A tier 2 helpdesk technician receives multiple incident reports from accounting personnel stating that when navigating to an industry-specific news and regulatory updates website they visit daily, their web browsers display certificate warnings and attempt to redirect them to a fake single sign-on portal. Upon investigation, the technician confirms that internal corporate DNS server records and local workstation hosts files are unmodified and accurate. Further forensic analysis reveals that malicious code was injected directly into the external news site to target visitors originating from the company's public IP address range. Which of the following security threat types is demonstrated in this scenario?
- Watering hole attackAnswer
- BPharming
- CTyposquatting
- DPretexting
Answer
Watering hole attack
The correct answer identifies a watering hole attack. In this attack vector, adversaries compromise a third-party website known to be regularly visited by employees of a targeted organization. Because internal DNS and local host settings remain untouched, the malicious redirection originates directly from the compromised external site targeting visitors from specific corporate IP blocks.
Step-by-Step Solution
Key Concept
Watering Hole Attack Identification