During an infrastructure security review at an industrial design firm, security analysts discover that several senior hardware engineers were infected with malware after visiting a popular, highly niche third-party CAD community forum. Investigation reveals that threat actors compromised the forum server weeks earlier and modified its code to selectively deliver an exploit payload only to visitors originating from the design firm's corporate IP address range. Which social engineering vector did the threat actor primarily execute to target these specific employees?
- Watering hole attackCevap
- BSpear phishing campaign
- CPretexting attack
- DBaiting attack
Cevap
Watering hole attack
The correct answer is a watering hole attack. In a watering hole scenario, attackers identify sites frequently visited by members of a targeted group or enterprise, compromise one or more of those websites, and set up exploits to infect visitors connecting from the target organization's network.
Adım Adım Çözüm
Anahtar Kavram
Watering Hole Attack Identification and Indicators
Tahmini Süre:2m 0s