A defense contractor's incident response team discovers that several senior propulsion engineers' workstations were compromised by specialized remote access trojans (RATs). Forensic analysis indicates that none of the engineers received malicious emails, text messages, or direct phone calls. Instead, the threat actors compromised a reputable, third-party industry standards forum frequently visited by propulsion engineers and modified its server code to dynamically serve malicious drive-by exploits only to visitors originating from the contractor's specific public IP range. Which social engineering attack vector was primarily utilized in this scenario?
- Watering hole attackCevap
- BSpear phishing campaign
- CBusiness email compromise (BEC)
- DTyposquatting drive-by attack
Cevap
Watering hole attack
The correct answer accurately identifies a watering hole attack. In this attack vector, adversaries observe or anticipate which legitimate websites a target organization or interest group frequently visits, compromise one or more of those sites, and strategically deploy malware (such as drive-by exploit scripts) configured to trigger specifically for visitors from the target organization's IP address space.
Adım Adım Çözüm
Anahtar Kavram
Watering Hole Attack
Tahmini Süre:2m 0s