An IT security analyst is investigating a breach where multiple compliance officers' workstations were infected with spyware simultaneously. Email security logs show no suspicious incoming messages, external USB storage devices are blocked via Group Policy, and physical access logs show no unauthorized entry. Analysis reveals that all affected personnel regularly visit a specific third-party industry news website, which had been secretly compromised to serve malicious scripts to site visitors. Which of the following attack types best describes this scenario?
- Watering hole attackAnswer
- BSpear phishing
- CUSB baiting
- DPretexting
Answer
Watering hole attack
A watering hole attack occurs when an attacker compromises a specific website frequently visited by a target organization or department, planting malware to infect users upon visit. In this scenario, since email logs showed no malicious emails and USB ports were disabled, the infection of multiple users via a frequented third-party news site precisely fits the definition of a watering hole attack.
Step-by-Step Solution
Key Concept
Watering Hole Attack Identification