A watering hole attack compromises a third-party website frequently visited by members of a target organization, using it as a vector to deliver malware and gain access to the intended network.
Watering Hole Attack
If we're targeting a specific business and we're trying to get a foothold into it, it might actually be better if we target something else instead. Maybe another website that we know is visited by the people that are within the organization. This is what's called a watering hole.
In the animal kingdom, you have predators and preys. The predators eat the prey. Now, think of a desert, and think of the vast amount of land that's really dry and not much water at all. But every once in a while, you find an oasis, a hole that has water inside of it, and that's a collection point for all of those animals. All the animals need water, so they come down to that water to drink it at these watering holes.
Where do you think a predator is going to set up camp? Where do you think they're going to look for their next meal? They could wander the vast amount of desert and just hope that they run across an animal, or they can go to the watering hole, where they're going to see animals drinking out of this water, and that's where they can attack to find their next meal.
In cyber security, we have a watering hole attack. The idea is the same thing: maybe there's this company that you want to target that has too high of defenses that we can't penetrate it. But we also know that some of the users of this company frequent a different website. For instance, maybe this company has a robotics program, and the robotics program uses a certain website that they host things out of. So what we can do, rather than attacking the company itself, is actually attack the website that these people frequent often, and then the next time they visit they're going to pick up the virus and then take that into the business, and suddenly we have access into the business.
It's called the watering hole effect because it's the same type of thing. We've got users within the company that are visiting these websites, and what we're doing is we're staking out these websites in order to leverage that company that we're targeting.
So our attack card is that adversaries are compromising websites that specific groups frequently visit, and we are targeting that group or that company, and so therefore we're targeting this website that's an outside source. So that's how a watering hole attack works.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →