{"id":7063,"date":"2021-06-28T13:16:30","date_gmt":"2021-06-28T11:16:30","guid":{"rendered":"https:\/\/tekmart.co.za\/t-blog\/?p=7063"},"modified":"2021-06-28T13:16:56","modified_gmt":"2021-06-28T11:16:56","slug":"watering-hole-attack-what-these-are-how-they-work-and-how-to-prevent-becoming-a-victim","status":"publish","type":"post","link":"https:\/\/tekmart.co.za\/t-blog\/watering-hole-attack-what-these-are-how-they-work-and-how-to-prevent-becoming-a-victim\/","title":{"rendered":"Watering hole attacks; what these are, how they work and how to prevent becoming a victim."},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>\n<h2 class=\"wp-block-heading\"><strong>A watering hole attack is a security exploit in which the attacker seeks to compromise a specific group of end users by infecting websites that members of the group are known to visit.<\/strong><\/h2>\n\n\n\n<p>By<a href=\"https:\/\/www.techtarget.com\/contributor\/Gavin-Wright\">Gavin Wright<\/a> and <a href=\"https:\/\/www.techtarget.com\/contributor\/Madelyn-Bacon\">Madelyn Bacon<\/a><\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>The goal is to infect a targeted user&#8217;s computer and gain access to the network at the target&#8217;s workplace.<\/p><\/blockquote><\/figure>\n\n\n\n<p>The term&nbsp;<em>watering hole attack<\/em>&nbsp;comes from hunting. Rather than tracking its prey over a long distance, the hunter instead determines where the prey is likely to go, most commonly to a body of water &#8212; the watering hole &#8212; and the hunter waits there. When the prey comes of its own will, often with its guard down, the hunter attacks.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>The target victim can be an individual, an organization or a group of people. The attacker profiles its targets &#8212; typically, employees of large enterprises, human rights organizations, religious groups or government offices &#8212; to determine the type of websites they frequent. These are often messaging boards or general interest sites popular with the intended target.<\/p><\/blockquote>\n\n\n\n<p>While watering hole attacks are uncommon, they pose a considerable threat since they are difficult to detect and typically target highly secure organizations through their less security-conscious employees, business partners or connected vendors. And, because they may breach several layers of security, they can be extremely destructive.<\/p>\n\n\n\n<p>Watering hole attacks &#8212; a type of social engineering attack &#8212; are also referred to as&nbsp;<em>water-holing<\/em>, a&nbsp;<em>water hole attack<\/em>&nbsp;or a&nbsp;<em>strategically compromised website<\/em>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How does a watering hole attack work?<\/strong><\/h3>\n\n\n\n<p>A watering hole attack involves a chain of events initiated by an attacker to gain access to a victim. However, the attacker does not target the victim directly.<\/p>\n\n\n\n<p>First, the attacker identifies a website or service that the intended victim already uses and is familiar with. Generally, the target site has relatively low security, is frequently visited and is popular with the intended victim. The attacker then compromises the target site and injects a malicious code payload into the site, often in the form of JavaScript or HyperText Markup Language (HTML). When the victim visits the compromised site, the payload is triggered, and it begins an\u00a0exploit\u00a0chain to infect the victim&#8217;s computer. The payload may be automatic, or the attack may cause a bogus prompt to appear telling the user to take an additional action that will download malicious code. The exploit chain may be one that already exists and is well known or a novel exploit created by the attacker.<\/p>\n\n\n\n<p>Once the payload has been triggered on the victim&#8217;s computer, the attacker can access other assets on the network and use that computer to launch a pivot attack to achieve other goals. The goals may be to gather information about the victim, use the victim&#8217;s computer as part of a bot network or try to exploit other computers within the victim&#8217;s network.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"410\" src=\"https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work-1024x410.png\" alt=\"how watering hole attacks work\" class=\"wp-image-7064\" srcset=\"https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work-1024x410.png 1024w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work-300x120.png 300w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work-768x308.png 768w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work-800x321.png 800w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work-776x310.png 776w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/06\/how-watering-hole-attacks-work.png 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption><strong>How watering hole attacks work<\/strong><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Other security exploits similar to watering hole attacks<\/strong><\/h3>\n\n\n\n<p>A watering hole attack is similar to other tactics used by cybercriminals:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Supply chain attack.<\/strong>\u00a0In both a\u00a0supply chain attack\u00a0and a watering hole attack, a third-party service is compromised by the attacker to infect other systems. However, in supply chain attacks, it is usually a product purchased by the target that is compromised rather than the neutral websites compromised during a watering hole attack.<\/li><li><strong>Honeypot attack.<\/strong>\u00a0A\u00a0honeypot\u00a0attack presents an attractive target that entices the victim to take an action, while a watering hole attack focuses on an existing site that the target already uses.<\/li><li><strong>Man-in-the-middle (MitM) attack.<\/strong>\u00a0In a\u00a0MitM\u00a0attack, the attacker intercepts and reads or changes communication between the victim and a third-party site, but the site itself is not compromised.<\/li><li><strong>Tailgating.<\/strong>\u00a0Tailgating\u00a0is similar in that an attacker follows closely behind someone trusted to gain access, but it is most commonly a physical attack.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How to prevent a watering hole attack<\/strong><\/h3>\n\n\n\n<p>These steps and operational requirements can help to avoid watering hole attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Use best practices for computer security.<\/strong>\u00a0Since watering hole attacks are often web exploits, following\u00a0published best practices\u00a0and computer hardening guidelines may prevent the exploit chain from running.<\/li><li><strong>Do not allow personal use of corporate resources.<\/strong>\u00a0Block access to websites not used for work, and do not allow users to access websites for personal communication.<\/li><li><strong>Do not add trusts to third-party sites.\u00a0<\/strong>Some sites require additional permissions to run properly. Audit or simply don&#8217;t allow these exceptions, as they may allow an attacker to use the site in the future.<\/li><li><strong>Train users to recognize strange behavior and avoid violations.<\/strong>\u00a0Users may be lax with sites they commonly visit, so they should be trained to not click on suspicious links or bypass security warnings.<\/li><li><strong>Scan and monitor internet traffic.<\/strong>\u00a0Use web proxies that can scan content in real time; monitor for common exploits; and use web logging to detect suspicious activity.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Examples of watering hole attacks<\/strong><\/h3>\n\n\n\n<p>Watering hole attacks have been around for some time. Here are some notable examples of past attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>In 2012, several sites were compromised, including the U.S. Council on Foreign Relations (CFR). The attack used the Gh0st Rat exploit and was known as the VOHO attacks.<\/li><li>In 2016, the Canada-based International Civil Aviation Organization (ICAO)\u00a0spread malware\u00a0that infected the United Nations (UN) network.<\/li><li>In 2017, Ukrainian government websites were compromised to spread the ExPetr malware.<\/li><li>In 2019, many religious and humanitarian websites were compromised to target specific Asian communities.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>A watering hole attack is a security exploit in which the attacker seeks to compromise a specific group of end users by infecting websites that members of the group are known to visit. ByGavin Wright and Madelyn Bacon The goal is to infect a targeted user&#8217;s computer and gain access to the network at the target&#8217;s workplace. The term&nbsp;watering hole<\/p>\n<p><a class=\"more-link\" href=\"https:\/\/tekmart.co.za\/t-blog\/watering-hole-attack-what-these-are-how-they-work-and-how-to-prevent-becoming-a-victim\/\">Read More<\/a><\/p>\n","protected":false},"author":113,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75,155,38,35,8,138,172,54,56,195],"tags":[],"class_list":["post-7063","post","type-post","status-publish","format-standard","hentry","category-new-normal-courtesy-of-covid-19","category-batting-for-tech-in-the-covid-19-times","category-best-practices-for-data-center-operations","category-data-center-facilities","category-data-center-hardware","category-data-security","category-datacentre-disaster-recovery-and-security","category-hackers-and-cybercrime-prevention","category-it-infrastructure-management-and-planning-data-center-facilities","category-network-visibility"],"_links":{"self":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/7063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/users\/113"}],"replies":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/comments?post=7063"}],"version-history":[{"count":2,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/7063\/revisions"}],"predecessor-version":[{"id":7066,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/7063\/revisions\/7066"}],"wp:attachment":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/media?parent=7063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/categories?post=7063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/tags?post=7063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}