Scanning your connection...
Back to Glossary
Attacks

What is Watering Hole Attack?

A targeted attack that compromises a website frequently visited by a specific group of people, infecting visitors with malware.

Named after predators that wait at watering holes for prey, this attack targets the websites a victim group regularly visits.

How It Works

  1. Attacker identifies websites commonly visited by the target group
  2. Finds a vulnerability in one of these websites
  3. Injects malicious code into the website
  4. When targets visit the site, the malware silently infects their devices
  5. The attack is specific — it may only activate for visitors from certain IP ranges

Famous Examples

  • iOS exploits (2019): Uyghur community websites were compromised to install spyware on iPhone visitors
  • Polish financial regulator (2017): Compromised to target banking employees

Why It's Effective

  • Targets don't need to click suspicious links
  • The compromised site is one they trust
  • Can be very targeted (only infect specific visitors)

Protection

  1. Keep browsers and plugins updated
  2. Use a browser with good sandboxing (Chrome, Brave)
  3. Consider using a different browser for high-risk browsing
  4. Use a VPN to avoid being profiled by IP range

Related Terms

Have more questions?

Use our guided flow to get the right next privacy step for Watering Hole Attack.

Open Guided Flow