourceReader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.