Technique.View on attack.mitre.org
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
* A legitimate website is compromised, allowing adversaries to inject malicious code
* Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary
* Malicious ads are paid for and served through legitimate ad providers (i.e., Malvertising)
* Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting)
Browser push notifications may also be abused by adversaries and leveraged for malicious code injection via User Execution. By clicking "allow" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser.
Often the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring.
Typical drive-by compromise process:
1. A user visits a website that is used to host the adversary controlled content.
2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes.
3. Upon finding a vulnerable version, exploit code is delivered to the browser.
4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered.
Unlike Exploit Public-Facing Application, the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.
Rules on DetectionCode tagged with T1189.
| Rule | Level | Log source |
|---|---|---|
| Cross Site Scripting Strings | high | NULL / webserver |
| Flash Player Update from Suspicious Location | high | NULL / proxy |
| Suspicious Browser Child Process - MacOS | medium | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect hosts connecting to dynamic domain providers | TTP | NULL | Sysmon EventID 22 |
| Splunk XSS Privilege Escalation via Custom Urls in Dashboard | Hunting | NULL | Splunk |
| Used by | Procedure example |
|---|---|
| GroupAndariel | Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range. |
| GroupAPT19 | APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
| GroupAPT28 | APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages. |
| GroupAPT32 | APT32 has infected victims by tricking them into visiting compromised watering hole websites. |
| GroupAPT37 | APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly. |
| GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| GroupAxiom | Axiom has used watering hole attacks to gain access. |
| GroupBRONZE BUTLER | BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks. |
| Used by | Procedure example |
|---|---|
| MalwareBad Rabbit | Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a |
| MalwareBundlore | Bundlore has been spread through malicious advertisements on websites. |
| MalwareGrandoreiro | Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer. |
| MalwareIcedID | IcedID has cloned legitimate websites/applications to distribute the malware. |
| MalwareKARAE | KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure. |
| MalwareLoudMiner | LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS. |
| MalwarePOORAIM | POORAIM has been delivered through compromised sites acting as watering holes. |
| MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus compromised the `www.tradingtechnologies[.]com` website hosting a hidden IFRAME to exploit visitors, two months before the site was known to deliver a compromised version of the X_TRADER software package. |
| CampaignC0010 | During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.