Crime and Justice Atlas

How Justice Is Served
Sign In
Text size
100%
Theme
Offense

Watering Hole Attack

Cyber and Technology-Enabled Offenses

A watering hole attack is a computer attack strategy in which an attacker guesses or observes which websites members of a targeted organization frequently visit, then compromises one or more of those legitimate sites to distribute malware to visitors from the organization; some attackers narrow the attack further to target only visitors from a specific IP address, which makes both detection and research into the attack more difficult. The term derives from the way a predator lies in wait near a watering hole to ambush prey that must eventually visit it; the RSA Blog formally named the attack strategy in 2012. Because the attack relies on compromising websites that are already legitimate and trusted by the target, standard blacklisting cannot easily block it, and the malware and scripts used are often carefully engineered to evade detection by antivirus software.

Facts
Elements of Offense
Attacker observes which sites an organization's users frequent, then compromises those sites to distribute malware 1
Notable Example
2019 Holy Water campaign against Asian religious and charity groups 1
Classification
Offense Grade
Serious or Indictable Offense 1
Connections

Has Offense Grade

Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.

Sources
1. Watering hole attack, Wikipedia
  • Definition
    an attacker guesses or observes which websites an organization's users frequent and then uses one or more of the websites to distribute malware
  • Notable examples, Holy Water
    targeted Asian religious and charity groups
View the Source
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.