A cybersecurity analyst is investigating an unauthorized network intrusion at a mid-sized engineering firm. System logs indicate that several high-level research engineers were infected with keylogger malware after visiting a legitimate, specialized computer-aided design (CAD) software forum that they frequently use for industry updates. Further analysis confirms the attacker compromised the forum site's web server beforehand to serve exploit code specifically targeting site visitors originating from the engineering firm's public IP address range. Which of the following social engineering threat types best describes this attack strategy?
- Watering hole attackAnswer
- BWhaling attack
- CPretexting attack
- DPharming attack
Answer
The attack strategy described is a watering hole attack because the attacker compromised a trusted third-party website routinely visited by the target group to deliver malware.
The correct answer is the option identifying a watering hole attack. In a watering hole attack, adversaries identify and compromise a trusted third-party website that members of a targeted organization frequently visit. Once the website is infected, visitors from the targeted organization are quietly served malicious code.
Step-by-Step Solution
Key Concept
Watering Hole Attack