What is a watering hole attack?

[ad_1]

Most hackers start The victim made some kind of mistake, whether it was typing the password on a convincing person Phishing page or Accidentally downloaded a malicious attachment On the work computer. But a particularly sinister technique starts with simply visiting a real website. They are called watering hole attacks, and in addition to being a long-standing threat, they have recently become behind several high-profile incidents.

The most notorious watering hole attack in recent memory came to light in 2019, after which Targeting iPhone users in the Uighur Muslim community in China Two years. But threat intelligence researchers emphasize that the technology is quite common, probably because it is very powerful and efficient. Internet security company ESET said it detects multiple watering hole attacks every year, and Google’s Threat Analysis Group (TAG) also detects as many as once a month.

The name comes from the idea of ​​poisoning a central water source and then infecting anyone who drinks it. Relatedly, it also evokes predators lurking near puddles waiting for their prey to stop. Watering hole attacks can be difficult to detect because they usually run quietly on legitimate websites, and their owners may not notice any problems. Even once discovered, it is usually unclear how long the attack lasted and how many victims there were.

“Assume that attackers are hunting down democracy activists. They may hack into democracy activist websites knowing that all these potential targets will be accessed,” said Shane Huntley, director of Google TAG. An important step where the target must do something or be deceived. Instead of targeting activists with something they actually have to click on, it can be difficult because they are so savvy that you can go where they have already been and immediately skip to the part where you actually use people’s devices. “

For example, earlier this month, TAG released its findings regarding the watering hole attack, which compromised the websites of many media and pro-democracy groups. Target visitors who use Mac and iPhone in Hong KongBased on the evidence that can be collected, TAG cannot determine how long the attack lasted or how many devices were affected.

Watering hole attacks always have two types of victims: legitimate websites or services that the attacker destroys in order to embed their malicious infrastructure, and users who are compromised while visiting. Attackers are becoming more adept at minimizing their footprint, using the infected website or service only as a conduit between the victim and the external malicious infrastructure, without any indication that the user has any problems. In this way, the attacker does not have to build all the content within the infected site itself. This is convenient for hackers, which makes the attack easier to set up and harder to track down.

To turn a website visit into a real hack, the attacker needs to be able to take advantage of the software flaws on the victim’s device, usually a series of Browser errorThis provides the attacker with the access rights needed to install spyware or other malicious software. If hackers really want to spread the net, they will build their own infrastructure to use as many devices and software versions as possible. However, the researchers pointed out that although watering hole attacks appear to be indiscriminate, hackers have the ability to target victims more precisely through the type of device or other information collected using the browser (such as which country their IP address is from).

[ad_2]

Source link