# What is a Watering Hole Attack?

> A watering hole attack targets a group by compromising or abusing an online destination that its members are likely to visit, then using that destination to profile, redirect, deceive, or attack selected visitors.

- Canonical URL: https://yellowcube.eu/glossary/watering-hole-attack/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The attacker chooses the destination because of the audience it attracts. The destination may be legitimate and unaware, and not every visitor must receive the same content or payload.

The destination might be a website, portal, forum, or download page. Attackers can alter the destination, a third-party resource, or a publishing account. Follow-on activity may exploit client software, present a deceptive download or sign-in page, or redirect visitors.

### Key points

- **Targeting logic:** Identify the community the destination serves, which visitors were selected, when harmful content appeared, and whether delivery varied by location, device, account, or other characteristics.
- **Investigation:** Preserve page and redirect evidence, relevant web and content-management changes, third-party dependencies, browser and endpoint events, network activity, and the timing of affected visits.
- **Risk reduction:** Protect publishing accounts and web infrastructure, govern external content, maintain browsers and related software, isolate higher-risk browsing where appropriate, and correlate web, endpoint, identity, and network telemetry.
- **Important limitation:** A visit before an incident does not prove that the destination caused it, and compromise does not make the site owner complicit. Content may rotate, target only some visitors, require another action, or fail to exploit the device.

### Related terms

[Malvertising](<https://yellowcube.eu/glossary/malvertising/>) · [Exploit](<https://yellowcube.eu/glossary/exploit/>) · [Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Social engineering](<https://yellowcube.eu/glossary/social-engineering/>) · [Browser security](<https://yellowcube.eu/glossary/browser-security/>) · [Drive-by compromise](<https://yellowcube.eu/glossary/drive-by-compromise/>)

### Sources

[NIST SP 800-150: Guide to Cyber Threat Information Sharing](https://csrc.nist.gov/pubs/sp/800/150/final) · [MITRE ATT&CK T1189: Drive-by Compromise](https://attack.mitre.org/techniques/T1189/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

