During a malware investigation, an incident responder discovers that several engineers in an organization had their workstations infected after visiting an authentic, third-party software development forum that they frequently use for work. The attacker had previously breached the forum and injected a malicious drive-by download script targeting visitors originating from the organization's corporate IP range. Which of the following social engineering attack vectors was executed by the threat actor?
- Watering hole attackAnswer
- BSpear phishing
- CTyposquatting
- DPretexting
Answer
Watering hole attack
The correct answer is watering hole attack. In a watering hole attack, threat actors observe or predict which authentic websites a target group frequently visits, breach one of those sites, and plant malicious code to infect visitors from the target organization.
Step-by-Step Solution
Key Concept
Watering Hole Attack Vector Identification
Estimated Time:1m 0s