Watering Hole Attacks
A watering hole attack compromises or manipulates a legitimate website, portal, platform, or other online resource routinely used by a defined group, allowing normal access patterns to create the initial opportunity.
Trust is inherited from routine use. A familiar supplier portal, industry resource, or shared platform already fits the target audience’s workflow and may receive less scrutiny during repeated visits. The destination can therefore provide contextual legitimacy before an unusual request or change in behaviour is assessed.
Attackers may alter an existing resource, insert malicious content, profile visitors, redirect selected users, or use the compromised resource to deliver malware or capture credentials. Familiarity with the legitimate location can cause changes in its behaviour to receive less scrutiny.
How it appears
Section titled “How it appears”Watering hole attacks appear through compromised websites, altered supplier portals, community platforms, file repositories, software download pages, and other legitimate resources that deliver malicious content or redirect visitors elsewhere.
A standalone lookalike site is better treated as phishing or website impersonation rather than a watering hole. It can, however, form part of a watering hole attack when a compromised legitimate resource redirects selected visitors to it.
Common scenarios include:
- a compromised site used by a target industry or professional group
- a supplier or partner portal presenting an unfamiliar authentication flow
- an established resource page offering an unexpected file or update
- a community platform directing users to altered or external content
- a software page serving a modified installer
- a familiar website redirecting to another domain or login page
- a legitimate industry, supplier, event, or professional resource that has been compromised and continues to circulate through trusted networks
- a resource requesting credentials or sensitive information outside its normal workflow
These attacks turn on a small set of elements:
| Element | What it means | Examples |
|---|---|---|
| Trusted location | The website, portal, or online resource the target audience already expects to use. | Supplier portal, industry site, association page, community forum, file repository, software page. |
| Target audience | The group the attacker expects to reach through that location. | Employees, suppliers, sector members, developers, researchers, customers, event attendees. |
| Trust basis | The familiarity or relationship that makes the location appear legitimate. | Known domain, established brand, industry relevance, previous use, trusted community, supplier relationship. |
| Unexpected behaviour | The change in the site, page, or workflow that may indicate compromise or malicious manipulation. | New login prompt, redirect, download, warning, certificate issue, altered page, unusual form. |
| Requested action | The action sought through the altered or deceptive experience. | Enter credentials, approve MFA, download a file, install software, submit data, open a document. |
Indicators
Section titled “Indicators”Behavioural change in an established destination carries the indicators: a new action, altered content, or movement outside the workflow previously associated with the resource.
| Indicator | What to look for |
|---|---|
| Unexpected login prompt | A familiar website, portal, or resource suddenly requests credentials, MFA codes, recovery details, or account verification outside the established workflow. |
| Changed site behaviour | A known resource presents unfamiliar content, prompts, wording, navigation, or page behaviour. |
| Unexpected download | The site offers a file, installer, plugin, browser extension, document viewer, update, or security tool without an established reason. |
| Unexplained redirect | The resource moves to another domain, login page, file-sharing service, payment page, form, or support portal without a clear workflow basis. |
| Domain or certificate inconsistency | The URL, certificate, browser warning, domain spelling, or subdomain differs from the expected destination. |
| Unusual information request | Personal information, business information, payment details, credentials, MFA codes, or other sensitive data is requested where the resource does not normally require it. |
| Security control warning | Browser, endpoint, DNS, email, or download controls warn about the site, redirect, certificate, file, or page behaviour. |
| Shared reports of abnormal behaviour | Multiple users report the same unusual prompt, redirect, download, error, or account issue associated with the resource. |
| Redirect to a lookalike resource | A legitimate resource unexpectedly redirects to a page that reproduces a known industry, supplier, community, software, or portal site while using a different address or inconsistent branding. |
| Workflow mismatch | The requested action does not align with the established purpose or normal operation of the site, portal, or resource. |