During a security audit at a financial consulting firm, a technician discovers that multiple workstations in the payroll department were infected with stealth malware. Logs show that all compromised users routinely visit an obscure, third-party state tax regulation portal to verify daily compliance updates. An attacker secretly compromised this trusted external portal and injected code that automatically redirects visiting payroll staff to a server hosting an exploit kit, executing malicious code on unpatched web browsers without requiring any user interaction or email link clicks. Which of the following attack vectors best describes this incident?
- Watering hole attackAnswer
- BSpear phishing
- CPretexting
- DTyposquatting
Answer
The attack vector described in the scenario is a watering hole attack.
A watering hole attack occurs when an attacker identifies a website frequently visited by members of a targeted group or organization, compromises that site, and plants malicious code to infect visitors' systems. In this scenario, compromising the third-party state tax regulation portal to infect payroll staff automatically upon visiting aligns precisely with a watering hole attack.
Step-by-Step Solution
Key Concept
Watering Hole Attack
Estimated Time:2m 0s