Watering hole attack

From HandWiki
Short description: Computer attack strategy


Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects one or more of them with malware. Eventually, some member of the targeted group will become infected.[1][2][3] Hacks looking for specific information may only attack users coming from a specific IP address. This also makes the hacks harder to detect and research.[4] The name is derived from predators in the natural world, who wait for an opportunity to attack their prey near watering holes.[5]

One of the most significant dangers of watering hole attacks is that they are executed via legitimate websites that are unable to be easily blacklisted. Also, the scripts and malware used in these attacks are often meticulously created, making it challenging for an antivirus software to identify them as threats.[6]

Defense techniques

Websites are often infected through zero-day vulnerabilities on browsers or other software.[4] A defense against known vulnerabilities is to apply the latest software patches to remove the vulnerability that allowed the site to be infected. This is assisted by users to ensure that all of their software is running the latest version. An additional defense is for companies to monitor their websites and networks and then block traffic if malicious content is detected.[7] Other defense techniques include utilizing complex passwords and passkeys to access websites as well as biometric information to protect data from attacks. Utilizing web injections such as firewalls or downloading anti-virus software on to devices can also protect from attacks. [8] Additionally, websites can enhance protection by disabling or removing vulnerable software, such as Flash and Adobe Reader, which are commonly targeted in cyber attacks.

Examples

2012 US Council on Foreign Relations

In December 2012, the Council on Foreign Relations website was found to be infected with malware through a zero-day vulnerability in Microsoft's Internet Explorer. In this attack, the malware was only deployed to users using Internet Explorer set to English, Chinese, Japanese, Korean and Russian.[9]

2013 Havex ICS software supply chain attack

Havex was discovered in 2013 and is one of five known Industrial Control System (ICS) tailored malware developed in the past decade. Energetic Bear began utilizing Havex in a widespread espionage campaign targeting energy, aviation, pharmaceutical, defense, and petrochemical sectors. The campaign targeted victims primarily in the United States and Europe.[10] Havex exploited supply chain and watering-hole attacks on ICS vendor software in addition to spear phishing campaigns to gain access to victim systems.[11]

2013 US Department of Labor

In mid-early 2013, attackers used the United States Department of Labor website to gather information on users that visited the website. This attack specifically targeted users visiting pages with nuclear-related content.[12]

2016 Polish banks

In late 2016, a Polish bank discovered malware on the institution's computers. It is believed that the source of this malware was the web server of the Polish Financial Supervision Authority.[13] There have been no reports on any financial losses as a result of this hack.[13]

2017 Montreal-based International Civil Aviation Organization attack

There was an organization-level watering-hole attack in Montreal from 2016-2017 by an unknown entity causing a data breach.[14]

2017 CCleaner attack

From August to September 2017, the installation binary of CCleaner distributed by the vendor's download servers included malware. CCleaner is a popular tool used to clean potentially unwanted files from Windows computers, widely used by security-minded users. The distributed installer binaries were signed with the developer's certificate making it likely that an attacker compromised the development or build environment and used this to insert malware.[15][16]

2017 NotPetya attack

In June 2017, the NotPetya (also known as ExPetr) malware, believed to have originated in Ukraine, compromised a Ukrainian government website. The attack vector was from users of the site downloading it. The malware erases the contents of victims' hard drives.[17]

2018 Chinese country-level attack

There was a country-level watering-hole attack in China from late 2017 into March 2018, by the group "LuckyMouse" also known as "Iron Tiger", "EmissaryPanda", "APT 27" and "Threat Group-3390."[18]

2019 Holy Water Campaign

In 2019, a watering-hole attack, called Holy Water Campaign, targeted Asian religious and charity groups.[19] Victims were prompted to update Adobe Flash which triggered the attack. It was creative and distinct due to its fast evolution.[20] Motive remains unclear.[20] Experts provided a detailed technical analysis along with a long list of Indicators of Compromise (IoCs) involved in the campaign, but none could be traced back to an Advanced Persistent Threat.[21]

See also

References

  1. Gragido, Will (20 July 2012). "Lions at the Watering Hole – The "VOHO" Affair". EMC Corporation. https://blogs.rsa.com/lions-at-the-watering-hole-the-voho-affair/. 
  2. Haaster, Jelle Van; Gevers, Rickey; Sprengers, Martijn (2016-06-13) (in en). Cyber Guerilla. Syngress. p. 57. ISBN 9780128052846. https://books.google.com/books?id=DDiOCgAAQBAJ&pg=PA57. 
  3. Miller, Joseph B. (2014). Internet Technologies and Information Services, 2nd Edition. ABC-CLIO. p. 123. ISBN 9781610698863. https://books.google.com/books?id=VBuDBAAAQBAJ&pg=PA123. 
  4. 4.0 4.1 Symantec. Internet Security Threat Report, April 2016, p. 38 https://www.symantec.com/content/dam/symantec/docs/reports/istr-21-2016-en.pdf
  5. Rouse, Margaret. "What is watering hole attack?" (in en-US). SearchSecurity. http://searchsecurity.techtarget.com/definition/watering-hole-attack. 
  6. APOSTOL, Mihai; PALINIUC, Bogdan; MORAR, Rareș; VIDU, Florin (2022-05-18). "Malicious Strategy: Watering Hole Attacks" (in en). Romanian Cyber Security Journal 4 (1): 29–37. doi:10.54851/v4i1y202204. ISSN 2668-6430. 
  7. Grimes, Roger A.. "Watch out for waterhole attacks -- hackers' latest stealth weapon" (in en). InfoWorld. http://www.infoworld.com/article/2614643/security/watch-out-for-waterhole-attacks----hackers--latest-stealth-weapon.html. 
  8. Ismail, Khairun Ashikin; Singh, Manmeet Mahinderjit; Mustaffa, Norlia; Keikhosrokiani, Pantea; Zulkefli, Zakiah (2017-01-01). "Security Strategies for Hindering Watering Hole Cyber Crime Attack". Procedia Computer Science. 4th Information Systems International Conference 2017, ISICO 2017, 6-8 November 2017, Bali, Indonesia 124: 656–663. doi:10.1016/j.procs.2017.12.202. ISSN 1877-0509. https://www.sciencedirect.com/science/article/pii/S1877050917329708. 
  9. "Council on Foreign Relations Website Hit by Watering Hole Attack, IE Zero-Day Exploit" (in en-US). Threatpost. 2012-12-29. https://threatpost.com/council-foreign-relations-website-hit-watering-hole-attack-ie-zero-day-exploit-122912/77352/. 
  10. "ICS Focused Malware" (in en). https://ics-cert.us-cert.gov/advisories/ICSA-14-178-01. 
  11. "Full Disclosure of Havex Trojans" (in en). 27 October 2014. https://www.netresec.com/?page=Blog&month=2014-10&post=Full-Disclosure-of-Havex-Trojans. 
  12. "Department of Labor Watering Hole Attack Confirmed to be 0-Day with Possible Advanced Reconnaissance Capabilities" (in en-US). 4 May 2013. http://blogs.cisco.com/security/department-of-labor-watering-hole-attack-confirmed-to-be-0-day-with-possible-advanced-reconnaissance-capabilities. 
  13. 13.0 13.1 "Attackers target dozens of global banks with new malware". Symantec Security Response. https://www.symantec.com/connect/blogs/attackers-target-dozens-global-banks-new-malware. 
  14. "'Patient zero' in cyberattack on UN aviation agency was senior official's son, email reveals | CBC News". 2023-02-20. https://www.cbc.ca/news/canada/montreal/icao-patient-zero-cyberattack-whistleblower-1.5223883. 
  15. "CCleanup: A Vast Number of Machines at Risk" (in en-US). http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html. 
  16. "Security Notification for CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 for 32-bit Windows users" (in en-US). https://www.piriform.com/news/blog/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users. 
  17. "Researchers Find BlackEnergy APT Links in ExPetr Code". 3 July 2017. https://threatpost.com/researchers-find-blackenergy-apt-links-in-expetr-code/126662/. 
  18. "Chinese Hackers Carried Out Country-Level Watering Hole Attack". https://thehackernews.com/2018/06/chinese-watering-hole-attack.html. 
  19. "Kaspersky uncovers a creative water hole attack discovered in the wild". 26 May 2021. https://usa.kaspersky.com/about/press-releases/2020_kaspersky-uncovers-a-creative-water-hole-attack-discovered-in-the-wild. 
  20. 20.0 20.1 "Holy water: ongoing targeted water-holing attack in Asia". 31 March 2020. https://securelist.com/holy-water-ongoing-targeted-water-holing-attack-in-asia/96311/. 
  21. "Holy water: ongoing targeted water-holing attack in Asia". 31 March 2020. https://securelist.com/holy-water-ongoing-targeted-water-holing-attack-in-asia/96311/.