Watering Hole Attack
A watering hole attack compromises a website a target group already trusts and visits, infecting visitors instead of approaching them directly.
A watering hole attack is a targeted attack in which the adversary compromises a legitimate website that a specific group of people is known to visit — an industry news portal, a supplier's support page, a regional government site — and plants malicious code there. Instead of approaching victims directly, the attacker waits for them to come to the "watering hole," the way a predator waits where prey drinks.
How it works
The attacker first profiles the target organization or sector and identifies websites its employees frequent. They then find a vulnerability in one of those sites and inject code that either exploits visitors' browsers directly or redirects them to a controlled page — often a fake login portal or a prompt to install a "required update." Because the compromised site is genuinely legitimate and often allow-listed by corporate web filters, the traffic looks normal to both the victim and many security tools. Watering hole campaigns have been used repeatedly in espionage operations against defense, energy, and financial-sector targets precisely because they bypass the skepticism employees apply to unsolicited email.
What makes the technique dangerous is the inversion of trust: every safe-browsing habit an employee has learned ("only visit sites you know") works in the attacker's favor, because the site is one they know. Unlike spear phishing, there is no suspicious message to spot — the victim initiates the visit themselves.
How to defend against it
Keep browsers and plugins patched aggressively — most watering hole exploits target known, unpatched vulnerabilities. Use web protection that inspects content and behavior rather than relying only on domain reputation, since the referring domain is legitimate by design. Segment networks and apply least privilege so a single compromised endpoint cannot become a foothold for lateral movement. Finally, train employees to treat unexpected prompts — a login request or "update" appearing on a familiar site — as a red flag worth reporting, and measure that reflex with realistic simulations. Understanding which employees and teams are most exposed to this class of attack is part of building a complete human risk management picture.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo