The attacker chooses the destination because of the audience it attracts. The destination may be legitimate and unaware, and not every visitor must receive the same content or payload.
The destination might be a website, portal, forum, or download page. Attackers can alter the destination, a third-party resource, or a publishing account. Follow-on activity may exploit client software, present a deceptive download or sign-in page, or redirect visitors.
Key points
Targeting logicIdentify the community the destination serves, which visitors were selected, when harmful content appeared, and whether delivery varied by location, device, account, or other characteristics.
InvestigationPreserve page and redirect evidence, relevant web and content-management changes, third-party dependencies, browser and endpoint events, network activity, and the timing of affected visits.
Risk reductionProtect publishing accounts and web infrastructure, govern external content, maintain browsers and related software, isolate higher-risk browsing where appropriate, and correlate web, endpoint, identity, and network telemetry.
Important limitationA visit before an incident does not prove that the destination caused it, and compromise does not make the site owner complicit. Content may rotate, target only some visitors, require another action, or fail to exploit the device.